[selinux-policy: 2987/3172] Use relabel permission sets where possible.

Daniel J Walsh dwalsh at fedoraproject.org
Thu Oct 7 23:25:52 UTC 2010


commit a3d20a3c3a4988018e94a2619cf16d3fa2f64dc6
Author: Dominick Grift <domg472 at gmail.com>
Date:   Thu Sep 16 10:45:36 2010 +0200

    Use relabel permission sets where possible.

 policy/modules/services/xserver.if |    4 ++--
 1 files changed, 2 insertions(+), 2 deletions(-)
---
diff --git a/policy/modules/services/xserver.if b/policy/modules/services/xserver.if
index 8ed36f2..5efb656 100644
--- a/policy/modules/services/xserver.if
+++ b/policy/modules/services/xserver.if
@@ -158,10 +158,10 @@ interface(`xserver_role',`
 	allow $2 xserver_tmpfs_t:file rw_file_perms;
 
 	allow $2 iceauth_home_t:file manage_file_perms;
-	allow $2 iceauth_home_t:file { relabelfrom relabelto };
+	allow $2 iceauth_home_t:file relabel_file_perms;
 
 	allow $2 xauth_home_t:file manage_file_perms;
-	allow $2 xauth_home_t:file { relabelfrom relabelto };
+	allow $2 xauth_home_t:file relabel_file_perms;
 
 	mls_xwin_read_to_clearance($2)
 	manage_dirs_pattern($2, user_fonts_t, user_fonts_t)


More information about the scm-commits mailing list