[selinux-policy: 815/3172] Fixed a problem which was allowing processes to become unconfined from initrc

Daniel J Walsh dwalsh at fedoraproject.org
Thu Oct 7 20:15:33 UTC 2010


commit 0354e306b763d05cfaf9ca81467af4ae130fd63e
Author: Don Miner <dminer at tresys.com>
Date:   Mon Oct 24 18:10:47 2005 +0000

    Fixed a problem which was allowing processes to become unconfined from initrc

 refpolicy/policy/modules/system/init.te |    1 -
 1 files changed, 0 insertions(+), 1 deletions(-)
---
diff --git a/refpolicy/policy/modules/system/init.te b/refpolicy/policy/modules/system/init.te
index 1f1a6c8..0f3715c 100644
--- a/refpolicy/policy/modules/system/init.te
+++ b/refpolicy/policy/modules/system/init.te
@@ -440,7 +440,6 @@ ifdef(`distro_redhat',`
 ifdef(`targeted_policy',`
 	domain_subj_id_change_exempt(initrc_t)
 	unconfined_domain_template(initrc_t)
-	unconfined_shell_domtrans(initrc_t)
 ')
 
 optional_policy(`apache.te',`


More information about the scm-commits mailing list