[selinux-policy: 1592/3172] clean up usercanread

Daniel J Walsh dwalsh at fedoraproject.org
Thu Oct 7 21:22:47 UTC 2010


commit 376fbc0be9c2bbddaac8887f8a9dbc7e5d3c2677
Author: Chris PeBenito <cpebenito at tresys.com>
Date:   Mon Sep 11 18:23:09 2006 +0000

    clean up usercanread

 policy/modules/services/cups.te |   26 ++------------------------
 1 files changed, 2 insertions(+), 24 deletions(-)
---
diff --git a/policy/modules/services/cups.te b/policy/modules/services/cups.te
index e879d56..6043f6c 100644
--- a/policy/modules/services/cups.te
+++ b/policy/modules/services/cups.te
@@ -1,5 +1,5 @@
 
-policy_module(cups,1.3.12)
+policy_module(cups,1.3.13)
 
 ########################################
 #
@@ -157,8 +157,6 @@ domain_read_all_domains_state(cupsd_t)
 
 fs_getattr_all_fs(cupsd_t)
 fs_search_auto_mountpoints(cupsd_t)
-# from old usercanread attrib:
-fs_read_removable_files(cupsd_t)
 
 term_dontaudit_use_console(cupsd_t)
 term_write_unallocated_ttys(cupsd_t)
@@ -271,12 +269,7 @@ optional_policy(`
 ')
 
 optional_policy(`
-	# from old usercanread attrib:
-	rpc_read_nfs_content(cupsd_t)
-	rpc_read_nfs_state_data(cupsd_t)
-')
-
-optional_policy(`
+	samba_read_config(cupsd_t)
 	samba_rw_var_files(cupsd_t)
 ')
 
@@ -288,21 +281,6 @@ optional_policy(`
 	udev_read_db(cupsd_t)
 ')
 
-optional_policy(`
-	# from old usercanread attrib:
-	usermanage_read_crack_db(cupsd_t)
-')
-
-optional_policy(`
-	# from old usercanread attrib:
-	xserver_read_xkb_libs(cupsd_t)
-')
-
-#FIXME:
-allow cupsd_t usercanread:dir r_dir_perms;
-allow cupsd_t usercanread:file r_file_perms;
-allow cupsd_t usercanread:lnk_file { getattr read };
-
 ########################################
 #
 # Cups configuration daemon local policy


More information about the scm-commits mailing list