[selinux-policy: 1592/3172] clean up usercanread
Daniel J Walsh
dwalsh at fedoraproject.org
Thu Oct 7 21:22:47 UTC 2010
commit 376fbc0be9c2bbddaac8887f8a9dbc7e5d3c2677
Author: Chris PeBenito <cpebenito at tresys.com>
Date: Mon Sep 11 18:23:09 2006 +0000
clean up usercanread
policy/modules/services/cups.te | 26 ++------------------------
1 files changed, 2 insertions(+), 24 deletions(-)
---
diff --git a/policy/modules/services/cups.te b/policy/modules/services/cups.te
index e879d56..6043f6c 100644
--- a/policy/modules/services/cups.te
+++ b/policy/modules/services/cups.te
@@ -1,5 +1,5 @@
-policy_module(cups,1.3.12)
+policy_module(cups,1.3.13)
########################################
#
@@ -157,8 +157,6 @@ domain_read_all_domains_state(cupsd_t)
fs_getattr_all_fs(cupsd_t)
fs_search_auto_mountpoints(cupsd_t)
-# from old usercanread attrib:
-fs_read_removable_files(cupsd_t)
term_dontaudit_use_console(cupsd_t)
term_write_unallocated_ttys(cupsd_t)
@@ -271,12 +269,7 @@ optional_policy(`
')
optional_policy(`
- # from old usercanread attrib:
- rpc_read_nfs_content(cupsd_t)
- rpc_read_nfs_state_data(cupsd_t)
-')
-
-optional_policy(`
+ samba_read_config(cupsd_t)
samba_rw_var_files(cupsd_t)
')
@@ -288,21 +281,6 @@ optional_policy(`
udev_read_db(cupsd_t)
')
-optional_policy(`
- # from old usercanread attrib:
- usermanage_read_crack_db(cupsd_t)
-')
-
-optional_policy(`
- # from old usercanread attrib:
- xserver_read_xkb_libs(cupsd_t)
-')
-
-#FIXME:
-allow cupsd_t usercanread:dir r_dir_perms;
-allow cupsd_t usercanread:file r_file_perms;
-allow cupsd_t usercanread:lnk_file { getattr read };
-
########################################
#
# Cups configuration daemon local policy
More information about the scm-commits
mailing list