[selinux-policy: 2216/3172] fix ordering in pcmcia.

Daniel J Walsh dwalsh at fedoraproject.org
Thu Oct 7 22:16:45 UTC 2010


commit 4b218bd6462b44e8692da7122c3379a25073525b
Author: Chris PeBenito <cpebenito at tresys.com>
Date:   Wed Aug 5 10:18:31 2009 -0400

    fix ordering in pcmcia.

 policy/modules/system/pcmcia.te |   19 +++++++++----------
 1 files changed, 9 insertions(+), 10 deletions(-)
---
diff --git a/policy/modules/system/pcmcia.te b/policy/modules/system/pcmcia.te
index 4f2324d..d17a662 100644
--- a/policy/modules/system/pcmcia.te
+++ b/policy/modules/system/pcmcia.te
@@ -51,7 +51,7 @@ kernel_read_system_state(cardmgr_t)
 kernel_read_kernel_sysctls(cardmgr_t)
 kernel_dontaudit_getattr_message_if(cardmgr_t)
 
-files_search_kernel_modules(cardmgr_t)
+corecmd_exec_all_executables(cardmgr_t)
 
 dev_read_sysfs(cardmgr_t)
 dev_manage_cardmgr_dev(cardmgr_t)
@@ -61,15 +61,6 @@ dev_getattr_all_blk_files(cardmgr_t)
 # for SSP
 dev_read_urand(cardmgr_t)
 
-fs_getattr_all_fs(cardmgr_t)
-fs_search_auto_mountpoints(cardmgr_t)
-
-term_use_unallocated_ttys(cardmgr_t)
-term_getattr_all_user_ttys(cardmgr_t)
-term_dontaudit_getattr_all_user_ptys(cardmgr_t)
-
-corecmd_exec_all_executables(cardmgr_t)
-
 domain_use_interactive_fds(cardmgr_t)
 # Read /proc/PID directories for all domains (for fuser).
 domain_read_confined_domains_state(cardmgr_t)
@@ -79,6 +70,7 @@ domain_dontaudit_ptrace_confined_domains(cardmgr_t)
 domain_dontaudit_getattr_all_pipes(cardmgr_t)
 domain_dontaudit_getattr_all_sockets(cardmgr_t)
 
+files_search_kernel_modules(cardmgr_t)
 files_list_usr(cardmgr_t)
 files_search_home(cardmgr_t)
 files_read_etc_runtime_files(cardmgr_t)
@@ -93,6 +85,13 @@ files_dontaudit_getattr_all_symlinks(cardmgr_t)
 files_dontaudit_getattr_all_pipes(cardmgr_t)
 files_dontaudit_getattr_all_sockets(cardmgr_t)
 
+fs_getattr_all_fs(cardmgr_t)
+fs_search_auto_mountpoints(cardmgr_t)
+
+term_use_unallocated_ttys(cardmgr_t)
+term_getattr_all_user_ttys(cardmgr_t)
+term_dontaudit_getattr_all_user_ptys(cardmgr_t)
+
 libs_exec_ld_so(cardmgr_t)
 libs_exec_lib_files(cardmgr_t)
 


More information about the scm-commits mailing list