[selinux-policy: 2216/3172] fix ordering in pcmcia.
Daniel J Walsh
dwalsh at fedoraproject.org
Thu Oct 7 22:16:45 UTC 2010
commit 4b218bd6462b44e8692da7122c3379a25073525b
Author: Chris PeBenito <cpebenito at tresys.com>
Date: Wed Aug 5 10:18:31 2009 -0400
fix ordering in pcmcia.
policy/modules/system/pcmcia.te | 19 +++++++++----------
1 files changed, 9 insertions(+), 10 deletions(-)
---
diff --git a/policy/modules/system/pcmcia.te b/policy/modules/system/pcmcia.te
index 4f2324d..d17a662 100644
--- a/policy/modules/system/pcmcia.te
+++ b/policy/modules/system/pcmcia.te
@@ -51,7 +51,7 @@ kernel_read_system_state(cardmgr_t)
kernel_read_kernel_sysctls(cardmgr_t)
kernel_dontaudit_getattr_message_if(cardmgr_t)
-files_search_kernel_modules(cardmgr_t)
+corecmd_exec_all_executables(cardmgr_t)
dev_read_sysfs(cardmgr_t)
dev_manage_cardmgr_dev(cardmgr_t)
@@ -61,15 +61,6 @@ dev_getattr_all_blk_files(cardmgr_t)
# for SSP
dev_read_urand(cardmgr_t)
-fs_getattr_all_fs(cardmgr_t)
-fs_search_auto_mountpoints(cardmgr_t)
-
-term_use_unallocated_ttys(cardmgr_t)
-term_getattr_all_user_ttys(cardmgr_t)
-term_dontaudit_getattr_all_user_ptys(cardmgr_t)
-
-corecmd_exec_all_executables(cardmgr_t)
-
domain_use_interactive_fds(cardmgr_t)
# Read /proc/PID directories for all domains (for fuser).
domain_read_confined_domains_state(cardmgr_t)
@@ -79,6 +70,7 @@ domain_dontaudit_ptrace_confined_domains(cardmgr_t)
domain_dontaudit_getattr_all_pipes(cardmgr_t)
domain_dontaudit_getattr_all_sockets(cardmgr_t)
+files_search_kernel_modules(cardmgr_t)
files_list_usr(cardmgr_t)
files_search_home(cardmgr_t)
files_read_etc_runtime_files(cardmgr_t)
@@ -93,6 +85,13 @@ files_dontaudit_getattr_all_symlinks(cardmgr_t)
files_dontaudit_getattr_all_pipes(cardmgr_t)
files_dontaudit_getattr_all_sockets(cardmgr_t)
+fs_getattr_all_fs(cardmgr_t)
+fs_search_auto_mountpoints(cardmgr_t)
+
+term_use_unallocated_ttys(cardmgr_t)
+term_getattr_all_user_ttys(cardmgr_t)
+term_dontaudit_getattr_all_user_ptys(cardmgr_t)
+
libs_exec_ld_so(cardmgr_t)
libs_exec_lib_files(cardmgr_t)
More information about the scm-commits
mailing list