[selinux-policy: 2217/3172] fix ordering in raid.
Daniel J Walsh
dwalsh at fedoraproject.org
Thu Oct 7 22:16:50 UTC 2010
commit 48bf6397fc4d733cba3350d0e19c42bc63c435d5
Author: Chris PeBenito <cpebenito at tresys.com>
Date: Wed Aug 5 10:19:28 2009 -0400
fix ordering in raid.
policy/modules/system/raid.te | 24 ++++++++++++------------
1 files changed, 12 insertions(+), 12 deletions(-)
---
diff --git a/policy/modules/system/raid.te b/policy/modules/system/raid.te
index 91f1259..24a899c 100644
--- a/policy/modules/system/raid.te
+++ b/policy/modules/system/raid.te
@@ -32,6 +32,10 @@ kernel_read_kernel_sysctls(mdadm_t)
kernel_rw_software_raid_state(mdadm_t)
kernel_getattr_core_if(mdadm_t)
+# Helper program access
+corecmd_exec_bin(mdadm_t)
+corecmd_exec_shell(mdadm_t)
+
dev_read_sysfs(mdadm_t)
# Ignore attempts to read every device file
dev_dontaudit_getattr_all_blk_files(mdadm_t)
@@ -41,28 +45,24 @@ dev_dontaudit_getattr_generic_chr_files(mdadm_t)
dev_dontaudit_getattr_generic_blk_files(mdadm_t)
dev_read_realtime_clock(mdadm_t)
+domain_use_interactive_fds(mdadm_t)
+
+files_read_etc_files(mdadm_t)
+files_read_etc_runtime_files(mdadm_t)
+
fs_search_auto_mountpoints(mdadm_t)
fs_dontaudit_list_tmpfs(mdadm_t)
+mls_file_read_all_levels(mdadm_t)
+mls_file_write_all_levels(mdadm_t)
+
# RAID block device access
storage_manage_fixed_disk(mdadm_t)
storage_dev_filetrans_fixed_disk(mdadm_t)
storage_read_scsi_generic(mdadm_t)
-mls_file_read_all_levels(mdadm_t)
-mls_file_write_all_levels(mdadm_t)
-
term_dontaudit_list_ptys(mdadm_t)
-# Helper program access
-corecmd_exec_bin(mdadm_t)
-corecmd_exec_shell(mdadm_t)
-
-domain_use_interactive_fds(mdadm_t)
-
-files_read_etc_files(mdadm_t)
-files_read_etc_runtime_files(mdadm_t)
-
init_dontaudit_getattr_initctl(mdadm_t)
logging_send_syslog_msg(mdadm_t)
More information about the scm-commits
mailing list