[selinux-policy: 2981/3172] Use domtrans_pattern because it include permission the sigchld target domain and other required acce

Daniel J Walsh dwalsh at fedoraproject.org
Thu Oct 7 23:25:21 UTC 2010


commit 5ebd1a52a569eb58a53538c683ad64d12434af0e
Author: Dominick Grift <domg472 at gmail.com>
Date:   Thu Sep 16 08:51:01 2010 +0200

    Use domtrans_pattern because it include permission the sigchld target domain and other required access to domain transition.
    
    Signed-off-by: Dominick Grift <domg472 at gmail.com>

 policy/modules/services/ucspitcp.if |    5 +----
 1 files changed, 1 insertions(+), 4 deletions(-)
---
diff --git a/policy/modules/services/ucspitcp.if b/policy/modules/services/ucspitcp.if
index c1feba4..bf82170 100644
--- a/policy/modules/services/ucspitcp.if
+++ b/policy/modules/services/ucspitcp.if
@@ -31,8 +31,5 @@ interface(`ucspitcp_service_domain', `
 
 	role system_r types $1;
 
-	domain_auto_trans(ucspitcp_t, $2, $1)
-	allow $1 ucspitcp_t:fd use;
-	allow $1 ucspitcp_t:process sigchld;
-	allow $1 ucspitcp_t:tcp_socket rw_stream_socket_perms;
+	domtrans_pattern(ucspitcp_t, $2, $1)
 ')


More information about the scm-commits mailing list