[selinux-policy: 2/2] Cleanup related to init_domain()+inetd_domain fixes

Daniel J Walsh dwalsh at fedoraproject.org
Thu Sep 5 13:43:01 UTC 2013


commit 8f2f92723cfecb59299667c78b650e164c301866
Merge: 1b0e092 22545a1
Author: Dan Walsh <dwalsh at redhat.com>
Date:   Thu Sep 5 09:42:38 2013 -0400

    Cleanup related to init_domain()+inetd_domain fixes
    
    - Use just init_domain instead of init_daemon_domain in inetd_core_service_domain
    - svirt domains neeed to create kobject_uevint_sockets
    - Lots of new access required for sosreport
    - Allow tgtd_t to connect to isns ports
    - Allow init_t to transition to all inetd domains:
    - openct needs to be able to create netlink_object_uevent_sockets
    - Dontaudit leaks into ldconfig_t
    - Dontaudit su domains getattr on /dev devices, move su domains to attribute based calls
    - Move kernel_stream_connect into all Xwindow using users
    - Dontaudit inherited lock files in ifconfig o dhcpc_t

---


More information about the scm-commits mailing list