[refpolicy] [PATCH] make consolekit_t a confined X client

Eamon Walsh ewalsh at tycho.nsa.gov
Fri Oct 30 18:13:02 CDT 2009

Note: I don't know what to put for the third argument to xserver_user_x_domain_template.
tmpfs_t?  user_tmpfs_t?  Why does this template have a tmpfs argument anyway?

commit fa343fbf30f96528e06a1b487dfef5e808f3b68b
Author: Eamon Walsh <ewalsh at tycho.nsa.gov>
Date:   Fri Oct 30 18:47:17 2009 -0400

    Make consolekit_t a confined X user.
    The program /usr/libexec/ck-get-x11-server-pid connects to the
    X server after a user login.  The program itself doesn't do
    anything except call getpeercred(), however Xlib helpfully
    creates some objects and reads properties in XOpenDisplay().
    TODO: Fix consolekit to use libxcb instead...
    Signed-off-by: Eamon Walsh <ewalsh at tycho.nsa.gov>

diff --git a/policy/modules/services/consolekit.te b/policy/modules/services/consolekit.te
index 1ead55d..ba53a09 100644
--- a/policy/modules/services/consolekit.te
+++ b/policy/modules/services/consolekit.te
@@ -108,6 +108,7 @@ optional_policy(`
+	xserver_user_x_domain_template(consolekit, consolekit_t, tmpfs_t)


Eamon Walsh 
National Security Agency

More information about the refpolicy mailing list