[refpolicy] roles_staff.patch
Daniel J Walsh
dwalsh at redhat.com
Wed Jun 2 15:31:26 CDT 2010
http://people.fedoraproject.org/~dwalsh/SELinux/F14/roles_staff.patch
Allow staff user to exec files on removable devices
Needs access to run sandbox
Additional access for staff reading kernel info.
staff_t needs to run newrole to relabel content in his homedir
Needs to run ping
Added distro_redhat to eliminate all of the transitions that we did not
want.
More information about the refpolicy
mailing list