Changeset 156
- Timestamp:
- 01/08/08 12:26:34
(11 months ago)
- Author:
- bwilliams
- Message:
fixed bug with booleans
-
Files:
-
Legend:
- Unmodified
- Added
- Removed
- Modified
- Copied
- Moved
| r153 |
r156 |
|
| 128 | 128 | </desc> |
|---|
| 129 | 129 | </tunable> |
|---|
| | 130 | <tunable name="spamd_enable_home_dirs" dftval="false"> |
|---|
| | 131 | <desc> |
|---|
| | 132 | <p> |
|---|
| | 133 | Allow applications to write untrusted content |
|---|
| | 134 | </p> |
|---|
| | 135 | </desc> |
|---|
| | 136 | </tunable> |
|---|
| | 137 | <tunable name="spamassassin_can_network" dftval="false"> |
|---|
| | 138 | <desc> |
|---|
| | 139 | <p> |
|---|
| | 140 | Allow applications to write untrusted content |
|---|
| | 141 | </p> |
|---|
| | 142 | </desc> |
|---|
| | 143 | </tunable> |
|---|
| | 144 | <tunable name="samba_enable_home_dirs" dftval="false"> |
|---|
| | 145 | <desc> |
|---|
| | 146 | <p> |
|---|
| | 147 | Allow applications to write untrusted content |
|---|
| | 148 | </p> |
|---|
| | 149 | </desc> |
|---|
| | 150 | </tunable> |
|---|
| | 151 | <tunable name="pppd_for_user" dftval="false"> |
|---|
| | 152 | <desc> |
|---|
| | 153 | <p> |
|---|
| | 154 | Allow applications to write untrusted content |
|---|
| | 155 | </p> |
|---|
| | 156 | </desc> |
|---|
| | 157 | </tunable> |
|---|
| | 158 | <tunable name="allow_kerberos" dftval="false"> |
|---|
| | 159 | <desc> |
|---|
| | 160 | <p> |
|---|
| | 161 | Allow applications to write untrusted content |
|---|
| | 162 | </p> |
|---|
| | 163 | </desc> |
|---|
| | 164 | </tunable> |
|---|
| r153 |
r156 |
|
| 1135 | 1135 | <rolecap/> |
|---|
| 1136 | 1136 | </interface> |
|---|
| 1137 | | <interface name="netutils_exec_ping" lineno="203"> |
|---|
| | 1137 | <interface name="netutils_exec_ping" lineno="202"> |
|---|
| 1138 | 1138 | <summary> |
|---|
| 1139 | 1139 | Execute ping in the caller domain. |
|---|
| … | … | |
| 1145 | 1145 | </param> |
|---|
| 1146 | 1146 | </interface> |
|---|
| 1147 | | <interface name="netutils_domtrans_traceroute" lineno="221"> |
|---|
| | 1147 | <interface name="netutils_domtrans_traceroute" lineno="220"> |
|---|
| 1148 | 1148 | <summary> |
|---|
| 1149 | 1149 | Execute traceroute in the traceroute domain. |
|---|
| … | … | |
| 1155 | 1155 | </param> |
|---|
| 1156 | 1156 | </interface> |
|---|
| 1157 | | <interface name="netutils_run_traceroute" lineno="251"> |
|---|
| | 1157 | <interface name="netutils_run_traceroute" lineno="250"> |
|---|
| 1158 | 1158 | <summary> |
|---|
| 1159 | 1159 | Execute traceroute in the traceroute domain, and |
|---|
| … | … | |
| 1177 | 1177 | <rolecap/> |
|---|
| 1178 | 1178 | </interface> |
|---|
| 1179 | | <interface name="netutils_run_traceroute_cond" lineno="283"> |
|---|
| | 1179 | <interface name="netutils_run_traceroute_cond" lineno="282"> |
|---|
| 1180 | 1180 | <summary> |
|---|
| 1181 | 1181 | Conditionally execute traceroute in the traceroute domain, and |
|---|
| … | … | |
| 1199 | 1199 | <rolecap/> |
|---|
| 1200 | 1200 | </interface> |
|---|
| 1201 | | <interface name="netutils_exec_traceroute" lineno="307"> |
|---|
| | 1201 | <interface name="netutils_exec_traceroute" lineno="305"> |
|---|
| 1202 | 1202 | <summary> |
|---|
| 1203 | 1203 | Execute traceroute in the caller domain. |
|---|
| … | … | |
| 1678 | 1678 | </param> |
|---|
| 1679 | 1679 | </template> |
|---|
| 1680 | | <interface name="su_exec" lineno="317"> |
|---|
| | 1680 | <interface name="su_exec" lineno="316"> |
|---|
| 1681 | 1681 | <summary> |
|---|
| 1682 | 1682 | Execute su in the caller domain. |
|---|
| … | … | |
| 44613 | 44613 | <rolecap/> |
|---|
| 44614 | 44614 | </interface> |
|---|
| 44615 | | <interface name="selinux_load_policy" lineno="219"> |
|---|
| | 44615 | <interface name="selinux_load_policy" lineno="218"> |
|---|
| 44616 | 44616 | <summary> |
|---|
| 44617 | 44617 | Allow caller to load the policy into the kernel. |
|---|
| … | … | |
| 44623 | 44623 | </param> |
|---|
| 44624 | 44624 | </interface> |
|---|
| 44625 | | <interface name="selinux_set_boolean" lineno="262"> |
|---|
| | 44625 | <interface name="selinux_set_boolean" lineno="260"> |
|---|
| 44626 | 44626 | <summary> |
|---|
| 44627 | 44627 | Allow caller to set the state of Booleans to |
|---|
| … | … | |
| 44645 | 44645 | <rolecap/> |
|---|
| 44646 | 44646 | </interface> |
|---|
| 44647 | | <interface name="selinux_set_parameters" lineno="303"> |
|---|
| | 44647 | <interface name="selinux_set_parameters" lineno="300"> |
|---|
| 44648 | 44648 | <summary> |
|---|
| 44649 | 44649 | Allow caller to set SELinux access vector cache parameters. |
|---|
| … | … | |
| 44667 | 44667 | <rolecap/> |
|---|
| 44668 | 44668 | </interface> |
|---|
| 44669 | | <interface name="selinux_validate_context" lineno="327"> |
|---|
| | 44669 | <interface name="selinux_validate_context" lineno="324"> |
|---|
| 44670 | 44670 | <summary> |
|---|
| 44671 | 44671 | Allows caller to validate security contexts. |
|---|
| … | … | |
| 44678 | 44678 | <rolecap/> |
|---|
| 44679 | 44679 | </interface> |
|---|
| 44680 | | <interface name="selinux_compute_access_vector" lineno="348"> |
|---|
| | 44680 | <interface name="selinux_compute_access_vector" lineno="345"> |
|---|
| 44681 | 44681 | <summary> |
|---|
| 44682 | 44682 | Allows caller to compute an access vector. |
|---|
| … | … | |
| 44689 | 44689 | <rolecap/> |
|---|
| 44690 | 44690 | </interface> |
|---|
| 44691 | | <interface name="selinux_compute_create_context" lineno="369"> |
|---|
| | 44691 | <interface name="selinux_compute_create_context" lineno="366"> |
|---|
| 44692 | 44692 | <summary> |
|---|
| 44693 | 44693 | Calculate the default type for object creation. |
|---|
| … | … | |
| 44700 | 44700 | <rolecap/> |
|---|
| 44701 | 44701 | </interface> |
|---|
| 44702 | | <interface name="selinux_compute_member" lineno="390"> |
|---|
| | 44702 | <interface name="selinux_compute_member" lineno="387"> |
|---|
| 44703 | 44703 | <summary> |
|---|
| 44704 | 44704 | Allows caller to compute polyinstatntiated |
|---|
| … | … | |
| 44711 | 44711 | </param> |
|---|
| 44712 | 44712 | </interface> |
|---|
| 44713 | | <interface name="selinux_compute_relabel_context" lineno="419"> |
|---|
| | 44713 | <interface name="selinux_compute_relabel_context" lineno="416"> |
|---|
| 44714 | 44714 | <summary> |
|---|
| 44715 | 44715 | Calculate the context for relabeling objects. |
|---|
| … | … | |
| 44730 | 44730 | </param> |
|---|
| 44731 | 44731 | </interface> |
|---|
| 44732 | | <interface name="selinux_compute_user_contexts" lineno="439"> |
|---|
| | 44732 | <interface name="selinux_compute_user_contexts" lineno="436"> |
|---|
| 44733 | 44733 | <summary> |
|---|
| 44734 | 44734 | Allows caller to compute possible contexts for a user. |
|---|
| … | … | |
| 44740 | 44740 | </param> |
|---|
| 44741 | 44741 | </interface> |
|---|
| 44742 | | <interface name="selinux_unconfined" lineno="459"> |
|---|
| | 44742 | <interface name="selinux_unconfined" lineno="456"> |
|---|
| 44743 | 44743 | <summary> |
|---|
| 44744 | 44744 | Unconfined access to the SELinux kernel security server. |
|---|
| … | … | |
| 53242 | 53242 | </param> |
|---|
| 53243 | 53243 | </template> |
|---|
| 53244 | | <template name="xserver_ro_session_template" lineno="457"> |
|---|
| | 53244 | <template name="xserver_ro_session_template" lineno="469"> |
|---|
| 53245 | 53245 | <summary> |
|---|
| 53246 | 53246 | Template for creating sessions on a |
|---|
| … | … | |
| 53266 | 53266 | </param> |
|---|
| 53267 | 53267 | </template> |
|---|
| 53268 | | <template name="xserver_rw_session_template" lineno="504"> |
|---|
| | 53268 | <template name="xserver_rw_session_template" lineno="516"> |
|---|
| 53269 | 53269 | <summary> |
|---|
| 53270 | 53270 | Template for creating sessions on a |
|---|
| … | … | |
| 53290 | 53290 | </param> |
|---|
| 53291 | 53291 | </template> |
|---|
| 53292 | | <template name="xserver_user_client_template" lineno="536"> |
|---|
| | 53292 | <template name="xserver_user_client_template" lineno="548"> |
|---|
| 53293 | 53293 | <summary> |
|---|
| 53294 | 53294 | Template for creating full client sessions |
|---|
| … | … | |
| 53312 | 53312 | </param> |
|---|
| 53313 | 53313 | </template> |
|---|
| 53314 | | <template name="xserver_use_user_fonts" lineno="607"> |
|---|
| | 53314 | <template name="xserver_use_user_fonts" lineno="619"> |
|---|
| 53315 | 53315 | <summary> |
|---|
| 53316 | 53316 | Read user fonts, user font configuration, |
|---|
| … | … | |
| 53339 | 53339 | </param> |
|---|
| 53340 | 53340 | </template> |
|---|
| 53341 | | <template name="xserver_domtrans_user_xauth" lineno="652"> |
|---|
| | 53341 | <template name="xserver_domtrans_user_xauth" lineno="664"> |
|---|
| 53342 | 53342 | <summary> |
|---|
| 53343 | 53343 | Transition to a user Xauthority domain. |
|---|
| … | … | |
| 53364 | 53364 | </param> |
|---|
| 53365 | 53365 | </template> |
|---|
| 53366 | | <template name="xserver_user_home_dir_filetrans_user_xauth" lineno="685"> |
|---|
| | 53366 | <template name="xserver_user_home_dir_filetrans_user_xauth" lineno="697"> |
|---|
| 53367 | 53367 | <summary> |
|---|
| 53368 | 53368 | Transition to a user Xauthority domain. |
|---|
| … | … | |
| 53389 | 53389 | </param> |
|---|
| 53390 | 53390 | </template> |
|---|
| 53391 | | <interface name="xserver_use_all_users_fonts" lineno="704"> |
|---|
| | 53391 | <interface name="xserver_use_all_users_fonts" lineno="716"> |
|---|
| 53392 | 53392 | <summary> |
|---|
| 53393 | 53393 | Read all users fonts, user font configurations, |
|---|
| … | … | |
| 53400 | 53400 | </param> |
|---|
| 53401 | 53401 | </interface> |
|---|
| 53402 | | <interface name="xserver_read_all_users_xauth" lineno="734"> |
|---|
| | 53402 | <interface name="xserver_read_all_users_xauth" lineno="746"> |
|---|
| 53403 | 53403 | <summary> |
|---|
| 53404 | 53404 | Read all users .Xauthority. |
|---|
| … | … | |
| 53410 | 53410 | </param> |
|---|
| 53411 | 53411 | </interface> |
|---|
| 53412 | | <interface name="xserver_setattr_console_pipes" lineno="753"> |
|---|
| | 53412 | <interface name="xserver_setattr_console_pipes" lineno="765"> |
|---|
| 53413 | 53413 | <summary> |
|---|
| 53414 | 53414 | Set the attributes of the X windows console named pipes. |
|---|
| … | … | |
| 53420 | 53420 | </param> |
|---|
| 53421 | 53421 | </interface> |
|---|
| 53422 | | <interface name="xserver_rw_console" lineno="771"> |
|---|
| | 53422 | <interface name="xserver_rw_console" lineno="783"> |
|---|
| 53423 | 53423 | <summary> |
|---|
| 53424 | 53424 | Read and write the X windows console named pipe. |
|---|
| … | … | |
| 53430 | 53430 | </param> |
|---|
| 53431 | 53431 | </interface> |
|---|
| 53432 | | <interface name="xserver_use_xdm_fds" lineno="789"> |
|---|
| | 53432 | <interface name="xserver_use_xdm_fds" lineno="801"> |
|---|
| 53433 | 53433 | <summary> |
|---|
| 53434 | 53434 | Use file descriptors for xdm. |
|---|
| … | … | |
| 53440 | 53440 | </param> |
|---|
| 53441 | 53441 | </interface> |
|---|
| 53442 | | <interface name="xserver_dontaudit_use_xdm_fds" lineno="808"> |
|---|
| | 53442 | <interface name="xserver_dontaudit_use_xdm_fds" lineno="820"> |
|---|
| 53443 | 53443 | <summary> |
|---|
| 53444 | 53444 | Do not audit attempts to inherit |
|---|
| … | … | |
| 53451 | 53451 | </param> |
|---|
| 53452 | 53452 | </interface> |
|---|
| 53453 | | <interface name="xserver_rw_xdm_pipes" lineno="826"> |
|---|
| | 53453 | <interface name="xserver_rw_xdm_pipes" lineno="838"> |
|---|
| 53454 | 53454 | <summary> |
|---|
| 53455 | 53455 | Read and write XDM unnamed pipes. |
|---|
| … | … | |
| 53461 | 53461 | </param> |
|---|
| 53462 | 53462 | </interface> |
|---|
| 53463 | | <interface name="xserver_dontaudit_rw_xdm_pipes" lineno="845"> |
|---|
| | 53463 | <interface name="xserver_dontaudit_rw_xdm_pipes" lineno="857"> |
|---|
| 53464 | 53464 | <summary> |
|---|
| 53465 | 53465 | Do not audit attempts to read and write |
|---|
| … | … | |
| 53472 | 53472 | </param> |
|---|
| 53473 | 53473 | </interface> |
|---|
| 53474 | | <interface name="xserver_stream_connect_xdm" lineno="865"> |
|---|
| | 53474 | <interface name="xserver_stream_connect_xdm" lineno="877"> |
|---|
| 53475 | 53475 | <summary> |
|---|
| 53476 | 53476 | Connect to XDM over a unix domain |
|---|
| … | … | |
| 53483 | 53483 | </param> |
|---|
| 53484 | 53484 | </interface> |
|---|
| 53485 | | <interface name="xserver_read_xdm_rw_config" lineno="884"> |
|---|
| | 53485 | <interface name="xserver_read_xdm_rw_config" lineno="896"> |
|---|
| 53486 | 53486 | <summary> |
|---|
| 53487 | 53487 | Read xdm-writable configuration files. |
|---|
| … | … | |
| 53493 | 53493 | </param> |
|---|
| 53494 | 53494 | </interface> |
|---|
| 53495 | | <interface name="xserver_setattr_xdm_tmp_dirs" lineno="903"> |
|---|
| | 53495 | <interface name="xserver_setattr_xdm_tmp_dirs" lineno="915"> |
|---|
| 53496 | 53496 | <summary> |
|---|
| 53497 | 53497 | Set the attributes of XDM temporary directories. |
|---|
| … | … | |
| 53503 | 53503 | </param> |
|---|
| 53504 | 53504 | </interface> |
|---|
| 53505 | | <interface name="xserver_create_xdm_tmp_sockets" lineno="922"> |
|---|
| | 53505 | <interface name="xserver_create_xdm_tmp_sockets" lineno="934"> |
|---|
| 53506 | 53506 | <summary> |
|---|
| 53507 | 53507 | Create a named socket in a XDM |
|---|
| … | … | |
| 53514 | 53514 | </param> |
|---|
| 53515 | 53515 | </interface> |
|---|
| 53516 | | <interface name="xserver_read_xdm_pid" lineno="942"> |
|---|
| | 53516 | <interface name="xserver_read_xdm_pid" lineno="954"> |
|---|
| 53517 | 53517 | <summary> |
|---|
| 53518 | 53518 | Read XDM pid files. |
|---|
| … | … | |
| 53524 | 53524 | </param> |
|---|
| 53525 | 53525 | </interface> |
|---|
| 53526 | | <interface name="xserver_read_xdm_lib_files" lineno="961"> |
|---|
| | 53526 | <interface name="xserver_read_xdm_lib_files" lineno="973"> |
|---|
| 53527 | 53527 | <summary> |
|---|
| 53528 | 53528 | Read XDM var lib files. |
|---|
| … | … | |
| 53534 | 53534 | </param> |
|---|
| 53535 | 53535 | </interface> |
|---|
| 53536 | | <interface name="xserver_domtrans_xdm_xserver" lineno="979"> |
|---|
| | 53536 | <interface name="xserver_domtrans_xdm_xserver" lineno="991"> |
|---|
| 53537 | 53537 | <summary> |
|---|
| 53538 | 53538 | Execute the X server in the XDM X server domain. |
|---|
| … | … | |
| 53544 | 53544 | </param> |
|---|
| 53545 | 53545 | </interface> |
|---|
| 53546 | | <interface name="xserver_xsession_entry_type" lineno="998"> |
|---|
| | 53546 | <interface name="xserver_xsession_entry_type" lineno="1010"> |
|---|
| 53547 | 53547 | <summary> |
|---|
| 53548 | 53548 | Make an X session script an entrypoint for the specified domain. |
|---|
| … | … | |
| 53554 | 53554 | </param> |
|---|
| 53555 | 53555 | </interface> |
|---|
| 53556 | | <interface name="xserver_xsession_spec_domtrans" lineno="1035"> |
|---|
| | 53556 | <interface name="xserver_xsession_spec_domtrans" lineno="1047"> |
|---|
| 53557 | 53557 | <summary> |
|---|
| 53558 | 53558 | Execute an X session in the target domain. This |
|---|
| … | … | |
| 53583 | 53583 | </param> |
|---|
| 53584 | 53584 | </interface> |
|---|
| 53585 | | <interface name="xserver_getattr_log" lineno="1053"> |
|---|
| | 53585 | <interface name="xserver_getattr_log" lineno="1065"> |
|---|
| 53586 | 53586 | <summary> |
|---|
| 53587 | 53587 | Get the attributes of X server logs. |
|---|
| … | … | |
| 53593 | 53593 | </param> |
|---|
| 53594 | 53594 | </interface> |
|---|
| 53595 | | <interface name="xserver_dontaudit_write_log" lineno="1073"> |
|---|
| | 53595 | <interface name="xserver_dontaudit_write_log" lineno="1085"> |
|---|
| 53596 | 53596 | <summary> |
|---|
| 53597 | 53597 | Do not audit attempts to write the X server |
|---|
| … | … | |
| 53604 | 53604 | </param> |
|---|
| 53605 | 53605 | </interface> |
|---|
| 53606 | | <interface name="xserver_delete_log" lineno="1092"> |
|---|
| | 53606 | <interface name="xserver_delete_log" lineno="1104"> |
|---|
| 53607 | 53607 | <summary> |
|---|
| 53608 | 53608 | Do not audit attempts to write the X server |
|---|
| … | … | |
| 53615 | 53615 | </param> |
|---|
| 53616 | 53616 | </interface> |
|---|
| 53617 | | <interface name="xserver_read_xkb_libs" lineno="1113"> |
|---|
| | 53617 | <interface name="xserver_read_xkb_libs" lineno="1125"> |
|---|
| 53618 | 53618 | <summary> |
|---|
| 53619 | 53619 | Read X keyboard extension libraries. |
|---|
| … | … | |
| 53625 | 53625 | </param> |
|---|
| 53626 | 53626 | </interface> |
|---|
| 53627 | | <interface name="xserver_read_xdm_xserver_tmp_files" lineno="1134"> |
|---|
| | 53627 | <interface name="xserver_read_xdm_xserver_tmp_files" lineno="1146"> |
|---|
| 53628 | 53628 | <summary> |
|---|
| 53629 | 53629 | Read xdm temporary files. |
|---|
| … | … | |
| 53635 | 53635 | </param> |
|---|
| 53636 | 53636 | </interface> |
|---|
| 53637 | | <interface name="xserver_read_xdm_tmp_files" lineno="1152"> |
|---|
| | 53637 | <interface name="xserver_read_xdm_tmp_files" lineno="1164"> |
|---|
| 53638 | 53638 | <summary> |
|---|
| 53639 | 53639 | Read xdm temporary files. |
|---|
| … | … | |
| 53645 | 53645 | </param> |
|---|
| 53646 | 53646 | </interface> |
|---|
| 53647 | | <interface name="xserver_dontaudit_read_xdm_tmp_files" lineno="1171"> |
|---|
| | 53647 | <interface name="xserver_dontaudit_read_xdm_tmp_files" lineno="1183"> |
|---|
| 53648 | 53648 | <summary> |
|---|
| 53649 | 53649 | Do not audit attempts to read xdm temporary files. |
|---|
| … | … | |
| 53655 | 53655 | </param> |
|---|
| 53656 | 53656 | </interface> |
|---|
| 53657 | | <interface name="xserver_rw_xdm_tmp_files" lineno="1190"> |
|---|
| | 53657 | <interface name="xserver_rw_xdm_tmp_files" lineno="1202"> |
|---|
| 53658 | 53658 | <summary> |
|---|
| 53659 | 53659 | Read write xdm temporary files. |
|---|
| … | … | |
| 53665 | 53665 | </param> |
|---|
| 53666 | 53666 | </interface> |
|---|
| 53667 | | <interface name="xserver_manage_xdm_tmp_files" lineno="1209"> |
|---|
| | 53667 | <interface name="xserver_manage_xdm_tmp_files" lineno="1221"> |
|---|
| 53668 | 53668 | <summary> |
|---|
| 53669 | 53669 | Create, read, write, and delete xdm temporary files. |
|---|
| … | … | |
| 53675 | 53675 | </param> |
|---|
| 53676 | 53676 | </interface> |
|---|
| 53677 | | <interface name="xserver_dontaudit_getattr_xdm_tmp_sockets" lineno="1227"> |
|---|
| | 53677 | <interface name="xserver_dontaudit_getattr_xdm_tmp_sockets" lineno="1239"> |
|---|
| 53678 | 53678 | <summary> |
|---|
| 53679 | 53679 | dontaudit getattr xdm temporary named sockets. |
|---|
| … | … | |
| 53685 | 53685 | </param> |
|---|
| 53686 | 53686 | </interface> |
|---|
| 53687 | | <interface name="xserver_signal_xdm_xserver" lineno="1245"> |
|---|
| | 53687 | <interface name="xserver_signal_xdm_xserver" lineno="1257"> |
|---|
| 53688 | 53688 | <summary> |
|---|
| 53689 | 53689 | Signal XDM X servers |
|---|
| … | … | |
| 53695 | 53695 | </param> |
|---|
| 53696 | 53696 | </interface> |
|---|
| 53697 | | <interface name="xserver_kill_xdm_xserver" lineno="1263"> |
|---|
| | 53697 | <interface name="xserver_kill_xdm_xserver" lineno="1275"> |
|---|
| 53698 | 53698 | <summary> |
|---|
| 53699 | 53699 | Kill XDM X servers |
|---|
| … | … | |
| 53705 | 53705 | </param> |
|---|
| 53706 | 53706 | </interface> |
|---|
| 53707 | | <interface name="xserver_dontaudit_rw_xdm_xserver_tcp_sockets" lineno="1282"> |
|---|
| | 53707 | <interface name="xserver_dontaudit_rw_xdm_xserver_tcp_sockets" lineno="1294"> |
|---|
| 53708 | 53708 | <summary> |
|---|
| 53709 | 53709 | Do not audit attempts to read and write to |
|---|
| … | … | |
| 53716 | 53716 | </param> |
|---|
| 53717 | 53717 | </interface> |
|---|
| 53718 | | <interface name="xserver_dontaudit_rw_xdm_stream_sockets" lineno="1301"> |
|---|
| | 53718 | <interface name="xserver_dontaudit_rw_xdm_stream_sockets" lineno="1313"> |
|---|
| 53719 | 53719 | <summary> |
|---|
| 53720 | 53720 | Do not audit attempts to read and write xdm_xserver |
|---|
| … | … | |
| 53727 | 53727 | </param> |
|---|
| 53728 | 53728 | </interface> |
|---|
| 53729 | | <interface name="xserver_stream_connect_xdm_xserver" lineno="1320"> |
|---|
| | 53729 | <interface name="xserver_stream_connect_xdm_xserver" lineno="1332"> |
|---|
| 53730 | 53730 | <summary> |
|---|
| 53731 | 53731 | Connect to xdm_xserver over a unix domain |
|---|
| … | … | |
| 57128 | 57128 | </param> |
|---|
| 57129 | 57129 | </interface> |
|---|
| 57130 | | <interface name="modutils_run_insmod" lineno="132"> |
|---|
| | 57130 | <interface name="modutils_run_insmod" lineno="128"> |
|---|
| 57131 | 57131 | <summary> |
|---|
| 57132 | 57132 | Execute insmod in the insmod domain, and |
|---|
| … | … | |
| 57152 | 57152 | <rolecap/> |
|---|
| 57153 | 57153 | </interface> |
|---|
| 57154 | | <interface name="modutils_exec_insmod" lineno="152"> |
|---|
| | 57154 | <interface name="modutils_exec_insmod" lineno="148"> |
|---|
| 57155 | 57155 | <summary> |
|---|
| 57156 | 57156 | Execute insmod in the caller domain. |
|---|
| … | … | |
| 57162 | 57162 | </param> |
|---|
| 57163 | 57163 | </interface> |
|---|
| 57164 | | <interface name="modutils_domtrans_depmod" lineno="171"> |
|---|
| | 57164 | <interface name="modutils_domtrans_depmod" lineno="167"> |
|---|
| 57165 | 57165 | <summary> |
|---|
| 57166 | 57166 | Execute depmod in the depmod domain. |
|---|
| … | … | |
| 57172 | 57172 | </param> |
|---|
| 57173 | 57173 | </interface> |
|---|
| 57174 | | <interface name="modutils_run_depmod" lineno="201"> |
|---|
| | 57174 | <interface name="modutils_run_depmod" lineno="197"> |
|---|
| 57175 | 57175 | <summary> |
|---|
| 57176 | 57176 | Execute depmod in the depmod domain. |
|---|
| … | … | |
| 57193 | 57193 | <rolecap/> |
|---|
| 57194 | 57194 | </interface> |
|---|
| 57195 | | <interface name="modutils_exec_depmod" lineno="221"> |
|---|
| | 57195 | <interface name="modutils_exec_depmod" lineno="217"> |
|---|
| 57196 | 57196 | <summary> |
|---|
| 57197 | 57197 | Execute depmod in the caller domain. |
|---|
| … | … | |
| 57203 | 57203 | </param> |
|---|
| 57204 | 57204 | </interface> |
|---|
| 57205 | | <interface name="modutils_domtrans_update_mods" lineno="240"> |
|---|
| | 57205 | <interface name="modutils_domtrans_update_mods" lineno="236"> |
|---|
| 57206 | 57206 | <summary> |
|---|
| 57207 | 57207 | Execute depmod in the depmod domain. |
|---|
| … | … | |
| 57213 | 57213 | </param> |
|---|
| 57214 | 57214 | </interface> |
|---|
| 57215 | | <interface name="modutils_run_update_mods" lineno="270"> |
|---|
| | 57215 | <interface name="modutils_run_update_mods" lineno="266"> |
|---|
| 57216 | 57216 | <summary> |
|---|
| 57217 | 57217 | Execute update_modules in the update_modules domain. |
|---|
| … | … | |
| 57234 | 57234 | <rolecap/> |
|---|
| 57235 | 57235 | </interface> |
|---|
| 57236 | | <interface name="modutils_exec_update_mods" lineno="290"> |
|---|
| | 57236 | <interface name="modutils_exec_update_mods" lineno="286"> |
|---|
| 57237 | 57237 | <summary> |
|---|
| 57238 | 57238 | Execute update_modules in the caller domain. |
|---|
| … | … | |
| 62377 | 62377 | </desc> |
|---|
| 62378 | 62378 | </tunable> |
|---|
| | 62379 | <tunable name="spamd_enable_home_dirs" dftval="false"> |
|---|
| | 62380 | <desc> |
|---|
| | 62381 | <p> |
|---|
| | 62382 | Allow applications to write untrusted content |
|---|
| | 62383 | </p> |
|---|
| | 62384 | </desc> |
|---|
| | 62385 | </tunable> |
|---|
| | 62386 | <tunable name="spamassassin_can_network" dftval="false"> |
|---|
| | 62387 | <desc> |
|---|
| | 62388 | <p> |
|---|
| | 62389 | Allow applications to write untrusted content |
|---|
| | 62390 | </p> |
|---|
| | 62391 | </desc> |
|---|
| | 62392 | </tunable> |
|---|
| | 62393 | <tunable name="samba_enable_home_dirs" dftval="false"> |
|---|
| | 62394 | <desc> |
|---|
| | 62395 | <p> |
|---|
| | 62396 | Allow applications to write untrusted content |
|---|
| | 62397 | </p> |
|---|
| | 62398 | </desc> |
|---|
| | 62399 | </tunable> |
|---|
| | 62400 | <tunable name="pppd_for_user" dftval="false"> |
|---|
| | 62401 | <desc> |
|---|
| | 62402 | <p> |
|---|
| | 62403 | Allow applications to write untrusted content |
|---|
| | 62404 | </p> |
|---|
| | 62405 | </desc> |
|---|
| | 62406 | </tunable> |
|---|
| | 62407 | <tunable name="allow_kerberos" dftval="false"> |
|---|
| | 62408 | <desc> |
|---|
| | 62409 | <p> |
|---|
| | 62410 | Allow applications to write untrusted content |
|---|
| | 62411 | </p> |
|---|
| | 62412 | </desc> |
|---|
| | 62413 | </tunable> |
|---|
| 62379 | 62414 | <bool name="secure_mode" dftval="false"> |
|---|
| 62380 | 62415 | <desc> |
|---|
| r153 |
r156 |
|
| 435 | 435 | write_untrusted_content = false |
|---|
| 436 | 436 | |
|---|
| | 437 | # |
|---|
| | 438 | # Allow applications to write untrusted content |
|---|
| | 439 | # |
|---|
| | 440 | spamd_enable_home_dirs = true |
|---|
| | 441 | |
|---|
| | 442 | # |
|---|
| | 443 | # Allow applications to write untrusted content |
|---|
| | 444 | # |
|---|
| | 445 | spamassassin_can_network = false |
|---|
| | 446 | |
|---|
| | 447 | # |
|---|
| | 448 | # Allow applications to write untrusted content |
|---|
| | 449 | # |
|---|
| | 450 | samba_enable_home_dirs = false |
|---|
| | 451 | |
|---|
| | 452 | # |
|---|
| | 453 | # Allow applications to write untrusted content |
|---|
| | 454 | # |
|---|
| | 455 | pppd_for_user = false |
|---|
| | 456 | |
|---|
| | 457 | # |
|---|
| | 458 | # Allow applications to write untrusted content |
|---|
| | 459 | # |
|---|
| | 460 | allow_kerberos = false |
|---|
| | 461 | |
|---|
| r153 |
r156 |
|
| 133 | 133 | ## </desc> |
|---|
| 134 | 134 | gen_tunable(write_untrusted_content,false) |
|---|
| | 135 | |
|---|
| | 136 | ## <desc> |
|---|
| | 137 | ## <p> |
|---|
| | 138 | ## Allow applications to write untrusted content |
|---|
| | 139 | ## </p> |
|---|
| | 140 | ## </desc> |
|---|
| | 141 | gen_tunable(spamd_enable_home_dirs, false) |
|---|
| | 142 | |
|---|
| | 143 | ## <desc> |
|---|
| | 144 | ## <p> |
|---|
| | 145 | ## Allow applications to write untrusted content |
|---|
| | 146 | ## </p> |
|---|
| | 147 | ## </desc> |
|---|
| | 148 | gen_tunable(spamassassin_can_network, false) |
|---|
| | 149 | |
|---|
| | 150 | ## <desc> |
|---|
| | 151 | ## <p> |
|---|
| | 152 | ## Allow applications to write untrusted content |
|---|
| | 153 | ## </p> |
|---|
| | 154 | ## </desc> |
|---|
| | 155 | gen_tunable(samba_enable_home_dirs, false) |
|---|
| | 156 | |
|---|
| | 157 | ## <desc> |
|---|
| | 158 | ## <p> |
|---|
| | 159 | ## Allow applications to write untrusted content |
|---|
| | 160 | ## </p> |
|---|
| | 161 | ## </desc> |
|---|
| | 162 | gen_tunable(pppd_for_user, false) |
|---|
| | 163 | |
|---|
| | 164 | ## <desc> |
|---|
| | 165 | ## <p> |
|---|
| | 166 | ## Allow applications to write untrusted content |
|---|
| | 167 | ## </p> |
|---|
| | 168 | ## </desc> |
|---|
| | 169 | gen_tunable(allow_kerberos, false) |
|---|
| | 170 | |
|---|
| r153 |
r156 |
|
| 180 | 180 | gen_require(` |
|---|
| 181 | 181 | type ping_t; |
|---|
| 182 | | bool user_ping; |
|---|
| 183 | 182 | ') |
|---|
| 184 | 183 | |
|---|
| … | … | |
| 284 | 283 | gen_require(` |
|---|
| 285 | 284 | type traceroute_t; |
|---|
| 286 | | bool user_ping; |
|---|
| 287 | 285 | ') |
|---|
| 288 | 286 | |
|---|
| r153 |
r156 |
|
| 164 | 164 | attribute su_domain_type; |
|---|
| 165 | 165 | type su_exec_t; |
|---|
| 166 | | bool secure_mode; |
|---|
| 167 | 166 | ') |
|---|
| 168 | 167 | |
|---|
| r153 |
r156 |
|
| 190 | 190 | type security_t; |
|---|
| 191 | 191 | attribute can_setenforce; |
|---|
| 192 | | bool secure_mode_policyload; |
|---|
| 193 | 192 | ') |
|---|
| 194 | 193 | |
|---|
| … | … | |
| 221 | 220 | type security_t; |
|---|
| 222 | 221 | attribute can_load_policy; |
|---|
| 223 | | bool secure_mode_policyload; |
|---|
| 224 | 222 | ') |
|---|
| 225 | 223 | |
|---|
| … | … | |
| 263 | 261 | gen_require(` |
|---|
| 264 | 262 | type security_t; |
|---|
| 265 | | bool secure_mode_policyload; |
|---|
| 266 | 263 | ') |
|---|
| 267 | 264 | |
|---|
| r153 |
r156 |
|
| 97 | 97 | # |
|---|
| 98 | 98 | interface(`modutils_domtrans_insmod',` |
|---|
| 99 | | gen_require(` |
|---|
| 100 | | bool secure_mode_insmod; |
|---|
| 101 | | ') |
|---|
| 102 | | |
|---|
| 103 | 99 | if (!secure_mode_insmod) { |
|---|
| 104 | 100 | modutils_domtrans_insmod_uncond($1) |
|---|
| r153 |
r156 |
|
| 1 | 1 | |
|---|
| 2 | 2 | policy_module(modutils,1.5.1) |
|---|
| 3 | | |
|---|
| 4 | | gen_require(` |
|---|
| 5 | | bool secure_mode_insmod; |
|---|
| 6 | | ') |
|---|
| 7 | 3 | |
|---|
| 8 | 4 | ######################################## |
|---|
| r153 |
r156 |
|
| 1 | 1 | |
|---|
| 2 | 2 | policy_module(selinuxutil,1.7.1) |
|---|
| 3 | | |
|---|
| 4 | | gen_require(` |
|---|
| 5 | | bool secure_mode; |
|---|
| 6 | | ') |
|---|
| 7 | 3 | |
|---|
| 8 | 4 | ######################################## |
|---|
| r153 |
r156 |
|
| 130 | 130 | |
|---|
| 131 | 131 | define(`declare_required_symbols',` |
|---|
| 132 | | ifelse(regexp($1, `\w'), -1, `', `dnl |
|---|
| | 132 | ifelse(regexp($1, `\w'), -1, `', `dnl |
|---|
| 133 | 133 | bool regexp($1, `\(\w+\)', `\1'); |
|---|
| 134 | | declare_required_symbols(regexp($1, `\w+\(.*\)', `\1'))dnl |
|---|
| 135 | | ') dnl |
|---|
| | 134 | declare_required_symbols(regexp($1, `\w+\(.*\)', `\1'))dnl |
|---|
| | 135 | ') dnl |
|---|
| 136 | 136 | ') |
|---|
| 137 | 137 | |
|---|
Download in other formats:
* Generating other formats may take time.