Changeset 2668
- Timestamp:
- 04/29/08 08:58:34 (7 months ago)
- Files:
-
- trunk/Changelog (modified) (1 diff)
- trunk/policy/modules/admin/acct.te (modified) (2 diffs)
- trunk/policy/modules/admin/alsa.te (modified) (2 diffs)
- trunk/policy/modules/admin/amanda.te (modified) (3 diffs)
- trunk/policy/modules/admin/anaconda.te (modified) (2 diffs)
- trunk/policy/modules/admin/bootloader.te (modified) (2 diffs)
- trunk/policy/modules/admin/dmesg.te (modified) (2 diffs)
- trunk/policy/modules/admin/firstboot.te (modified) (2 diffs)
- trunk/policy/modules/admin/kudzu.te (modified) (2 diffs)
- trunk/policy/modules/admin/logrotate.te (modified) (3 diffs)
- trunk/policy/modules/admin/logwatch.te (modified) (2 diffs)
- trunk/policy/modules/admin/mrtg.te (modified) (2 diffs)
- trunk/policy/modules/admin/portage.if (modified) (1 diff)
- trunk/policy/modules/admin/portage.te (modified) (1 diff)
- trunk/policy/modules/admin/readahead.te (modified) (2 diffs)
- trunk/policy/modules/admin/usermanage.te (modified) (4 diffs)
- trunk/policy/modules/apps/calamaris.te (modified) (2 diffs)
- trunk/policy/modules/apps/games.te (modified) (2 diffs)
- trunk/policy/modules/apps/mono.te (modified) (2 diffs)
- trunk/policy/modules/apps/uml.te (modified) (2 diffs)
- trunk/policy/modules/apps/userhelper.if (modified) (1 diff)
- trunk/policy/modules/apps/userhelper.te (modified) (1 diff)
- trunk/policy/modules/apps/vmware.te (modified) (2 diffs)
- trunk/policy/modules/roles (added)
- trunk/policy/modules/roles/auditadm.fc (added)
- trunk/policy/modules/roles/auditadm.if (added)
- trunk/policy/modules/roles/auditadm.te (added)
- trunk/policy/modules/roles/metadata.xml (added)
- trunk/policy/modules/roles/secadm.fc (added)
- trunk/policy/modules/roles/secadm.if (added)
- trunk/policy/modules/roles/secadm.te (added)
- trunk/policy/modules/roles/staff.fc (added)
- trunk/policy/modules/roles/staff.if (added)
- trunk/policy/modules/roles/staff.te (added)
- trunk/policy/modules/roles/sysadm.fc (added)
- trunk/policy/modules/roles/sysadm.if (added)
- trunk/policy/modules/roles/sysadm.te (added)
- trunk/policy/modules/roles/unprivuser.fc (added)
- trunk/policy/modules/roles/unprivuser.if (added)
- trunk/policy/modules/roles/unprivuser.te (added)
- trunk/policy/modules/services/afs.te (modified) (5 diffs)
- trunk/policy/modules/services/amavis.te (modified) (3 diffs)
- trunk/policy/modules/services/apache.te (modified) (3 diffs)
- trunk/policy/modules/services/apm.te (modified) (2 diffs)
- trunk/policy/modules/services/arpwatch.te (modified) (2 diffs)
- trunk/policy/modules/services/asterisk.te (modified) (2 diffs)
- trunk/policy/modules/services/audioentropy.te (modified) (2 diffs)
- trunk/policy/modules/services/automount.te (modified) (2 diffs)
- trunk/policy/modules/services/avahi.te (modified) (2 diffs)
- trunk/policy/modules/services/bind.te (modified) (2 diffs)
- trunk/policy/modules/services/bluetooth.te (modified) (2 diffs)
- trunk/policy/modules/services/canna.te (modified) (2 diffs)
- trunk/policy/modules/services/comsat.te (modified) (2 diffs)
- trunk/policy/modules/services/courier.te (modified) (2 diffs)
- trunk/policy/modules/services/cups.te (modified) (3 diffs)
- trunk/policy/modules/services/cyrus.te (modified) (2 diffs)
- trunk/policy/modules/services/dante.te (modified) (2 diffs)
- trunk/policy/modules/services/dbus.te (modified) (2 diffs)
- trunk/policy/modules/services/dcc.te (modified) (4 diffs)
- trunk/policy/modules/services/ddclient.te (modified) (2 diffs)
- trunk/policy/modules/services/dhcp.te (modified) (2 diffs)
- trunk/policy/modules/services/distcc.te (modified) (2 diffs)
- trunk/policy/modules/services/dnsmasq.te (modified) (2 diffs)
- trunk/policy/modules/services/dovecot.te (modified) (2 diffs)
- trunk/policy/modules/services/exim.te (modified) (2 diffs)
- trunk/policy/modules/services/fetchmail.te (modified) (2 diffs)
- trunk/policy/modules/services/finger.te (modified) (2 diffs)
- trunk/policy/modules/services/ftp.te (modified) (2 diffs)
- trunk/policy/modules/services/gatekeeper.te (modified) (2 diffs)
- trunk/policy/modules/services/gpm.te (modified) (2 diffs)
- trunk/policy/modules/services/hal.te (modified) (2 diffs)
- trunk/policy/modules/services/howl.te (modified) (2 diffs)
- trunk/policy/modules/services/i18n_input.te (modified) (2 diffs)
- trunk/policy/modules/services/imaze.te (modified) (2 diffs)
- trunk/policy/modules/services/inetd.te (modified) (2 diffs)
- trunk/policy/modules/services/inn.te (modified) (2 diffs)
- trunk/policy/modules/services/ircd.te (modified) (2 diffs)
- trunk/policy/modules/services/irqbalance.te (modified) (2 diffs)
- trunk/policy/modules/services/jabber.te (modified) (2 diffs)
- trunk/policy/modules/services/kerberos.te (modified) (3 diffs)
- trunk/policy/modules/services/ldap.te (modified) (2 diffs)
- trunk/policy/modules/services/lpd.te (modified) (2 diffs)
- trunk/policy/modules/services/mailman.te (modified) (2 diffs)
- trunk/policy/modules/services/monop.te (modified) (2 diffs)
- trunk/policy/modules/services/mta.te (modified) (2 diffs)
- trunk/policy/modules/services/munin.te (modified) (2 diffs)
- trunk/policy/modules/services/mysql.te (modified) (2 diffs)
- trunk/policy/modules/services/nagios.te (modified) (2 diffs)
- trunk/policy/modules/services/nessus.te (modified) (2 diffs)
- trunk/policy/modules/services/networkmanager.te (modified) (2 diffs)
- trunk/policy/modules/services/nis.te (modified) (4 diffs)
- trunk/policy/modules/services/nscd.te (modified) (2 diffs)
- trunk/policy/modules/services/nsd.te (modified) (3 diffs)
- trunk/policy/modules/services/ntop.te (modified) (2 diffs)
- trunk/policy/modules/services/ntp.te (modified) (2 diffs)
- trunk/policy/modules/services/oav.te (modified) (2 diffs)
- trunk/policy/modules/services/oddjob.te (modified) (2 diffs)
- trunk/policy/modules/services/openct.te (modified) (2 diffs)
- trunk/policy/modules/services/pegasus.te (modified) (2 diffs)
- trunk/policy/modules/services/perdition.te (modified) (2 diffs)
- trunk/policy/modules/services/portmap.te (modified) (2 diffs)
- trunk/policy/modules/services/postgresql.te (modified) (2 diffs)
- trunk/policy/modules/services/postgrey.te (modified) (2 diffs)
- trunk/policy/modules/services/ppp.te (modified) (3 diffs)
- trunk/policy/modules/services/privoxy.te (modified) (2 diffs)
- trunk/policy/modules/services/procmail.te (modified) (2 diffs)
- trunk/policy/modules/services/pxe.te (modified) (2 diffs)
- trunk/policy/modules/services/pyzor.te (modified) (3 diffs)
- trunk/policy/modules/services/radius.te (modified) (2 diffs)
- trunk/policy/modules/services/radvd.te (modified) (2 diffs)
- trunk/policy/modules/services/rhgb.te (modified) (2 diffs)
- trunk/policy/modules/services/roundup.te (modified) (2 diffs)
- trunk/policy/modules/services/samba.te (modified) (6 diffs)
- trunk/policy/modules/services/sasl.te (modified) (2 diffs)
- trunk/policy/modules/services/sendmail.te (modified) (3 diffs)
- trunk/policy/modules/services/setroubleshoot.te (modified) (2 diffs)
- trunk/policy/modules/services/slrnpull.te (modified) (2 diffs)
- trunk/policy/modules/services/smartmon.te (modified) (2 diffs)
- trunk/policy/modules/services/snmp.te (modified) (2 diffs)
- trunk/policy/modules/services/snort.te (modified) (2 diffs)
- trunk/policy/modules/services/soundserver.te (modified) (2 diffs)
- trunk/policy/modules/services/spamassassin.te (modified) (2 diffs)
- trunk/policy/modules/services/speedtouch.te (modified) (2 diffs)
- trunk/policy/modules/services/squid.te (modified) (2 diffs)
- trunk/policy/modules/services/stunnel.te (modified) (2 diffs)
- trunk/policy/modules/services/sysstat.te (modified) (2 diffs)
- trunk/policy/modules/services/tftp.te (modified) (2 diffs)
- trunk/policy/modules/services/timidity.te (modified) (2 diffs)
- trunk/policy/modules/services/transproxy.te (modified) (2 diffs)
- trunk/policy/modules/services/uptime.te (modified) (2 diffs)
- trunk/policy/modules/services/uwimap.te (modified) (2 diffs)
- trunk/policy/modules/services/watchdog.te (modified) (2 diffs)
- trunk/policy/modules/services/xfs.te (modified) (2 diffs)
- trunk/policy/modules/services/xprint.te (modified) (2 diffs)
- trunk/policy/modules/services/xserver.te (modified) (3 diffs)
- trunk/policy/modules/services/zebra.te (modified) (2 diffs)
- trunk/policy/modules/system/authlogin.te (modified) (2 diffs)
- trunk/policy/modules/system/hotplug.te (modified) (2 diffs)
- trunk/policy/modules/system/init.te (modified) (3 diffs)
- trunk/policy/modules/system/ipsec.te (modified) (3 diffs)
- trunk/policy/modules/system/locallogin.te (modified) (2 diffs)
- trunk/policy/modules/system/logging.te (modified) (4 diffs)
- trunk/policy/modules/system/lvm.te (modified) (2 diffs)
- trunk/policy/modules/system/modutils.te (modified) (3 diffs)
- trunk/policy/modules/system/pcmcia.te (modified) (2 diffs)
- trunk/policy/modules/system/raid.te (modified) (2 diffs)
- trunk/policy/modules/system/selinuxutil.te (modified) (2 diffs)
- trunk/policy/modules/system/sysnetwork.te (modified) (2 diffs)
- trunk/policy/modules/system/userdomain.if (modified) (55 diffs)
- trunk/policy/modules/system/userdomain.te (modified) (3 diffs)
- trunk/policy/modules/system/xen.te (modified) (2 diffs)
Legend:
- Unmodified
- Added
- Removed
- Modified
- Copied
- Moved
trunk/Changelog
r2664 r2668 1 - Move user roles into individual modules. 1 2 - Make hald_log_t a log file. 2 3 - Cryptsetup runs shell scripts. Patch from Martin Orr. trunk/policy/modules/admin/acct.te
r2553 r2668 1 1 2 policy_module(acct,1.1. 0)2 policy_module(acct,1.1.1) 3 3 4 4 ######################################## … … 67 67 miscfiles_read_localization(acct_t) 68 68 69 userdom_dontaudit_search_sysadm_home_dirs(acct_t)70 69 userdom_dontaudit_use_unpriv_user_fds(acct_t) 70 71 sysadm_dontaudit_search_home_dirs(acct_t) 71 72 72 73 optional_policy(` trunk/policy/modules/admin/alsa.te
r2656 r2668 1 1 2 policy_module(alsa,1.4. 0)2 policy_module(alsa,1.4.1) 3 3 4 4 ######################################## … … 61 61 userdom_manage_unpriv_user_semaphores(alsa_t) 62 62 userdom_manage_unpriv_user_shared_mem(alsa_t) 63 userdom_search_generic_user_home_dirs(alsa_t) 64 userdom_dontaudit_search_sysadm_home_dirs(alsa_t) 63 64 sysadm_dontaudit_search_home_dirs(alsa_t) 65 66 unprivuser_search_home_dirs(alsa_t) 65 67 66 68 optional_policy(` trunk/policy/modules/admin/amanda.te
r2553 r2668 1 1 2 policy_module(amanda,1.8. 0)2 policy_module(amanda,1.8.1) 3 3 4 4 ####################################### … … 182 182 manage_fifo_files_pattern(amanda_recover_t,amanda_recover_dir_t,amanda_recover_dir_t) 183 183 manage_sock_files_pattern(amanda_recover_t,amanda_recover_dir_t,amanda_recover_dir_t) 184 userdom_sysadm_home_dir_filetrans(amanda_recover_t,amanda_recover_dir_t,{ dir file lnk_file sock_file fifo_file })184 sysadm_home_dir_filetrans(amanda_recover_t,amanda_recover_dir_t,{ dir file lnk_file sock_file fifo_file }) 185 185 186 186 manage_dirs_pattern(amanda_recover_t,amanda_tmp_t,amanda_tmp_t) … … 229 229 miscfiles_read_localization(amanda_recover_t) 230 230 231 userdom_search_sysadm_home_content_dirs(amanda_recover_t)231 sysadm_search_home_content_dirs(amanda_recover_t) trunk/policy/modules/admin/anaconda.te
r2170 r2668 1 1 2 policy_module(anaconda,1.2. 0)2 policy_module(anaconda,1.2.1) 3 3 4 4 ######################################## … … 35 35 unconfined_domain(anaconda_t) 36 36 37 u serdom_generic_user_home_dir_filetrans_generic_user_home_content(anaconda_t,{ dir file lnk_file fifo_file sock_file })37 unprivuser_home_dir_filetrans_home_content(anaconda_t,{ dir file lnk_file fifo_file sock_file }) 38 38 39 39 optional_policy(` trunk/policy/modules/admin/bootloader.te
r2553 r2668 1 1 2 policy_module(bootloader,1.7. 0)2 policy_module(bootloader,1.7.1) 3 3 4 4 ######################################## … … 213 213 214 214 optional_policy(` 215 userdom_dontaudit_search_staff_home_dirs(bootloader_t) 216 userdom_dontaudit_search_sysadm_home_dirs(bootloader_t) 217 ') 215 staff_dontaudit_search_home_dirs(bootloader_t) 216 ') 217 218 optional_policy(` 219 sysadm_dontaudit_search_home_dirs(bootloader_t) 220 ') trunk/policy/modules/admin/dmesg.te
r2553 r2668 1 1 2 policy_module(dmesg,1.1. 0)2 policy_module(dmesg,1.1.1) 3 3 4 4 ######################################## … … 51 51 miscfiles_read_localization(dmesg_t) 52 52 53 userdom_use_sysadm_terms(dmesg_t)54 53 userdom_dontaudit_use_unpriv_user_fds(dmesg_t) 54 55 sysadm_use_terms(dmesg_t) 55 56 56 57 optional_policy(` trunk/policy/modules/admin/firstboot.te
r2553 r2668 1 1 2 policy_module(firstboot,1.6. 0)2 policy_module(firstboot,1.6.1) 3 3 4 4 gen_require(` … … 89 89 90 90 # Add/remove user home directories 91 u serdom_manage_generic_user_home_content_dirs(firstboot_t)92 u serdom_manage_generic_user_home_content_files(firstboot_t)93 u serdom_manage_generic_user_home_content_symlinks(firstboot_t)94 u serdom_manage_generic_user_home_content_pipes(firstboot_t)95 u serdom_manage_generic_user_home_content_sockets(firstboot_t)96 u serdom_home_filetrans_generic_user_home_dir(firstboot_t)97 u serdom_generic_user_home_dir_filetrans_generic_user_home_content(firstboot_t,{ dir file lnk_file fifo_file sock_file })91 unprivuser_manage_home_content_dirs(firstboot_t) 92 unprivuser_manage_home_content_files(firstboot_t) 93 unprivuser_manage_home_content_symlinks(firstboot_t) 94 unprivuser_manage_home_content_pipes(firstboot_t) 95 unprivuser_manage_home_content_sockets(firstboot_t) 96 unprivuser_home_filetrans_home_dir(firstboot_t) 97 unprivuser_home_dir_filetrans_home_content(firstboot_t, { dir file lnk_file fifo_file sock_file }) 98 98 99 99 optional_policy(` trunk/policy/modules/admin/kudzu.te
r2553 r2668 1 1 2 policy_module(kudzu,1.5. 0)2 policy_module(kudzu,1.5.1) 3 3 4 4 ######################################## … … 123 123 sysnet_read_config(kudzu_t) 124 124 125 userdom_search_sysadm_home_dirs(kudzu_t)126 125 userdom_dontaudit_use_unpriv_user_fds(kudzu_t) 126 127 sysadm_search_home_dirs(kudzu_t) 127 128 128 129 optional_policy(` trunk/policy/modules/admin/logrotate.te
r2656 r2668 1 1 2 policy_module(logrotate,1.8. 0)2 policy_module(logrotate,1.8.1) 3 3 4 4 ######################################## … … 116 116 seutil_dontaudit_read_config(logrotate_t) 117 117 118 userdom_dontaudit_search_sysadm_home_dirs(logrotate_t)119 118 userdom_use_unpriv_users_fds(logrotate_t) 120 119 … … 123 122 124 123 mta_send_mail(logrotate_t) 124 125 sysadm_dontaudit_search_home_dirs(logrotate_t) 125 126 126 127 ifdef(`distro_debian', ` trunk/policy/modules/admin/logwatch.te
r2553 r2668 1 1 2 policy_module(logwatch,1.7. 0)2 policy_module(logwatch,1.7.1) 3 3 4 4 ################################# … … 89 89 sysnet_dns_name_resolve(logwatch_t) 90 90 91 userdom_dontaudit_search_sysadm_home_dirs(logwatch_t) 92 userdom_dontaudit_getattr_sysadm_home_dirs(logwatch_t) 91 mta_send_mail(logwatch_t) 93 92 94 mta_send_mail(logwatch_t)93 sysadm_dontaudit_search_home_dirs(logwatch_t) 95 94 96 95 optional_policy(` trunk/policy/modules/admin/mrtg.te
r2553 r2668 1 1 2 policy_module(mrtg,1.3. 0)2 policy_module(mrtg,1.3.1) 3 3 4 4 ######################################## … … 116 116 117 117 userdom_dontaudit_use_unpriv_user_fds(mrtg_t) 118 userdom_use_sysadm_terms(mrtg_t) 118 119 sysadm_use_terms(mrtg_t) 119 120 120 121 ifdef(`enable_mls',` trunk/policy/modules/admin/portage.if
r2449 r2668 273 273 sysnet_dns_name_resolve($1) 274 274 275 userdom_dontaudit_read_sysadm_home_content_files($1)275 sysadm_dontaudit_read_home_content_files($1) 276 276 277 277 ifdef(`hide_broken_symptoms',` trunk/policy/modules/admin/portage.te
r2553 r2668 1 1 2 policy_module(portage,1.5. 0)2 policy_module(portage,1.5.1) 3 3 4 4 ######################################## trunk/policy/modules/admin/readahead.te
r2553 r2668 1 1 2 policy_module(readahead,1.5. 0)2 policy_module(readahead,1.5.1) 3 3 4 4 ######################################## … … 80 80 81 81 userdom_dontaudit_use_unpriv_user_fds(readahead_t) 82 userdom_dontaudit_search_sysadm_home_dirs(readahead_t) 82 83 sysadm_dontaudit_search_home_dirs(readahead_t) 83 84 84 85 optional_policy(` trunk/policy/modules/admin/usermanage.te
r2656 r2668 1 1 2 policy_module(usermanage,1.10. 0)2 policy_module(usermanage,1.10.1) 3 3 4 4 ######################################## … … 160 160 logging_send_syslog_msg(crack_t) 161 161 162 userdom_dontaudit_search_sysadm_home_dirs(crack_t)162 sysadm_dontaudit_search_home_dirs(crack_t) 163 163 164 164 ifdef(`distro_debian',` … … 237 237 238 238 userdom_use_unpriv_users_fds(groupadd_t) 239 239 240 # for when /root is the cwd 240 userdom_dontaudit_search_sysadm_home_dirs(groupadd_t)241 sysadm_dontaudit_search_home_dirs(groupadd_t) 241 242 242 243 optional_policy(` … … 502 503 503 504 userdom_use_unpriv_users_fds(useradd_t) 504 # for when /root is the cwd505 userdom_dontaudit_search_sysadm_home_dirs(useradd_t)506 505 # Add/remove user home directories 507 userdom_home_filetrans_generic_user_home_dir(useradd_t)508 506 userdom_manage_all_users_home_content_dirs(useradd_t) 509 507 userdom_manage_all_users_home_content_files(useradd_t) 510 userdom_generic_user_home_dir_filetrans_generic_user_home_content(useradd_t,notdevfile_class_set) 508 unprivuser_home_filetrans_home_dir(useradd_t) 509 unprivuser_home_dir_filetrans_home_content(useradd_t,notdevfile_class_set) 511 510 512 511 mta_manage_spool(useradd_t) trunk/policy/modules/apps/calamaris.te
r2360 r2668 1 1 2 policy_module(calamaris,1.2. 0)2 policy_module(calamaris,1.2.1) 3 3 4 4 ######################################## … … 68 68 sysnet_read_config(calamaris_t) 69 69 70 userdom_dontaudit_list_sysadm_home_dirs(calamaris_t)70 sysadm_dontaudit_list_home_dirs(calamaris_t) 71 71 72 72 squid_read_log(calamaris_t) trunk/policy/modules/apps/games.te
r2656 r2668 1 1 2 policy_module(games,1.6. 0)2 policy_module(games,1.6.1) 3 3 4 4 ######################################## … … 59 59 60 60 userdom_dontaudit_use_unpriv_user_fds(games_t) 61 userdom_dontaudit_search_sysadm_home_dirs(games_t) 61 62 sysadm_dontaudit_search_home_dirs(games_t) 62 63 63 64 optional_policy(` trunk/policy/modules/apps/mono.te
r2553 r2668 1 1 2 policy_module(mono,1.4. 0)2 policy_module(mono,1.4.1) 3 3 4 4 ######################################## … … 18 18 allow mono_t self:process { execheap execmem }; 19 19 20 u serdom_generic_user_home_dir_filetrans_generic_user_home_content(mono_t,{ dir file lnk_file fifo_file sock_file })20 unprivuser_home_dir_filetrans_home_content(mono_t,{ dir file lnk_file fifo_file sock_file }) 21 21 22 22 init_dbus_chat_script(mono_t) trunk/policy/modules/apps/uml.te
r2553 r2668 1 1 2 policy_module(uml,1.5. 0)2 policy_module(uml,1.5.1) 3 3 4 4 ######################################## … … 58 58 59 59 userdom_dontaudit_use_unpriv_user_fds(uml_switch_t) 60 userdom_dontaudit_search_sysadm_home_dirs(uml_switch_t) 60 61 sysadm_dontaudit_search_home_dirs(uml_switch_t) 61 62 62 63 optional_policy(` trunk/policy/modules/apps/userhelper.if
r2659 r2668 162 162 tunable_policy(`! secure_mode',` 163 163 #if we are not in secure mode then we can transition to sysadm_t 164 userdom_bin_spec_domtrans_sysadm($1_userhelper_t)165 userdom_entry_spec_domtrans_sysadm($1_userhelper_t)164 sysadm_bin_spec_domtrans($1_userhelper_t) 165 sysadm_entry_spec_domtrans($1_userhelper_t) 166 166 ') 167 167 trunk/policy/modules/apps/userhelper.te
r2431 r2668 1 1 2 policy_module(userhelper,1.3. 0)2 policy_module(userhelper,1.3.1) 3 3 4 4 ######################################## trunk/policy/modules/apps/vmware.te
r2656 r2668 1 1 2 policy_module(vmware,1.5. 0)2 policy_module(vmware,1.5.1) 3 3 4 4 ######################################## … … 88 88 89 89 userdom_dontaudit_use_unpriv_user_fds(vmware_host_t) 90 userdom_dontaudit_search_sysadm_home_dirs(vmware_host_t) 90 91 sysadm_dontaudit_search_home_dirs(vmware_host_t) 91 92 92 93 optional_policy(` trunk/policy/modules/services/afs.te
r2360 r2668 1 1 2 policy_module(afs,1.2. 0)2 policy_module(afs,1.2.1) 3 3 4 4 ######################################## … … 187 187 sysnet_read_config(afs_fsserver_t) 188 188 189 userdom_dontaudit_use_sysadm_ttys(afs_fsserver_t) 190 userdom_dontaudit_use_sysadm_ptys(afs_fsserver_t) 189 sysadm_dontaudit_use_terms(afs_fsserver_t) 191 190 192 191 ######################################## … … 236 235 sysnet_read_config(afs_kaserver_t) 237 236 238 userdom_dontaudit_use_sysadm_ttys(afs_kaserver_t) 239 userdom_dontaudit_use_sysadm_ptys(afs_kaserver_t) 237 sysadm_dontaudit_use_terms(afs_kaserver_t) 240 238 241 239 ######################################## … … 278 276 sysnet_read_config(afs_ptserver_t) 279 277 280 userdom_dontaudit_use_sysadm_ttys(afs_ptserver_t) 281 userdom_dontaudit_use_sysadm_ptys(afs_ptserver_t) 278 sysadm_dontaudit_use_terms(afs_ptserver_t) 282 279 283 280 ######################################## … … 320 317 sysnet_read_config(afs_vlserver_t) 321 318 322 userdom_dontaudit_use_sysadm_ttys(afs_vlserver_t) 323 userdom_dontaudit_use_sysadm_ptys(afs_vlserver_t) 319 sysadm_dontaudit_use_terms(afs_vlserver_t) trunk/policy/modules/services/amavis.te
r2656 r2668 1 1 2 policy_module(amavis,1.6. 0)2 policy_module(amavis,1.6.1) 3 3 4 4 ######################################## … … 144 144 sysnet_use_ldap(amavis_t) 145 145 146 userdom_dontaudit_search_sysadm_home_dirs(amavis_t)147 148 146 # Cron handling 149 147 cron_use_fds(amavis_t) … … 152 150 153 151 mta_read_config(amavis_t) 152 153 sysadm_dontaudit_search_home_dirs(amavis_t) 154 154 155 155 optional_policy(` trunk/policy/modules/services/apache.te
r2553 r2668 1 1 2 policy_module(apache,1.9. 0)2 policy_module(apache,1.9.1) 3 3 4 4 # … … 420 420 term_use_controlling_term(httpd_t) 421 421 422 userdom_use_sysadm_terms(httpd_t)422 sysadm_use_terms(httpd_t) 423 423 ',` 424 userdom_dontaudit_use_sysadm_terms(httpd_t)424 sysadm_dontaudit_use_terms(httpd_t) 425 425 ') 426 426 … … 516 516 517 517 tunable_policy(`httpd_tty_comm',` 518 # cjp: this is redundant: 519 term_use_controlling_term(httpd_helper_t) 520 521 userdom_use_sysadm_terms(httpd_helper_t) 518 sysadm_use_terms(httpd_helper_t) 522 519 ') 523 520 trunk/policy/modules/services/apm.te
r2553 r2668 1 1 2 policy_module(apm,1.6. 0)2 policy_module(apm,1.6.1) 3 3 4 4 ######################################## … … 140 140 141 141 userdom_dontaudit_use_unpriv_user_fds(apmd_t) 142 userdom_dontaudit_search_sysadm_home_dirs(apmd_t)143 142 userdom_dontaudit_search_all_users_home_content(apmd_t) # Excessive? 143 144 sysadm_dontaudit_search_home_dirs(apmd_t) 144 145 145 146 ifdef(`distro_redhat',` trunk/policy/modules/services/arpwatch.te
r2553 r2668 1 1 2 policy_module(arpwatch,1.5. 0)2 policy_module(arpwatch,1.5.1) 3 3 4 4 ######################################## … … 82 82 83 83 userdom_dontaudit_use_unpriv_user_fds(arpwatch_t) 84 userdom_dontaudit_search_sysadm_home_dirs(arpwatch_t)85 84 86 85 mta_send_mail(arpwatch_t) 86 87 sysadm_dontaudit_search_home_dirs(arpwatch_t) 87 88 88 89 optional_policy(` trunk/policy/modules/services/asterisk.te
r2553 r2668 1 1 2 policy_module(asterisk,1.4. 0)2 policy_module(asterisk,1.4.1) 3 3 4 4 ######################################## … … 127 127 128 128 userdom_dontaudit_use_unpriv_user_fds(asterisk_t) 129 userdom_dontaudit_search_sysadm_home_dirs(asterisk_t) 129 130 sysadm_dontaudit_search_home_dirs(asterisk_t) 130 131 131 132 optional_policy(` trunk/policy/modules/services/audioentropy.te
r2553 r2668 1 1 2 policy_module(audio_entropy,1.3. 0)2 policy_module(audio_entropy,1.3.1) 3 3 4 4 ######################################## … … 50 50 51 51 userdom_dontaudit_use_unpriv_user_fds(entropyd_t) 52 userdom_dontaudit_search_sysadm_home_dirs(entropyd_t) 52 53 sysadm_dontaudit_search_home_dirs(entropyd_t) 53 54 54 55 optional_policy(` trunk/policy/modules/services/automount.te
r2553 r2668 1 1 2 policy_module(automount,1.8. 0)2 policy_module(automount,1.8.1) 3 3 4 4 ######################################## … … 146 146 147 147 userdom_dontaudit_use_unpriv_user_fds(automount_t) 148 userdom_dontaudit_search_sysadm_home_dirs(automount_t) 148 149 sysadm_dontaudit_search_home_dirs(automount_t) 149 150 150 151 optional_policy(` trunk/policy/modules/services/avahi.te
r2553 r2668 1 1 2 policy_module(avahi,1.8. 0)2 policy_module(avahi,1.8.1) 3 3 4 4 ######################################## … … 79 79
