Changeset 2695

Show
Ignore:
Timestamp:
05/23/08 13:22:57 (6 months ago)
Author:
pebenito
Message:

trunk: start adding open perm to obvious places.

Files:

Legend:

Unmodified
Added
Removed
Modified
Copied
Moved
  • trunk/policy/modules/admin/amanda.te

    r2668 r2695  
    9595allow amanda_t amanda_gnutarlists_t:dir rw_dir_perms; 
    9696allow amanda_t amanda_gnutarlists_t:file manage_file_perms; 
    97 allow amanda_t amanda_gnutarlists_t:lnk_file manage_file_perms; 
     97allow amanda_t amanda_gnutarlists_t:lnk_file manage_lnk_file_perms; 
    9898 
    9999manage_dirs_pattern(amanda_t,amanda_var_lib_t,amanda_var_lib_t) 
  • trunk/policy/modules/services/gpm.te

    r2668 r2695  
    4242files_pid_filetrans(gpm_t,gpm_var_run_t,file) 
    4343 
    44 allow gpm_t gpmctl_t:sock_file manage_file_perms; 
    45 allow gpm_t gpmctl_t:fifo_file manage_file_perms; 
     44allow gpm_t gpmctl_t:sock_file manage_sock_file_perms; 
     45allow gpm_t gpmctl_t:fifo_file manage_fifo_file_perms; 
    4646dev_filetrans(gpm_t,gpmctl_t,{ sock_file fifo_file }) 
    4747 
  • trunk/policy/support/obj_perm_sets.spt

    r2690 r2695  
    194194define(`rename_dir_perms',`{ getattr rename }') 
    195195define(`delete_dir_perms',`{ getattr rmdir }') 
    196 define(`manage_dir_perms',`{ create getattr setattr read write link unlink rename search add_name remove_name reparent rmdir lock ioctl }') 
     196define(`manage_dir_perms',`{ create open getattr setattr read write link unlink rename search add_name remove_name reparent rmdir lock ioctl }') 
    197197define(`relabelfrom_dir_perms',`{ getattr relabelfrom }') 
    198198define(`relabelto_dir_perms',`{ getattr relabelto }') 
     
    210210define(`write_file_perms',`{ getattr write append lock ioctl }') 
    211211define(`rw_file_perms',`{ getattr read write append ioctl lock }') 
    212 define(`create_file_perms',`{ getattr create }') 
     212define(`create_file_perms',`{ getattr create open }') 
    213213define(`rename_file_perms',`{ getattr rename }') 
    214214define(`delete_file_perms',`{ getattr unlink }') 
    215 define(`manage_file_perms',`{ create getattr setattr read write append rename link unlink ioctl lock }') 
     215define(`manage_file_perms',`{ create open getattr setattr read write append rename link unlink ioctl lock }') 
    216216define(`relabelfrom_file_perms',`{ getattr relabelfrom }') 
    217217define(`relabelto_file_perms',`{ getattr relabelto }') 
     
    244244define(`write_fifo_file_perms',`{ getattr write append lock ioctl }') 
    245245define(`rw_fifo_file_perms',`{ getattr read write append ioctl lock }') 
    246 define(`create_fifo_file_perms',`{ getattr create }') 
     246define(`create_fifo_file_perms',`{ getattr create open }') 
    247247define(`rename_fifo_file_perms',`{ getattr rename }') 
    248248define(`delete_fifo_file_perms',`{ getattr unlink }') 
    249 define(`manage_fifo_file_perms',`{ create getattr setattr read write append rename link unlink ioctl lock }') 
     249define(`manage_fifo_file_perms',`{ create open getattr setattr read write append rename link unlink ioctl lock }') 
    250250define(`relabelfrom_fifo_file_perms',`{ getattr relabelfrom }') 
    251251define(`relabelto_fifo_file_perms',`{ getattr relabelto }') 
     
    280280define(`rename_blk_file_perms',`{ getattr rename }') 
    281281define(`delete_blk_file_perms',`{ getattr unlink }') 
    282 define(`manage_blk_file_perms',`{ create getattr setattr read write append rename link unlink ioctl lock }') 
     282define(`manage_blk_file_perms',`{ create open getattr setattr read write append rename link unlink ioctl lock }') 
    283283define(`relabelfrom_blk_file_perms',`{ getattr relabelfrom }') 
    284284define(`relabelto_blk_file_perms',`{ getattr relabelto }') 
     
    297297define(`rename_chr_file_perms',`{ getattr rename }') 
    298298define(`delete_chr_file_perms',`{ getattr unlink }') 
    299 define(`manage_chr_file_perms',`{ create getattr setattr read write append rename link unlink ioctl lock }') 
     299define(`manage_chr_file_perms',`{ create open getattr setattr read write append rename link unlink ioctl lock }') 
    300300define(`relabelfrom_chr_file_perms',`{ getattr relabelfrom }') 
    301301define(`relabelto_chr_file_perms',`{ getattr relabelto }')