Changeset 2774

Show
Ignore:
Timestamp:
08/11/08 09:03:36 (4 months ago)
Author:
cpebenito
Message:

trunk: 3 patches from the fedora policy, cherry picked by David Hardeman.

Files:

Legend:

Unmodified
Added
Removed
Modified
Copied
Moved
  • trunk/policy/modules/kernel/corenetwork.te.in

    r2701 r2774  
    11 
    2 policy_module(corenetwork,1.2.16
     2policy_module(corenetwork, 1.2.17
    33 
    44######################################## 
     
    110110network_port(isakmp, udp,500,s0) 
    111111network_port(iscsi, tcp,3260,s0) 
     112network_port(isns, tcp,3205,s0, udp,3205,s0) 
    112113network_port(jabber_client, tcp,5222,s0, tcp,5223,s0) 
    113114network_port(jabber_interserver, tcp,5269,s0) 
  • trunk/policy/modules/services/qmail.te

    r2763 r2774  
    11 
    2 policy_module(qmail, 1.3.0
     2policy_module(qmail, 1.3.1
    33 
    44######################################## 
     
    1515 
    1616type qmail_etc_t; 
    17 files_type(qmail_etc_t) 
     17files_config_file(qmail_etc_t) 
    1818 
    1919type qmail_exec_t; 
     
    8686libs_use_shared_libs(qmail_inject_t) 
    8787 
     88miscfiles_read_localization(qmail_inject_t) 
     89 
    8890qmail_read_config(qmail_inject_t) 
    8991 
     
    101103manage_files_pattern(qmail_local_t, qmail_alias_home_t, qmail_alias_home_t) 
    102104 
     105can_exec(qmail_local_t, qmail_local_exec_t) 
     106 
    103107allow qmail_local_t qmail_queue_exec_t:file read; 
    104108 
     
    107111kernel_read_system_state(qmail_local_t) 
    108112 
     113corecmd_exec_bin(qmail_local_t) 
    109114corecmd_exec_shell(qmail_local_t) 
    110115 
    111116files_read_etc_files(qmail_local_t) 
    112117files_read_etc_runtime_files(qmail_local_t) 
     118 
     119auth_use_nsswitch(qmail_local_t) 
     120 
     121logging_send_syslog_msg(qmail_local_t) 
    113122 
    114123mta_append_spool(qmail_local_t) 
     
    155164manage_files_pattern(qmail_queue_t, qmail_spool_t, qmail_spool_t) 
    156165rw_fifo_files_pattern(qmail_queue_t, qmail_spool_t, qmail_spool_t) 
     166 
     167corecmd_exec_bin(qmail_queue_t) 
     168 
     169logging_send_syslog_msg(qmail_queue_t) 
    157170 
    158171optional_policy(` 
  • trunk/policy/modules/system/ipsec.if

    r2531 r2774  
    130130 
    131131        allow $1 ipsec_spd_t:association setcontext; 
     132') 
     133 
     134######################################## 
     135## <summary> 
     136##      write the ipsec_var_run_t files. 
     137## </summary> 
     138## <param name="domain"> 
     139##      <summary> 
     140##      Domain allowed access. 
     141##      </summary> 
     142## </param> 
     143# 
     144interface(`ipsec_write_pid',` 
     145        gen_require(` 
     146                type ipsec_var_run_t; 
     147        ') 
     148 
     149        files_search_pids($1) 
     150        write_files_pattern($1, ipsec_var_run_t, ipsec_var_run_t) 
    132151') 
    133152 
  • trunk/policy/modules/system/ipsec.te

    r2742 r2774  
    11 
    2 policy_module(ipsec, 1.7.0
     2policy_module(ipsec, 1.7.1
    33 
    44######################################## 
     
    7070read_lnk_files_pattern(ipsec_t,ipsec_key_file_t,ipsec_key_file_t) 
    7171 
    72 allow ipsec_t ipsec_var_run_t:file manage_file_perms; 
    73 allow ipsec_t ipsec_var_run_t:sock_file manage_sock_file_perms; 
    74 files_pid_filetrans(ipsec_t,ipsec_var_run_t,{ file sock_file }) 
     72manage_files_pattern(ipsec_t, ipsec_var_run_t, ipsec_var_run_t) 
     73manage_sock_files_pattern(ipsec_t, ipsec_var_run_t, ipsec_var_run_t) 
     74files_pid_filetrans(ipsec_t, ipsec_var_run_t, { file sock_file }) 
    7575 
    7676can_exec(ipsec_t, ipsec_mgmt_exec_t) 
  • trunk/policy/modules/system/iscsi.fc

    r2441 r2774  
    11/sbin/iscsid            --      gen_context(system_u:object_r:iscsid_exec_t,s0) 
    22 
    3 /var/lib/iscsi(/.*)?    --    gen_context(system_u:object_r:iscsi_var_lib_t,s0) 
    4 /var/lock/iscsi(/.*)?   --    gen_context(system_u:object_r:iscsi_lock_t,s0) 
     3/var/lib/iscsi(/.*)?          gen_context(system_u:object_r:iscsi_var_lib_t,s0) 
     4/var/lock/iscsi(/.*)?         gen_context(system_u:object_r:iscsi_lock_t,s0) 
    55/var/run/iscsid\.pid    --      gen_context(system_u:object_r:iscsi_var_run_t,s0) 
  • trunk/policy/modules/system/iscsi.te

    r2656 r2774  
    11 
    2 policy_module(iscsid,1.4.0
     2policy_module(iscsid, 1.4.1
    33 
    44######################################## 
     
    3030 
    3131allow iscsid_t self:capability { dac_override ipc_lock net_admin sys_nice sys_resource }; 
    32 allow iscsid_t self:process { setrlimit setsched }; 
     32allow iscsid_t self:process { setrlimit setsched signal }; 
    3333allow iscsid_t self:fifo_file { read write }; 
    3434allow iscsid_t self:unix_stream_socket { create_stream_socket_perms connectto }; 
     
    6464corenet_tcp_connect_http_port(iscsid_t) 
    6565corenet_tcp_connect_iscsi_port(iscsid_t) 
     66corenet_tcp_connect_isns_port(iscsid_t) 
    6667 
    6768dev_rw_sysfs(iscsid_t) 
  • trunk/policy/modules/system/sysnetwork.te

    r2742 r2774  
    11 
    2 policy_module(sysnetwork, 1.7.0
     2policy_module(sysnetwork, 1.7.1
    33 
    44######################################## 
     
    321321 
    322322optional_policy(` 
     323        ipsec_write_pid(ifconfig_t) 
     324') 
     325 
     326optional_policy(` 
    323327        netutils_domtrans(dhcpc_t) 
    324328')