]> git.ipfire.org Git - people/stevee/selinux-policy.git/commit - policy/modules/roles/xguest.te
Remove execmem_exec_t, java_exec_t, mono_exec_t and allow confined users to use execm...
authordwalsh <dwalsh@redhat.com>
Thu, 10 Nov 2011 14:27:27 +0000 (09:27 -0500)
committerdwalsh <dwalsh@redhat.com>
Thu, 10 Nov 2011 14:27:27 +0000 (09:27 -0500)
commit4a09309634220f0053c2cb9191a649c6a563dcdd
tree5ddc9f84552f559008895297240f8f09e1795406
parente200bcc0364be9c7d73669f07b2b091252a4d3a5
Remove execmem_exec_t, java_exec_t, mono_exec_t and allow confined users to use execmem,  add deny_execmem boolean to turn off execmem for all users.  Probably will only work in server non graphical environments since so much of the desktop now requies JIT and execmem
16 files changed:
policy/global_tunables
policy/modules/admin/rpm.te
policy/modules/apps/games.te
policy/modules/apps/mozilla.te
policy/modules/apps/mplayer.te
policy/modules/apps/sandbox.te
policy/modules/apps/thumb.te
policy/modules/kernel/corecommands.te
policy/modules/roles/unconfineduser.te
policy/modules/roles/xguest.te
policy/modules/services/hadoop.if
policy/modules/services/hadoop.te
policy/modules/services/postgresql.te
policy/modules/services/xserver.te
policy/modules/system/unconfined.if
policy/modules/system/userdomain.if