]> git.ipfire.org Git - people/stevee/selinux-policy.git/commitdiff
Turn back on unconfined_domains for final release, but eliminate unconfined_domain...
authorDan Walsh <dwalsh@redhat.com>
Fri, 26 Aug 2011 15:17:43 +0000 (11:17 -0400)
committerDan Walsh <dwalsh@redhat.com>
Fri, 26 Aug 2011 15:17:43 +0000 (11:17 -0400)
16 files changed:
policy/modules/admin/bootloader.te
policy/modules/admin/kudzu.te
policy/modules/admin/prelink.te
policy/modules/admin/tmpreaper.te
policy/modules/admin/usermanage.te
policy/modules/services/apm.te
policy/modules/services/devicekit.te
policy/modules/services/piranha.te
policy/modules/services/rgmanager.te
policy/modules/services/virt.te
policy/modules/system/fstools.te
policy/modules/system/libraries.te
policy/modules/system/lvm.te
policy/modules/system/modutils.te
policy/modules/system/raid.te
policy/modules/system/selinuxutil.te

index 559bc9b22edfc1eec64db7352e1d359893176d27..9152065fb2422b59c050e2337ac15e048e6d73f7 100644 (file)
@@ -167,9 +167,9 @@ ifdef(`distro_redhat',`
                mount_domtrans(bootloader_t)
        ')
 
-       #optional_policy(`
-       #       unconfined_domain(bootloader_t)
-       #')
+       optional_policy(`
+               unconfined_domain(bootloader_t)
+       ')
 ')
 
 optional_policy(`
index 6c420a46ecaf8c7af7fc2d49860daebdc0b0afb6..a29af21c9a7ec3f65337e243857b4b05021305c1 100644 (file)
@@ -140,5 +140,4 @@ optional_policy(`
 
 optional_policy(`
        unconfined_domtrans(kudzu_t)
-       #unconfined_domain(kudzu_t)
 ')
index 77b9b29a62e76c5fd8bfb9b34c92e29ff65e4a3a..e83b341de94757d371e37f3db3f943600e4eddf4 100644 (file)
@@ -132,9 +132,9 @@ optional_policy(`
        rpm_manage_tmp_files(prelink_t)
 ')
 
-#optional_policy(`
-#      unconfined_domain(prelink_t)
-#')
+optional_policy(`
+       unconfined_domain(prelink_t)
+')
 
 ########################################
 #
index de58aeb99d2ed6c0e2413cc6f4e5216b30dd722d..90cf622e9136813893bbbb7f35a3baa1d82b21b9 100644 (file)
@@ -88,7 +88,3 @@ optional_policy(`
 optional_policy(`
        rpm_manage_cache(tmpreaper_t)
 ')
-
-#optional_policy(`
-#      unconfined_domain(tmpreaper_t)
-#')
index 233bbc6281a437fb1cdf032091b22091e3aab24d..3d2f4184a6ad6f3ee17aed1ed5dfd50c3988d0df 100644 (file)
@@ -508,12 +508,6 @@ userdom_manage_home_role(system_r, useradd_t)
 
 mta_manage_spool(useradd_t)
 
-#ifdef(`distro_redhat',`
-#      optional_policy(`
-#              unconfined_domain(useradd_t)
-#      ')
-#')
-
 optional_policy(`
        apache_manage_all_user_content(useradd_t)
 ')
index 4ae8a51b63582b09c150944a2943f6216a058025..21b91de5d56ce40e03dd3a2d7cda5f6edc0a0d46 100644 (file)
@@ -232,10 +232,6 @@ optional_policy(`
        udev_read_state(apmd_t) #necessary?
 ')
 
-#optional_policy(`
-#      unconfined_domain(apmd_t)
-#')
-
 optional_policy(`
        vbetool_domtrans(apmd_t)
 ')
index 4506fa33490c0027aec4a0bce7e6c5c07e9261b7..5a06fc7ff8e66f375c9d16cb55e0afed36701ebc 100644 (file)
@@ -188,11 +188,11 @@ optional_policy(`
        virt_manage_images(devicekit_disk_t)
 ')
 
-#optional_policy(`
-#      unconfined_domain(devicekit_t)
-#      unconfined_domain(devicekit_power_t)
-#      unconfined_domain(devicekit_disk_t)
-#')
+optional_policy(`
+       unconfined_domain(devicekit_t)
+       unconfined_domain(devicekit_power_t)
+       unconfined_domain(devicekit_disk_t)
+')
 
 ########################################
 #
index 0ac1a0c5d783703218d4536f916beef558388e4c..aaf3fa8dea4ab765ed6ab0cd3e5ffc0388e34b2c 100644 (file)
@@ -257,10 +257,6 @@ optional_policy(`
     udev_read_db(piranha_pulse_t)
 ')
 
-#optional_policy(`
-#       unconfined_domain(piranha_pulse_t)
-#')
-
 ####################################
 #
 # piranha domains common policy
index d95e1360956efc543c445027ed7f00850567f163..e6051054df147a8f2fe4fcdcba27d3eb0b41b0c0 100644 (file)
@@ -220,9 +220,9 @@ optional_policy(`
        virt_stream_connect(rgmanager_t)
 ')
 
-#optional_policy(`
-#      unconfined_domain(rgmanager_t)
-#')
+optional_policy(`
+       unconfined_domain(rgmanager_t)
+')
 
 optional_policy(`
        xen_domtrans_xm(rgmanager_t)
index e18ede2def8c851b6d9ba408610fbb6e999cd2c1..ccd2e5161223b6e069d9254b749dc74dd53531a6 100644 (file)
@@ -518,9 +518,9 @@ optional_policy(`
        udev_read_db(virtd_t)
 ')
 
-#optional_policy(`
-#      unconfined_domain(virtd_t)
-#')
+optional_policy(`
+       unconfined_domain(virtd_t)
+')
 
 ########################################
 #
index bf8ea27427b1e792b10c8b8b4dfdc92a74d45610..38390f52ba65e60141da20b26f697db40ebde90c 100644 (file)
@@ -158,11 +158,11 @@ seutil_read_config(fsadm_t)
 
 term_use_all_inherited_terms(fsadm_t)
 
-#ifdef(`distro_redhat',`
-#      optional_policy(`
-#              unconfined_domain(fsadm_t)
-#      ')
-#')
+ifdef(`distro_redhat',`
+       optional_policy(`
+               unconfined_domain(fsadm_t)
+       ')
+')
 
 optional_policy(`
        amanda_rw_dumpdates_files(fsadm_t)
index b32b945faade27fc905bb447ddeb2e02fe319898..c76046b4741e274f442d8ee9ed658bc111d6b3f7 100644 (file)
@@ -153,7 +153,3 @@ optional_policy(`
        rpm_manage_script_tmp_files(ldconfig_t)
 ')
 
-#optional_policy(`
-#      unconfined_domain(ldconfig_t)
-#')
-
index 4513ab912f070fca64c087a6756c64aca911d510..e55e9672ffac2f5ae9430e0ff21fdf0647fecbb9 100644 (file)
@@ -141,11 +141,11 @@ userdom_dontaudit_search_user_home_dirs(clvmd_t)
 lvm_domtrans(clvmd_t)
 lvm_read_config(clvmd_t)
 
-#ifdef(`distro_redhat',`
-#      optional_policy(`
-#              unconfined_domain(clvmd_t)
-#      ')
-#')
+ifdef(`distro_redhat',`
+       optional_policy(`
+               unconfined_domain(clvmd_t)
+       ')
+')
 
 optional_policy(`
        aisexec_stream_connect(clvmd_t)
@@ -333,9 +333,9 @@ ifdef(`distro_redhat',`
        # this is from the initrd:
        files_rw_isid_type_dirs(lvm_t)
 
-       #optional_policy(`
-       #       unconfined_domain(lvm_t)
-       #')
+       optional_policy(`
+               unconfined_domain(lvm_t)
+       ')
 ')
 
 optional_policy(`
index 8b724a521b6f9f38fa634ab724c2e989223d9270..d5408ff9149f9c5f7d9096d38206e4d67c1c3efd 100644 (file)
@@ -102,10 +102,9 @@ optional_policy(`
        rpm_manage_script_tmp_files(depmod_t)
 ')
 
-#optional_policy(`
-#      # Read System.map from home directories.
-#      unconfined_domain(depmod_t)
-#')
+optional_policy(`
+       unconfined_domain(depmod_t)
+')
 
 ########################################
 #
@@ -250,7 +249,7 @@ optional_policy(`
 ')
 
 optional_policy(`
-       #unconfined_domain(insmod_t)
+       unconfined_domain(insmod_t)
        unconfined_dontaudit_rw_pipes(insmod_t)
 ')
 
index 4e2ef363239546372e07be5745b06732aa1dfcba..dbcca4d87450e1edc8ae334672890665f8a99a4e 100644 (file)
@@ -97,6 +97,6 @@ optional_policy(`
        udev_read_db(mdadm_t)
 ')
 
-#optional_policy(`
-#      unconfined_domain(mdadm_t)
-#')
+optional_policy(`
+       unconfined_domain(mdadm_t)
+')
index 3e78f42252330490521bfe4839b0fff4210b1863..4e8cb385c52a3137d4bd0c1fe83d8c6da6902f35 100644 (file)
@@ -564,6 +564,6 @@ ifdef(`hide_broken_symptoms',`
        ')
 ')
 
-#optional_policy(`
-#      unconfined_domain(setfiles_mac_t)
-#')
+optional_policy(`
+       unconfined_domain(setfiles_mac_t)
+')