]> git.ipfire.org Git - people/stevee/selinux-policy.git/commitdiff
trunk: 3 patches from dan.
authorChris PeBenito <cpebenito@tresys.com>
Thu, 18 Oct 2007 19:31:14 +0000 (19:31 +0000)
committerChris PeBenito <cpebenito@tresys.com>
Thu, 18 Oct 2007 19:31:14 +0000 (19:31 +0000)
policy/modules/admin/brctl.te
policy/modules/admin/logwatch.te
policy/modules/admin/usermanage.if
policy/modules/admin/usermanage.te

index a46b0eb50b7e73bf35767a9292ea3249d8d4ac50..1e4aa13a300bd53a355170f4a1deffceaa4503a7 100644 (file)
@@ -1,4 +1,4 @@
-policy_module(brctl,1.0.1)
+policy_module(brctl,1.0.2)
 
 ########################################
 #
@@ -26,6 +26,7 @@ kernel_read_network_state(brctl_t)
 kernel_read_sysctl(brctl_t)
 
 dev_rw_sysfs(brctl_t)
+dev_write_sysfs_dirs(brctl_t)
 
 # Init script handling
 domain_use_interactive_fds(brctl_t)
index b0ee1b21448f7bcb77d3d29844879ac1c6e961a3..1728bb67c27a9101664ff7083b29ee0fca063516 100644 (file)
@@ -1,5 +1,5 @@
 
-policy_module(logwatch,1.6.0)
+policy_module(logwatch,1.6.1)
 
 #################################
 #
@@ -48,7 +48,7 @@ corecmd_exec_bin(logwatch_t)
 corecmd_exec_shell(logwatch_t)
 
 dev_read_urand(logwatch_t)
-dev_search_sysfs(logwatch_t)
+dev_read_sysfs(logwatch_t)
 
 # Read /proc/PID directories for all domains.
 domain_read_all_domains_state(logwatch_t)
index 74ccaf9967f46e4095132c3d86e1adb3db2285e2..8b18379dab316dcfcfc98817ca8e66b62589e557 100644 (file)
@@ -216,6 +216,24 @@ interface(`usermanage_run_admin_passwd',`
        ')
 ')
 
+########################################
+## <summary>
+##     Dontaudit attempts to use useradd fds
+## </summary>
+## <param name="domain">
+##     <summary>
+##     The type of the process performing this action.
+##     </summary>
+## </param>
+#
+interface(`usermanage_dontaudit_use_useradd_fds',`
+       gen_require(`
+               type useradd_t;
+       ')
+
+       dontaudit $1 useradd_t:fd use;
+')
+
 ########################################
 ## <summary>
 ##     Execute useradd in the useradd domain.
index b57a2cc357714b9d1d9afc0ebc4d286f43943fe7..14b20d9539c0fa58936ddf5e0794305114f2feeb 100644 (file)
@@ -1,5 +1,5 @@
 
-policy_module(usermanage,1.8.1)
+policy_module(usermanage,1.8.2)
 
 ########################################
 #
@@ -519,6 +519,10 @@ userdom_generic_user_home_dir_filetrans_generic_user_home_content(useradd_t,notd
 
 mta_manage_spool(useradd_t)
 
+optional_policy(`
+       apache_manage_all_user_content(useradd_t)
+')
+
 optional_policy(`
        dpkg_use_fds(useradd_t)
        dpkg_rw_pipes(useradd_t)