Fix cobbler_admin interface to require cobblerd_initrc_exec_t.
As per: http://oss.tresys.com/pipermail/refpolicy/2010-March/002258.html Signed-off-by: Dominick Grift <domg472@gmail.com> Signed-off-by: Chris PeBenito <cpebenito@tresys.com>
This commit is contained in:
parent
eeb7616f5e
commit
183f79e38e
@ -161,7 +161,7 @@ interface(`cobbler_manage_lib_files',`
|
|||||||
interface(`cobblerd_admin',`
|
interface(`cobblerd_admin',`
|
||||||
gen_require(`
|
gen_require(`
|
||||||
type cobblerd_t, cobbler_var_lib_t, cobbler_var_log_t;
|
type cobblerd_t, cobbler_var_lib_t, cobbler_var_log_t;
|
||||||
type cobbler_etc_t;
|
type cobbler_etc_t, cobblerd_initrc_exec_t;
|
||||||
')
|
')
|
||||||
|
|
||||||
allow $1 cobblerd_t:process { ptrace signal_perms getattr };
|
allow $1 cobblerd_t:process { ptrace signal_perms getattr };
|
||||||
|
Loading…
Reference in New Issue
Block a user