remove relabeling privilege for now
This commit is contained in:
parent
57d236548b
commit
1ea98d0407
@ -82,19 +82,6 @@ attribute can_load_kernmodule;
|
|||||||
class capability sys_module;
|
class capability sys_module;
|
||||||
')
|
')
|
||||||
|
|
||||||
########################################
|
|
||||||
#
|
|
||||||
# kernel_relabeling_privilege(domain,[`optional'])
|
|
||||||
#
|
|
||||||
define(`kernel_relabeling_privilege',`
|
|
||||||
requires_block_template(kernel_relabeling_privilege_depend,$2)
|
|
||||||
typeattribute $1 can_relabel;
|
|
||||||
')
|
|
||||||
|
|
||||||
define(`kernel_relabeling_privilege_depend',`
|
|
||||||
attribute can_relabel;
|
|
||||||
')
|
|
||||||
|
|
||||||
########################################
|
########################################
|
||||||
#
|
#
|
||||||
# kernel_kill_unlabeled_process(domain,[`optional'])
|
# kernel_kill_unlabeled_process(domain,[`optional'])
|
||||||
|
@ -79,7 +79,6 @@ devices_list_device_nodes_depend
|
|||||||
define(`terminal_reset_labels',`
|
define(`terminal_reset_labels',`
|
||||||
requires_block_template(terminal_reset_labels_depend,$2)
|
requires_block_template(terminal_reset_labels_depend,$2)
|
||||||
devices_list_device_nodes($1,optional)
|
devices_list_device_nodes($1,optional)
|
||||||
kernel_relabeling_privilege($1,optional)
|
|
||||||
allow $1 ttynode:chr_file relabelfrom;
|
allow $1 ttynode:chr_file relabelfrom;
|
||||||
allow $1 tty_device_t:chr_file relabelto;
|
allow $1 tty_device_t:chr_file relabelto;
|
||||||
')
|
')
|
||||||
|
Loading…
Reference in New Issue
Block a user