Policy fixes

This commit is contained in:
Dan Walsh 2010-08-30 08:57:06 -04:00
parent ac498fa5d9
commit 2d4a79a061
4 changed files with 29 additions and 2 deletions

View File

@ -471,7 +471,7 @@ interface(`gnome_stream_connect',`
######################################## ########################################
## <summary> ## <summary>
## read gnome homedir content (.config) ## list gnome homedir content (.config)
## </summary> ## </summary>
## <param name="user_domain"> ## <param name="user_domain">
## <summary> ## <summary>
@ -487,6 +487,24 @@ template(`gnome_list_home_config',`
allow $1 config_home_t:dir list_dir_perms; allow $1 config_home_t:dir list_dir_perms;
') ')
########################################
## <summary>
## read gnome homedir content (.config)
## </summary>
## <param name="user_domain">
## <summary>
## The type of the user domain.
## </summary>
## </param>
#
template(`gnome_read_home_config',`
gen_require(`
type config_home_t;
')
read_files_pattern($1, config_home_t, config_home_t)
')
######################################## ########################################
## <summary> ## <summary>
## Read/Write all inherited gnome home config ## Read/Write all inherited gnome home config

View File

@ -186,7 +186,11 @@ optional_policy(`
') ')
optional_policy(` optional_policy(`
xserver_rw_shm(unconfined_usertype) gen_require(`
type user_tmpfs_t;
')
xserver_rw_session(unconfined_usertype, user_tmpfs_t)
xserver_run_xauth(unconfined_usertype, unconfined_r) xserver_run_xauth(unconfined_usertype, unconfined_r)
xserver_dbus_chat_xdm(unconfined_usertype) xserver_dbus_chat_xdm(unconfined_usertype)
') ')

View File

@ -40,6 +40,7 @@ files_pid_filetrans(icecast_t, icecast_var_run_t, { file dir })
kernel_read_system_state(icecast_t) kernel_read_system_state(icecast_t)
corenet_tcp_bind_soundd_port(icecast_t) corenet_tcp_bind_soundd_port(icecast_t)
corenet_tcp_connect_soundd_port(icecast_t)
# Init script handling # Init script handling
domain_use_interactive_fds(icecast_t) domain_use_interactive_fds(icecast_t)

View File

@ -244,6 +244,10 @@ optional_policy(`
devicekit_dgram_send(udev_t) devicekit_dgram_send(udev_t)
') ')
optional_policy(`
gnome_read_home_config(udev_t)
')
optional_policy(` optional_policy(`
lvm_domtrans(udev_t) lvm_domtrans(udev_t)
') ')