From 5ebd1a52a569eb58a53538c683ad64d12434af0e Mon Sep 17 00:00:00 2001 From: Dominick Grift Date: Thu, 16 Sep 2010 08:51:01 +0200 Subject: [PATCH] Use domtrans_pattern because it include permission the sigchld target domain and other required access to domain transition. Signed-off-by: Dominick Grift --- policy/modules/services/ucspitcp.if | 5 +---- 1 file changed, 1 insertion(+), 4 deletions(-) diff --git a/policy/modules/services/ucspitcp.if b/policy/modules/services/ucspitcp.if index c1feba4f..bf821706 100644 --- a/policy/modules/services/ucspitcp.if +++ b/policy/modules/services/ucspitcp.if @@ -31,8 +31,5 @@ interface(`ucspitcp_service_domain', ` role system_r types $1; - domain_auto_trans(ucspitcp_t, $2, $1) - allow $1 ucspitcp_t:fd use; - allow $1 ucspitcp_t:process sigchld; - allow $1 ucspitcp_t:tcp_socket rw_stream_socket_perms; + domtrans_pattern(ucspitcp_t, $2, $1) ')