trunk: two tiny patches from Stefan Schulze Frielinghaus

This commit is contained in:
Chris PeBenito 2007-09-06 19:29:54 +00:00
parent 72f82c47c2
commit abc89340c4
3 changed files with 27 additions and 2 deletions

View File

@ -692,6 +692,25 @@ interface(`term_relabelto_all_user_ptys',`
allow $1 ptynode:chr_file relabelto; allow $1 ptynode:chr_file relabelto;
') ')
########################################
## <summary>
## Write to all user ptys.
## </summary>
## <param name="domain">
## <summary>
## Domain allowed access.
## </summary>
## </param>
#
interface(`term_write_all_user_ptys',`
gen_require(`
attribute ptynode;
')
dev_list_all_dev_nodes($1)
allow $1 ptynode:chr_file write_chr_file_perms;
')
######################################## ########################################
## <summary> ## <summary>
## Read and write all user ptys. ## Read and write all user ptys.

View File

@ -1,5 +1,5 @@
policy_module(terminal,1.5.0) policy_module(terminal,1.5.1)
######################################## ########################################
# #

View File

@ -1,5 +1,5 @@
policy_module(selinuxutil,1.6.2) policy_module(selinuxutil,1.6.3)
ifdef(`strict_policy',` ifdef(`strict_policy',`
gen_require(` gen_require(`
@ -477,6 +477,7 @@ mls_file_read_all_levels(semanage_t)
selinux_validate_context(semanage_t) selinux_validate_context(semanage_t)
selinux_get_enforce_mode(semanage_t) selinux_get_enforce_mode(semanage_t)
selinux_getattr_fs(semanage_t)
# for setsebool: # for setsebool:
selinux_set_boolean(semanage_t) selinux_set_boolean(semanage_t)
@ -510,6 +511,11 @@ seutil_manage_default_contexts(semanage_t)
userdom_search_sysadm_home_dirs(semanage_t) userdom_search_sysadm_home_dirs(semanage_t)
ifdef(`distro_debian',`
files_read_var_lib_files(semanage_t)
files_read_var_lib_symlinks(semanage_t)
')
# cjp: need a more general way to handle this: # cjp: need a more general way to handle this:
ifdef(`enable_mls',` ifdef(`enable_mls',`
# read secadm tmp files # read secadm tmp files