Use admin_pattern. Allow nslcd_admin to search parent directories to be able to interact with nslcd content.

Signed-off-by: Dominick Grift <domg472@gmail.com>
This commit is contained in:
Dominick Grift 2010-09-15 12:56:18 +02:00
parent eb12bc3076
commit b6d0a79f2c

View File

@ -106,9 +106,9 @@ interface(`nslcd_admin',`
role_transition $2 nslcd_initrc_exec_t system_r;
allow $2 system_r;
manage_files_pattern($1, nslcd_conf_t, nslcd_conf_t)
files_search_etc($1)
admin_pattern($1, nslcd_conf_t)
manage_dirs_pattern($1, nslcd_var_run_t, nslcd_var_run_t)
manage_files_pattern($1, nslcd_var_run_t, nslcd_var_run_t)
manage_lnk_files_pattern($1, nslcd_var_run_t, nslcd_var_run_t)
files_search_pids($1)
admin_pattern($1, nslcd_var_run_t, nslcd_var_run_t)
')