add privmail attribute and move make_{init,daemon,system}_domain to init
This commit is contained in:
parent
ff31386090
commit
c28c4b03c9
@ -266,8 +266,18 @@ domain_make_file_descriptors_widely_inheritable($1)
|
||||
|
||||
#
|
||||
# privlog: complete
|
||||
#
|
||||
logging_send_system_log_message($1)
|
||||
|
||||
#
|
||||
# privmail:
|
||||
#
|
||||
mta_send_mail_transition($1)
|
||||
# this needs more work:
|
||||
allow mta_user_agent $1:fd use;
|
||||
allow mta_user_agent $1:process sigchld;
|
||||
allow mta_user_agent $1:fifo_file { read write };
|
||||
|
||||
#
|
||||
# privmodule: complete
|
||||
#
|
||||
@ -685,7 +695,7 @@ allow $1 $2:lnk_file { create read getattr setattr link unlink rename };
|
||||
#
|
||||
type $1_t;
|
||||
type $1_exec_t;
|
||||
domain_make_daemon_domain($1_t,$1_exec_t)
|
||||
init_make_daemon_domain($1_t,$1_exec_t)
|
||||
role system_r types $1_t;
|
||||
dontaudit $1_t self:capability sys_tty_config;
|
||||
allow $1_t self:process { sigchld sigkill sigstop signull signal };
|
||||
@ -728,7 +738,7 @@ allow $1_t autofs_t:dir { search getattr };
|
||||
#
|
||||
type $1_t;
|
||||
type $1_exec_t;
|
||||
domain_make_daemon_domain($1_t,$1_exec_t)
|
||||
init_make_daemon_domain($1_t,$1_exec_t)
|
||||
type $1_var_run_t;
|
||||
files_make_daemon_runtime_file($1_var_run_t)
|
||||
allow $1_t $1_var_run_t:file { getattr create read write append setattr unlink };
|
||||
@ -891,7 +901,7 @@ role staff_r types $1;
|
||||
#
|
||||
type $1_t;
|
||||
type $1_exec_t;
|
||||
domain_make_daemon_domain($1_t,$1_exec_t)
|
||||
init_make_daemon_domain($1_t,$1_exec_t)
|
||||
dontaudit $1_t self:capability sys_tty_config;
|
||||
kernel_read_hardware_state($1_t)
|
||||
terminal_ignore_use_console($1_t)
|
||||
|
Loading…
Reference in New Issue
Block a user