Dominick Grift
ba6db03dc0
Redundant: mta_sendmail_domtrans calls domtrans_pattern which already includes these permissions.
2010-09-16 12:18:33 +02:00
Dominick Grift
b35d259348
XML summary ffixes.
...
XML summary fixes.
Signed-off-by: Dominick Grift <domg472@gmail.com>
XML summary fixes.
2010-09-16 12:18:33 +02:00
Dominick Grift
f92662114a
Search parent directory to be able to interact with target content.
...
Search parent directory to be able to interact with target content.
Search parent directory to be able to interact with target content.
Signed-off-by: Dominick Grift <domg472@gmail.com>
Search parent directory to be able to interact with target content.
Search parent directory to be able to interact with target content.
Signed-off-by: Dominick Grift <domg472@gmail.com>
Search parent directory to be able to interact with target content.
Search parent directory to be able to interact with target content.
Search parent directory to be able to interact with target content.
2010-09-16 12:18:33 +02:00
Dominick Grift
4ff4ddfaa3
Allow users to ptrace and send any kind of signal to spamassassin agents.
2010-09-16 12:18:33 +02:00
Dominick Grift
c5caddd673
This type is not required here.
2010-09-16 12:18:33 +02:00
Dominick Grift
b0e9aaafb9
This is not a role capability.
...
This is not a role capability.
Signed-off-by: Dominick Grift <domg472@gmail.com>
This is not a role capability.
2010-09-16 12:18:31 +02:00
Dominick Grift
a3d20a3c3a
Use relabel permission sets where possible.
2010-09-16 12:18:31 +02:00
Dominick Grift
9a2fd7d144
Redundant: This is included with userdom_read_user_home_content_files.
...
Signed-off-by: Dominick Grift <domg472@gmail.com>
2010-09-16 12:18:31 +02:00
Dominick Grift
50e85752ad
Allow users to ptrace and send any kind of signal to their ssh agent instead of only a generic signal.
...
Signed-off-by: Dominick Grift <domg472@gmail.com>
2010-09-16 12:18:31 +02:00
Dominick Grift
f416df73dd
Redundant: This is included with userdom_search_user_home_content.
...
Signed-off-by: Dominick Grift <domg472@gmail.com>
2010-09-16 12:18:31 +02:00
Dominick Grift
a87e8f736c
Redundant: domtrans_pattern includes these.
...
Signed-off-by: Dominick Grift <domg472@gmail.com>
2010-09-16 12:18:31 +02:00
Dominick Grift
d0b7562f02
Do not audit interface should not provide permission to read parent directories.
...
Signed-off-by: Dominick Grift <domg472@gmail.com>
2010-09-16 12:18:31 +02:00
Dominick Grift
5ebd1a52a5
Use domtrans_pattern because it include permission the sigchld target domain and other required access to domain transition.
...
Signed-off-by: Dominick Grift <domg472@gmail.com>
2010-09-16 12:18:31 +02:00
Dominick Grift
2d102f8402
Whitespace, newline and tab fixes.
...
Whitespace, newline and tab fixes.
Whitespace, newline and tab fixes.
Whitespace, newline and tab fixes.
Whitespace, newline and tab fixes.
Whitespace, newline and tab fixes.
Whitespace, newline and tab fixes.
Whitespace, newline and tab fixes.
Whitespace, newline and tab fixes.
Whitespace, newline and tab fixes.
Whitespace, newline and tab fixes.
Whitespace, newline and tab fixes.
Signed-off-by: Dominick Grift <domg472@gmail.com>
2010-09-16 12:18:31 +02:00
Dominick Grift
60d27bf8ab
Tunable, optional, if(n)def block go below.
...
Signed-off-by: Dominick Grift <domg472@gmail.com>
2010-09-16 10:43:14 +02:00
Dominick Grift
2e2a24e07d
Use stream_connect_pattern.
...
Signed-off-by: Dominick Grift <domg472@gmail.com>
2010-09-16 10:43:14 +02:00
Dominick Grift
83029ff3c5
Use relabel permission sets where possible.
...
Signed-off-by: Dominick Grift <domg472@gmail.com>
2010-09-15 17:42:29 +02:00
Dominick Grift
4ec4a49e8a
Add missing admin_patterns to rpcbind_admin.
...
Signed-off-by: Dominick Grift <domg472@gmail.com>
2010-09-15 17:42:29 +02:00
Dominick Grift
ac13ad949b
Use stream connect pattern.
...
Use stream_connect_pattern.
Use stream_connect_pattern.
Use stream_connect_pattern.
Signed-off-by: Dominick Grift <domg472@gmail.com>
2010-09-15 17:42:29 +02:00
Dominick Grift
ad424545db
Use ps_process_pattern to read state.
...
Use ps_process_pattern.
Signed-off-by: Dominick Grift <domg472@gmail.com>
2010-09-15 17:42:29 +02:00
Dominick Grift
87cd6eef3a
Reduntant: Is already included with userdom_search_user_home_dirs.
...
Signed-off-by: Dominick Grift <domg472@gmail.com>
2010-09-15 17:42:29 +02:00
Dominick Grift
4eaffd271f
Access to get attributes of target pppd_t domain is included with ps_process_pattern.
...
Access to get attributes of target privoxy_t domain is included with ps_process_pattern.
Access to get attributes of target radiusd_t domain is included with ps_process_pattern.
Signed-off-by: Dominick Grift <domg472@gmail.com>
2010-09-15 17:42:29 +02:00
Dominick Grift
39e118bc15
Use ps_process_pattern to read state. Access to get attributes of target afs_t domain is included with ps_process_pattern.
...
Use ps_process_pattern to read state. Access to get attributes of target boinc_t domain is included with ps_process_pattern.
Use ps_process_pattern to read state. Access to get attributes of target cobblerd_t domain is included with ps_process_pattern.
Use ps_process_pattern to read state. Permission to get attributes of target exim_t domain is included with ps_process_pattern.
Use ps_process_pattern to read state. Access to get attributes of target plymouthd_t domain is included with ps_process_pattern.
Use ps_process_pattern to read state. Access to get attributes of target pportreserve_t domain is included with ps_process_pattern.
Use ps_process_pattern to read state. Access to get attributes of target postfix domains is included with ps_process_pattern.
Use ps_process_pattern to read state. Permission to get attributes of target qpidd_t domain is included with ps_process_pattern.
Signed-off-by: Dominick Grift <domg472@gmail.com>
2010-09-15 17:42:28 +02:00
Dominick Grift
1215dfb87c
Allow pads_admin to search parent directories to be able to interact with pads content.
...
Allow plymouthd_admin to search parent directories to be able to interact with plymouthd content.
Allow postgresql admin to search parent directories to be able to manage postgresql content.
Allow prelude_admin to search parent directories to be able to manage prelude content.
Signed-off-by: Dominick Grift <domg472@gmail.com>
2010-09-15 17:42:28 +02:00
Dominick Grift
d183137edb
XML summary fix.
...
XML summary fix.
XML summary fix.
Signed-off-by: Dominick Grift <domg472@gmail.com>
2010-09-15 17:42:28 +02:00
Dominick Grift
dcbbeeada3
Access to get attributes of target accountsd_t domain is included with ps_process_pattern.
...
Permission to get attributes of target arpwatch_t domain is included with ps_process_pattern.
Access to get attributes of target asterisk_t domain is included with ps_process_pattern.
Permission to get attributes of target automount_t domain is included with ps_process_pattern.
Access to get attributes of target ntpd_t domain is included with ps_process_pattern.
Signed-off-by: Dominick Grift <domg472@gmail.com>
2010-09-15 17:42:28 +02:00
Dominick Grift
b6d0a79f2c
Use admin_pattern. Allow nslcd_admin to search parent directories to be able to interact with nslcd content.
...
Signed-off-by: Dominick Grift <domg472@gmail.com>
2010-09-15 17:42:28 +02:00
Dominick Grift
eb12bc3076
Source is required to search generic pid directories to be able to interact with mysql sockets in var_run.
...
Signed-off-by: Dominick Grift <domg472@gmail.com>
2010-09-15 17:42:28 +02:00
Dominick Grift
f386b9002d
Use the stream_connect_pattern.
...
Use stream_connect_pattern.
Signed-off-by: Dominick Grift <domg472@gmail.com>
2010-09-15 17:42:28 +02:00
Dominick Grift
c5e7db7a71
Allow mpd_admin to manage mpd tmpfs content.
...
Signed-off-by: Dominick Grift <domg472@gmail.com>
2010-09-15 17:42:28 +02:00
Dominick Grift
0ba923e7d9
Source is required to search generic tmpfs directories to be able to interact with mpd tmpfs content.
...
Signed-off-by: Dominick Grift <domg472@gmail.com>
2010-09-15 17:42:28 +02:00
Dominick Grift
0ab415250b
Redundant: mpd_search_lib already includes files_search_var_lib.
...
Signed-off-by: Dominick Grift <domg472@gmail.com>
2010-09-15 17:42:28 +02:00
Dominick Grift
7d34935ff2
Memcached_admin is required to search generic pid directories to be able to manage memcached pid content.
...
Signed-off-by: Dominick Grift <domg472@gmail.com>
2010-09-15 17:42:28 +02:00
Dominick Grift
aa5baa96ed
Allow icecast_admin to ptrace and signal the icecast_t domain.
...
Signed-off-by: Dominick Grift <domg472@gmail.com>
2010-09-15 17:42:28 +02:00
Dominick Grift
4b81a55013
This is redundant since base user can search generic proc directories and included ps_process_pattern call permits all else.
...
Signed-off-by: Dominick Grift <domg472@gmail.com>
2010-09-15 17:42:28 +02:00
Dominick Grift
7d36c9fa13
Permission to search proc_t directories is required to be able to read abrt state.
...
Signed-off-by: Dominick Grift <domg472@gmail.com>
Permission to search generic proc directories is required to read hald_t state.
2010-09-15 17:42:28 +02:00
Dominick Grift
b36824efdf
Permit fetchmail_admin to ptrace and signal the fetchmail_t domain.
...
Signed-off-by: Dominick Grift <domg472@gmail.com>
2010-09-15 17:42:28 +02:00
Dominick Grift
cf152b4953
Replace some type statements by comma delimiters.
...
Signed-off-by: Dominick Grift <domg472@gmail.com>
2010-09-15 17:42:28 +02:00
Dominick Grift
47cf98ddd5
Permission to get attributes of target devicekit_t, devicekit_disk_t and devicekit_power_t domains are included with ps_process_patterns.
...
Signed-off-by: Dominick Grift <domg472@gmail.com>
2010-09-15 17:42:28 +02:00
Dominick Grift
5ecaacae61
Type system_cronjob_var_run_t is not required here.
...
Signed-off-by: Dominick Grift <domg472@gmail.com>
2010-09-15 17:42:27 +02:00
Dominick Grift
beb9c35b25
Types crontab_exec_t, cron_spool_t and user_cron_spool_t are required here.
...
Signed-off-by: Dominick Grift <domg472@gmail.com>
2010-09-15 17:42:27 +02:00
Dominick Grift
d8d33a15bf
Permission to search generic pid directories is included with files_pid_filetrans.
...
Signed-off-by: Dominick Grift <domg472@gmail.com>
2010-09-15 17:42:27 +02:00
Dominick Grift
0540e22fcc
Use ps_process_pattern to read state. Permission to seach proc_t directories is required to read automount state.
...
Signed-off-by: Dominick Grift <domg472@gmail.com>
2010-09-15 17:42:27 +02:00
Dominick Grift
cb76ff4560
Type xenstored_var_run_t is required here.
...
Signed-off-by: Dominick Grift <domg472@gmail.com>
2010-09-15 17:42:27 +02:00
Dominick Grift
8c0a06a69a
Type print_spool_t is not required here.
...
Signed-off-by: Dominick Grift <domg472@gmail.com>
2010-09-15 17:42:27 +02:00
Miroslav Grepl
3b0a9c74bb
Allow iscsid to manage tgtd semaphores
2010-09-15 16:50:07 +02:00
Dan Walsh
6dfe56b4e5
Merge branch 'master' of ssh://git.fedorahosted.org/git/selinux-policy
2010-09-14 16:39:10 -04:00
Dan Walsh
43a0339db4
add labeling for /root/.debug
2010-09-14 15:29:18 -04:00
Dan Walsh
d7f2020c46
- Allow all domains that can use cgroups to search tmpfs_t directory
...
- Allow init to send audit messages
2010-09-14 15:18:34 -04:00
Miroslav Grepl
323c9f13bb
Fixes for vmware-host policy
2010-09-14 19:28:55 +02:00