selinux-policy/policy
Dominick Grift 623e4f0885 1/1] Make the ability to mmap zero conditional where this is fapplicable.
Retry: forgot to include attribute mmap_low_domain_type attribute to domain_mmap_low()	:

Inspired by similar implementation in Fedora.
Wine and vbetool do not always actually need the ability to mmap a low area of the address space.
In some cases this can be silently denied.

Therefore introduce an interface that facilitates "mmap low" conditionally, and the corresponding boolean.
Also implement booleans for wine and vbetool that enables the ability to not audit attempts by wine and vbetool to mmap a low area of the address space.

Rename domain_mmap_low interface to domain_mmap_low_uncond.

Change call to domain_mmap_low to domain_mmap_low_uncond for xserver_t. Also move this call to distro redhat ifndef block because Redhat does not need this ability.

Signed-off-by: Dominick Grift <domg472@gmail.com>
2010-09-01 09:41:56 -04:00
..
flask Add module_request permission, from Dan Walsh. 2009-11-19 08:52:06 -05:00
modules 1/1] Make the ability to mmap zero conditional where this is fapplicable. 2010-09-01 09:41:56 -04:00
support Create_lnk_perms fix from Russell Coker. 2010-06-28 09:33:17 -04:00
constraints Fix a typo of SElinux to SELinux. 2009-10-22 09:47:52 -04:00
global_booleans trunk: merge strict and targeted policies. merge shlib_t into lib_t. 2007-10-02 16:04:50 +00:00
global_tunables remove read_default_t tunable 2009-07-23 08:58:35 -04:00
mcs revise MCS constraints to use only MCS-specific attributes. 2009-10-07 11:48:14 -04:00
mls Add trusted object condition to unix socket connectto/sendto, to fix label translation. 2010-04-29 11:29:39 -04:00
policy_capabilities trunk: update policycaps comments for sock_file open perm. 2009-07-01 13:34:54 +00:00
rolemap trunk: merge UBAC. 2008-11-05 16:10:46 +00:00
users Typo in policy/users 2009-12-18 08:51:58 -05:00