selinux-policy/policy
Chris PeBenito a01a4a7183 trunk:
OK, the attached patch adds the following types for unprivileged clients.
 - unpriv_sepgsql_table_t
 - unpriv_sepgsql_sysobj_t
 - unpriv_sepgsql_proc_exec_t
 - unpriv_sepgsql_blob_t

These types are the default for unprivileged and unprefixed domains,
such as httpd_t and others.

In addition, TYPE_TRANSITION rules are moved to outside of tunable
of the sepgsql_enable_users_ddl. IIRC, it was enclosed within the
tunable because UBAC domains (user_t and so on) were allowed to
create sepgsql_table_t, and its default was pointed to this type
when sepgsql_enable_users_ddl is disabled.
However, it has different meanings now, so the TYPE_TRANSITION rules
should be unconditional.

KaiGai Kohei
2009-05-21 11:28:14 +00:00
..
flask se-postgresql update from kaigai 2009-05-07 12:35:32 +00:00
modules trunk: 2009-05-21 11:28:14 +00:00
support trunk: add open perm to sock_file. 2009-03-11 14:58:03 +00:00
constraints trunk: fix role change constraint. 2008-12-03 20:16:08 +00:00
global_booleans trunk: merge strict and targeted policies. merge shlib_t into lib_t. 2007-10-02 16:04:50 +00:00
global_tunables trunk: merge UBAC. 2008-11-05 16:10:46 +00:00
mcs se-postgresql update from kaigai 2009-05-07 12:35:32 +00:00
mls se-postgresql update from kaigai 2009-05-07 12:35:32 +00:00
policy_capabilities trunk: Enable network_peer_controls policy capability from Paul Moore. 2009-02-03 15:45:30 +00:00
rolemap trunk: merge UBAC. 2008-11-05 16:10:46 +00:00
users trunk: drop workaround rules. 2008-07-02 12:17:38 +00:00