selinux-policy/default_trans.patch

26 lines
946 B
Diff

diff --git a/policy/mcs b/policy/mcs
index ed7a0c1..90d0b1e 100644
--- a/policy/mcs
+++ b/policy/mcs
@@ -1,4 +1,6 @@
ifdef(`enable_mcs',`
+default_trans level dir_file_class_set parent;
+
#
# Define sensitivities
#
diff --git a/policy/modules/admin/bootloader.fc b/policy/modules/admin/bootloader.fc
index e117271..58b782e 100644
--- a/policy/modules/admin/bootloader.fc
+++ b/policy/modules/admin/bootloader.fc
@@ -3,9 +3,7 @@
/etc/yaboot\.conf.* -- gen_context(system_u:object_r:bootloader_etc_t,s0)
/sbin/grub.* -- gen_context(system_u:object_r:bootloader_exec_t,s0)
-/sbin/installkernel -- gen_context(system_u:object_r:bootloader_exec_t,s0)
/sbin/lilo.* -- gen_context(system_u:object_r:bootloader_exec_t,s0)
-/sbin/new-kernel-pkg -- gen_context(system_u:object_r:bootloader_exec_t,s0)
/sbin/ybin.* -- gen_context(system_u:object_r:bootloader_exec_t,s0)
/usr/sbin/grub -- gen_context(system_u:object_r:bootloader_exec_t,s0)