2012-10-15 10:26:48

by dominick.grift

[permalink] [raw]
Subject: [refpolicy] [PATCH] Changes to the modutils policy module


modutils_read_module_config() provides access to list modules_conf_t
directories so that we do not need a seperate
modutils_list_modules_config()

Signed-off-by: Dominick Grift <[email protected]>
diff --git a/policy/modules/system/modutils.if b/policy/modules/system/modutils.if
index 350c450..7449974 100644
--- a/policy/modules/system/modutils.if
+++ b/policy/modules/system/modutils.if
@@ -59,8 +59,9 @@
files_search_etc($1)
files_search_boot($1)

- read_files_pattern($1, modules_conf_t, modules_conf_t)
- read_lnk_files_pattern($1, modules_conf_t, modules_conf_t)
+ allow $1 modules_conf_t:dir list_dir_perms;
+ allow $1 modules_conf_t:file read_file_perms;
+ allow $1 modules_conf_t:lnk_file read_lnk_file_perms;
')

########################################


2012-10-19 13:20:11

by cpebenito

[permalink] [raw]
Subject: [refpolicy] [PATCH] Changes to the modutils policy module

On 10/15/12 06:26, Dominick Grift wrote:
>
> modutils_read_module_config() provides access to list modules_conf_t
> directories so that we do not need a seperate
> modutils_list_modules_config()
>
> Signed-off-by: Dominick Grift <[email protected]>
> diff --git a/policy/modules/system/modutils.if b/policy/modules/system/modutils.if
> index 350c450..7449974 100644
> --- a/policy/modules/system/modutils.if
> +++ b/policy/modules/system/modutils.if
> @@ -59,8 +59,9 @@
> files_search_etc($1)
> files_search_boot($1)
>
> - read_files_pattern($1, modules_conf_t, modules_conf_t)
> - read_lnk_files_pattern($1, modules_conf_t, modules_conf_t)
> + allow $1 modules_conf_t:dir list_dir_perms;
> + allow $1 modules_conf_t:file read_file_perms;
> + allow $1 modules_conf_t:lnk_file read_lnk_file_perms;
> ')

Merged.

--
Chris PeBenito
Tresys Technology, LLC
http://www.tresys.com | oss.tresys.com