2010-03-01 17:47:51

by domg472

[permalink] [raw]
Subject: [refpolicy] [ authlogin patch 1/1] Fix auth_domtrans_chk_passwd to use read_file_perms to surpress open AVC denials.

Signed-off-by: Dominick Grift <[email protected]>
---
:100644 100644 8a89f59... 7f21603... M policy/modules/system/authlogin.if
policy/modules/system/authlogin.if | 2 +-
1 files changed, 1 insertions(+), 1 deletions(-)

diff --git a/policy/modules/system/authlogin.if b/policy/modules/system/authlogin.if
index 8a89f59..7f21603 100644
--- a/policy/modules/system/authlogin.if
+++ b/policy/modules/system/authlogin.if
@@ -300,7 +300,7 @@ interface(`auth_domtrans_chk_passwd',`
corecmd_search_bin($1)
domtrans_pattern($1, chkpwd_exec_t, chkpwd_t)

- dontaudit $1 shadow_t:file { getattr read };
+ dontaudit $1 shadow_t:file read_file_perms;

dev_read_rand($1)
dev_read_urand($1)
--
1.6.6.1

-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 198 bytes
Desc: not available
Url : http://oss.tresys.com/pipermail/refpolicy/attachments/20100301/d4eaec78/attachment.bin


2010-03-01 18:35:01

by cpebenito

[permalink] [raw]
Subject: [refpolicy] [ authlogin patch 1/1] Fix auth_domtrans_chk_passwd to use read_file_perms to surpress open AVC denials.

On Mon, 2010-03-01 at 18:47 +0100, Dominick Grift wrote:
> Signed-off-by: Dominick Grift <[email protected]>

Merged.

> ---
> :100644 100644 8a89f59... 7f21603... M policy/modules/system/authlogin.if
> policy/modules/system/authlogin.if | 2 +-
> 1 files changed, 1 insertions(+), 1 deletions(-)
>
> diff --git a/policy/modules/system/authlogin.if b/policy/modules/system/authlogin.if
> index 8a89f59..7f21603 100644
> --- a/policy/modules/system/authlogin.if
> +++ b/policy/modules/system/authlogin.if
> @@ -300,7 +300,7 @@ interface(`auth_domtrans_chk_passwd',`
> corecmd_search_bin($1)
> domtrans_pattern($1, chkpwd_exec_t, chkpwd_t)
>
> - dontaudit $1 shadow_t:file { getattr read };
> + dontaudit $1 shadow_t:file read_file_perms;
>
> dev_read_rand($1)
> dev_read_urand($1)
> _______________________________________________
> refpolicy mailing list
> refpolicy at oss.tresys.com
> http://oss.tresys.com/mailman/listinfo/refpolicy

--
Chris PeBenito
Tresys Technology, LLC
(410) 290-1411 x150