2010-03-03 15:10:56

by domg472

[permalink] [raw]
Subject: [refpolicy] [ userdom patch 1/1] Fix userdom_write_user_tmp_sockets to use write_sock_file_perms to allow domains to open user_tmp_t sock_files.

Signed-off-by: Dominick Grift <[email protected]>
---
:100644 100644 cd08bc3... adbe494... M policy/modules/system/userdomain.if
policy/modules/system/userdomain.if | 2 +-
1 files changed, 1 insertions(+), 1 deletions(-)

diff --git a/policy/modules/system/userdomain.if b/policy/modules/system/userdomain.if
index cd08bc3..adbe494 100644
--- a/policy/modules/system/userdomain.if
+++ b/policy/modules/system/userdomain.if
@@ -2069,7 +2069,7 @@ interface(`userdom_write_user_tmp_sockets',`
type user_tmp_t;
')

- allow $1 user_tmp_t:sock_file write;
+ allow $1 user_tmp_t:sock_file write_sock_file_perms;
files_search_tmp($1)
')

--
1.6.6.1

-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 198 bytes
Desc: not available
Url : http://oss.tresys.com/pipermail/refpolicy/attachments/20100303/8304a884/attachment.bin


2010-03-03 15:32:22

by cpebenito

[permalink] [raw]
Subject: [refpolicy] [ userdom patch 1/1] Fix userdom_write_user_tmp_sockets to use write_sock_file_perms to allow domains to open user_tmp_t sock_files.

On Wed, 2010-03-03 at 16:10 +0100, Dominick Grift wrote:
> Signed-off-by: Dominick Grift <[email protected]>

Merged.

> ---
> :100644 100644 cd08bc3... adbe494... M policy/modules/system/userdomain.if
> policy/modules/system/userdomain.if | 2 +-
> 1 files changed, 1 insertions(+), 1 deletions(-)
>
> diff --git a/policy/modules/system/userdomain.if b/policy/modules/system/userdomain.if
> index cd08bc3..adbe494 100644
> --- a/policy/modules/system/userdomain.if
> +++ b/policy/modules/system/userdomain.if
> @@ -2069,7 +2069,7 @@ interface(`userdom_write_user_tmp_sockets',`
> type user_tmp_t;
> ')
>
> - allow $1 user_tmp_t:sock_file write;
> + allow $1 user_tmp_t:sock_file write_sock_file_perms;
> files_search_tmp($1)
> ')
>
> _______________________________________________
> refpolicy mailing list
> refpolicy at oss.tresys.com
> http://oss.tresys.com/mailman/listinfo/refpolicy

--
Chris PeBenito
Tresys Technology, LLC
(410) 290-1411 x150