2011-12-02 14:00:55

by Daniel Walsh

[permalink] [raw]
Subject: [refpolicy] New contrib policy for vdagent.

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

The new spice-vdagent package provides a SPICE agent for Linux guests.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.11 (GNU/Linux)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org/

iEYEARECAAYFAk7Y2hcACgkQrlYvE4MpobMWMgCg37K1fuBp9hZ/t5lI2XA47/IG
TWgAoOS0eeqI32qoe4ZwSbJyyL5tXsIy
=rImB
-----END PGP SIGNATURE-----
-------------- next part --------------
An embedded and charset-unspecified text was scrubbed...
Name: vdagent.patch
Url: http://oss.tresys.com/pipermail/refpolicy/attachments/20111202/89dba3f6/attachment.pl


2012-01-05 18:42:15

by sven.vermeulen

[permalink] [raw]
Subject: [refpolicy] New contrib policy for vdagent.

On Fri, Dec 02, 2011 at 09:00:55AM -0500, Daniel J Walsh wrote:
> The new spice-vdagent package provides a SPICE agent for Linux guests.
[...]
> +#####################################
> +## <summary>
> +## Getattr on vdagent executable.
> +## </summary>
> +## <param name="domain">
> +## <summary>
> +## Domain allowed access.
> +## </summary>
> +## </param>
> +#
> +interface(`vdagent_getattr_exec',`

Looking at shutdown and kudzu (those that I could find offering
similar interfaces) all name them _getattr_exec_files, so this might be
better named vdagent_getattr_exec_files instead.

Otherwise looks good.

Acked-by: Sven Vermeulen <[email protected]>