From: dwalsh@redhat.com (Daniel J Walsh) Date: Tue, 24 Nov 2009 15:10:35 -0500 Subject: [refpolicy] system_iscsi.patch In-Reply-To: <1259078909.27504.805.camel@gorn.columbia.tresys.com> References: <4AFC87EA.3090704@redhat.com> <1259078909.27504.805.camel@gorn.columbia.tresys.com> Message-ID: <4B0C3DBB.7000104@redhat.com> To: refpolicy@oss.tresys.com List-Id: refpolicy.oss.tresys.com On 11/24/2009 11:08 AM, Christopher J. PeBenito wrote: > On Thu, 2009-11-12 at 17:10 -0500, Daniel J Walsh wrote: >> http://people.fedoraproject.org/~dwalsh/SELinux/F12/system_iscsi.patch >> >> ISCSI calls getpw >> >> reads localization >> >> does a ps > > Does this really need to be allowed? > >> used debugfs > > > Otherwise merged. > > Probably can be changed to a dontaudit.