From: cpebenito@tresys.com (Christopher J. PeBenito) Date: Fri, 03 Sep 2010 10:53:24 -0400 Subject: [refpolicy] [mmap zero conditional for unconfined patch ] 1/1] Allow unconfined domains to mmap low conditionally. In-Reply-To: <20100901155432.GA22316@localhost.localdomain> References: <20100901155432.GA22316@localhost.localdomain> Message-ID: <4C810BE4.8070403@tresys.com> To: refpolicy@oss.tresys.com List-Id: refpolicy.oss.tresys.com On 09/01/10 11:54, Dominick Grift wrote: > Allow unconfined domains to mmap low conditionally. I'm very concerned about adding this to all unconfined domains, even if its conditional. Is this from the Fedora policy? > Signed-off-by: Dominick Grift > --- > :100644 100644 416e668... a1bfac5... M policy/modules/system/unconfined.if > policy/modules/system/unconfined.if | 1 + > 1 files changed, 1 insertions(+), 0 deletions(-) > > diff --git a/policy/modules/system/unconfined.if b/policy/modules/system/unconfined.if > index 416e668..a1bfac5 100644 > --- a/policy/modules/system/unconfined.if > +++ b/policy/modules/system/unconfined.if > @@ -37,6 +37,7 @@ interface(`unconfined_domain_noaudit',` > kernel_unconfined($1) > corenet_unconfined($1) > dev_unconfined($1) > + domain_mmap_low($1) > domain_unconfined($1) > domain_dontaudit_read_all_domains_state($1) > domain_dontaudit_ptrace_all_domains($1) -- Chris PeBenito Tresys Technology, LLC www.tresys.com | oss.tresys.com