From: domg472@gmail.com (Dominick Grift) Date: Mon, 4 Oct 2010 20:23:45 +0200 Subject: [refpolicy] [ patch 33/44] su: wants to search callers keyring. In-Reply-To: <1286216636-28449-1-git-send-email-domg472@gmail.com> References: <1286216636-28449-1-git-send-email-domg472@gmail.com> Message-ID: <1286216636-28449-35-git-send-email-domg472@gmail.com> To: refpolicy@oss.tresys.com List-Id: refpolicy.oss.tresys.com Signed-off-by: Dominick Grift --- :100644 100644 dd9c7bf... 2a4e0db... M policy/modules/admin/su.if policy/modules/admin/su.if | 2 ++ 1 files changed, 2 insertions(+), 0 deletions(-) diff --git a/policy/modules/admin/su.if b/policy/modules/admin/su.if index dd9c7bf..2a4e0db 100644 --- a/policy/modules/admin/su.if +++ b/policy/modules/admin/su.if @@ -186,6 +186,8 @@ template(`su_role_template',` allow $1_su_t self:netlink_audit_socket { nlmsg_relay create_netlink_socket_perms }; allow $1_su_t self:key { search write }; + allow $1_su_t $3:key search; + # Transition from the user domain to this domain. domtrans_pattern($3, su_exec_t, $1_su_t) -- 1.7.2.3