From: domg472@gmail.com (Dominick Grift) Date: Mon, 4 Oct 2010 20:23:49 +0200 Subject: [refpolicy] [ patch 37/44] sudo: do not audit attempts to search /root. In-Reply-To: <1286216636-28449-1-git-send-email-domg472@gmail.com> References: <1286216636-28449-1-git-send-email-domg472@gmail.com> Message-ID: <1286216636-28449-39-git-send-email-domg472@gmail.com> To: refpolicy@oss.tresys.com List-Id: refpolicy.oss.tresys.com Signed-off-by: Dominick Grift --- :100644 100644 ca36b15... da2afce... M policy/modules/admin/sudo.if policy/modules/admin/sudo.if | 1 + 1 files changed, 1 insertions(+), 0 deletions(-) diff --git a/policy/modules/admin/sudo.if b/policy/modules/admin/sudo.if index ca36b15..da2afce 100644 --- a/policy/modules/admin/sudo.if +++ b/policy/modules/admin/sudo.if @@ -101,6 +101,7 @@ template(`sudo_role_template',` files_read_usr_symlinks($1_sudo_t) files_getattr_usr_files($1_sudo_t) # for some PAM modules and for cwd + files_dontaudit_list_default($1_sudo_t) files_dontaudit_search_home($1_sudo_t) files_list_tmp($1_sudo_t) -- 1.7.2.3