From: cpebenito@tresys.com (Christopher J. PeBenito) Date: Fri, 08 Oct 2010 08:46:27 -0400 Subject: [refpolicy] [ patch 34/44] su: permission sets. In-Reply-To: <1286216636-28449-36-git-send-email-domg472@gmail.com> References: <1286216636-28449-1-git-send-email-domg472@gmail.com> <1286216636-28449-36-git-send-email-domg472@gmail.com> Message-ID: <4CAF12A3.6050402@tresys.com> To: refpolicy@oss.tresys.com List-Id: refpolicy.oss.tresys.com On 10/04/10 14:23, Dominick Grift wrote: > diff --git a/policy/modules/admin/su.if b/policy/modules/admin/su.if > index 2a4e0db..800852f 100644 > --- a/policy/modules/admin/su.if > +++ b/policy/modules/admin/su.if > @@ -138,7 +138,7 @@ template(`su_restricted_domain_template', ` > > ifdef(`TODO',` > # Caused by su - init scripts > - dontaudit $1_su_t initrc_devpts_t:chr_file { getattr ioctl }; > + dontaudit $1_su_t initrc_devpts_t:chr_file { getattr_chr_file_perms ioctl }; > ') dnl end TODO > ') It would be best to create an interface so the TODO can be removed. -- Chris PeBenito Tresys Technology, LLC www.tresys.com | oss.tresys.com