From: cpebenito@tresys.com (Christopher J. PeBenito) Date: Fri, 08 Oct 2010 08:51:27 -0400 Subject: [refpolicy] [ patch 33/44] su: wants to search callers keyring. In-Reply-To: <1286216636-28449-35-git-send-email-domg472@gmail.com> References: <1286216636-28449-1-git-send-email-domg472@gmail.com> <1286216636-28449-35-git-send-email-domg472@gmail.com> Message-ID: <4CAF13CF.7000004@tresys.com> To: refpolicy@oss.tresys.com List-Id: refpolicy.oss.tresys.com On 10/04/10 14:23, Dominick Grift wrote: > > Signed-off-by: Dominick Grift Merged. > :100644 100644 dd9c7bf... 2a4e0db... M policy/modules/admin/su.if > policy/modules/admin/su.if | 2 ++ > 1 files changed, 2 insertions(+), 0 deletions(-) > > diff --git a/policy/modules/admin/su.if b/policy/modules/admin/su.if > index dd9c7bf..2a4e0db 100644 > --- a/policy/modules/admin/su.if > +++ b/policy/modules/admin/su.if > @@ -186,6 +186,8 @@ template(`su_role_template',` > allow $1_su_t self:netlink_audit_socket { nlmsg_relay create_netlink_socket_perms }; > allow $1_su_t self:key { search write }; > > + allow $1_su_t $3:key search; > + > # Transition from the user domain to this domain. > domtrans_pattern($3, su_exec_t, $1_su_t) > -- Chris PeBenito Tresys Technology, LLC www.tresys.com | oss.tresys.com