From: cpebenito@tresys.com (Christopher J. PeBenito) Date: Fri, 08 Oct 2010 08:59:53 -0400 Subject: [refpolicy] [ patch 37/44] sudo: do not audit attempts to search /root. In-Reply-To: <1286216636-28449-39-git-send-email-domg472@gmail.com> References: <1286216636-28449-1-git-send-email-domg472@gmail.com> <1286216636-28449-39-git-send-email-domg472@gmail.com> Message-ID: <4CAF15C9.4000605@tresys.com> To: refpolicy@oss.tresys.com List-Id: refpolicy.oss.tresys.com On 10/04/10 14:23, Dominick Grift wrote: > diff --git a/policy/modules/admin/sudo.if b/policy/modules/admin/sudo.if > index ca36b15..da2afce 100644 > --- a/policy/modules/admin/sudo.if > +++ b/policy/modules/admin/sudo.if > @@ -101,6 +101,7 @@ template(`sudo_role_template',` > files_read_usr_symlinks($1_sudo_t) > files_getattr_usr_files($1_sudo_t) > # for some PAM modules and for cwd > + files_dontaudit_list_default($1_sudo_t) > files_dontaudit_search_home($1_sudo_t) > files_list_tmp($1_sudo_t) I'm confused, /root shouldn't be default_t. -- Chris PeBenito Tresys Technology, LLC www.tresys.com | oss.tresys.com