From: cpebenito@tresys.com (Christopher J. PeBenito) Date: Fri, 20 Apr 2012 16:11:27 -0400 Subject: [refpolicy] [PATCH 7/13] Adding dontaudits for xserver In-Reply-To: <20120322201046.GH3387@siphos.be> References: <20120322200229.GA3387@siphos.be> <20120322201046.GH3387@siphos.be> Message-ID: <4F91C2EF.7020706@tresys.com> To: refpolicy@oss.tresys.com List-Id: refpolicy.oss.tresys.com On 03/22/12 16:10, Sven Vermeulen wrote: > > Signed-off-by: Sven Vermeulen > --- > policy/modules/services/xserver.te | 2 ++ > 1 files changed, 2 insertions(+), 0 deletions(-) > > diff --git a/policy/modules/services/xserver.te b/policy/modules/services/xserver.te > index e92dddf..f5ffb79 100644 > --- a/policy/modules/services/xserver.te > +++ b/policy/modules/services/xserver.te > @@ -370,6 +370,8 @@ manage_files_pattern(xdm_t, xserver_log_t, xserver_log_t) > manage_fifo_files_pattern(xdm_t, xserver_log_t, xserver_log_t) > logging_log_filetrans(xdm_t, xserver_log_t, file) > > +domain_dontaudit_search_all_domains_state(xserver_t) > + > kernel_read_system_state(xdm_t) > kernel_read_kernel_sysctls(xdm_t) > kernel_read_net_sysctls(xdm_t) This is in xdm_t's section. It it supposed to be xdm_t or is it supposed to be xserver_t? In either case, it needs to move. -- Chris PeBenito Tresys Technology, LLC www.tresys.com | oss.tresys.com