From: cpebenito@tresys.com (Christopher J. PeBenito) Date: Fri, 4 May 2012 08:44:41 -0400 Subject: [refpolicy] [PATCH 1/1] Adding dontaudits for xserver In-Reply-To: <20120421161742.GD28496@siphos.be> References: <20120421161615.GB28496@siphos.be> <20120421161742.GD28496@siphos.be> Message-ID: <4FA3CF39.2030303@tresys.com> To: refpolicy@oss.tresys.com List-Id: refpolicy.oss.tresys.com On 04/21/12 12:17, Sven Vermeulen wrote: > > Signed-off-by: Sven Vermeulen > --- > policy/modules/services/xserver.te | 2 ++ > 1 files changed, 2 insertions(+), 0 deletions(-) > > diff --git a/policy/modules/services/xserver.te b/policy/modules/services/xserver.te > index e92dddf..259a67b 100644 > --- a/policy/modules/services/xserver.te > +++ b/policy/modules/services/xserver.te > @@ -635,6 +635,8 @@ allow xserver_t xauth_home_t:file read_file_perms; > manage_files_pattern(xserver_t, xserver_log_t, xserver_log_t) > logging_log_filetrans(xserver_t, xserver_log_t, file) > > +domain_dontaudit_search_all_domains_state(xserver_t) > + > kernel_read_system_state(xserver_t) > kernel_read_device_sysctls(xserver_t) > kernel_read_modprobe_sysctls(xserver_t) Merged. -- Chris PeBenito Tresys Technology, LLC www.tresys.com | oss.tresys.com