From: cpebenito@tresys.com (Christopher J. PeBenito) Date: Fri, 11 May 2012 11:38:17 -0400 Subject: [refpolicy] [PATCH v2 1/1] Allow groupadd/passwd to read selinux config and context files In-Reply-To: <20120507184734.GB5410@siphos.be> References: <20120507184734.GB5410@siphos.be> Message-ID: <4FAD3269.3070506@tresys.com> To: refpolicy@oss.tresys.com List-Id: refpolicy.oss.tresys.com On 05/07/12 14:47, Sven Vermeulen wrote: > Recent shadow utils require listing of SELinux config as well as read the file context information. > > See also > - https://bugs.gentoo.org/show_bug.cgi?id=413061 > - https://bugs.gentoo.org/show_bug.cgi?id=413065 > > Changes since v1 > - use correct domain (passwd_t) > > Signed-off-by: Sven Vermeulen > --- > policy/modules/admin/usermanage.te | 4 +++- > 1 files changed, 3 insertions(+), 1 deletions(-) > > diff --git a/policy/modules/admin/usermanage.te b/policy/modules/admin/usermanage.te > index 3e144b9..c822dcb 100644 > --- a/policy/modules/admin/usermanage.te > +++ b/policy/modules/admin/usermanage.te > @@ -241,6 +241,7 @@ auth_relabel_shadow(groupadd_t) > auth_etc_filetrans_shadow(groupadd_t) > > seutil_read_config(groupadd_t) > +seutil_read_file_contexts(groupadd_t) > > userdom_use_unpriv_users_fds(groupadd_t) > # for when /root is the cwd > @@ -336,7 +337,8 @@ logging_send_syslog_msg(passwd_t) > > miscfiles_read_localization(passwd_t) > > -seutil_dontaudit_search_config(passwd_t) > +seutil_read_config(passwd_t) > +seutil_read_file_contexts(passwd_t) > > userdom_use_user_terminals(passwd_t) > userdom_use_unpriv_users_fds(passwd_t) Merged. -- Chris PeBenito Tresys Technology, LLC www.tresys.com | oss.tresys.com