From: cpebenito@tresys.com (Christopher J. PeBenito) Date: Thu, 3 Jan 2013 10:13:28 -0500 Subject: [refpolicy] [PATCH 4/8] Update towards apache_manage_all_content In-Reply-To: <1355737370-27628-5-git-send-email-sven.vermeulen@siphos.be> References: <1355737370-27628-1-git-send-email-sven.vermeulen@siphos.be> <1355737370-27628-5-git-send-email-sven.vermeulen@siphos.be> Message-ID: <50E5A018.3000308@tresys.com> To: refpolicy@oss.tresys.com List-Id: refpolicy.oss.tresys.com On 12/17/12 04:42, Sven Vermeulen wrote: > The apache_manage_all_user_content interface has been deprecated and is now > pointing towards apache_manage_all_content. > > Signed-off-by: Sven Vermeulen > --- > policy/modules/admin/usermanage.te | 2 +- > 1 files changed, 1 insertions(+), 1 deletions(-) > > diff --git a/policy/modules/admin/usermanage.te b/policy/modules/admin/usermanage.te > index 673180c..9721f3b 100644 > --- a/policy/modules/admin/usermanage.te > +++ b/policy/modules/admin/usermanage.te > @@ -533,7 +533,7 @@ ifdef(`distro_redhat',` > ') > > optional_policy(` > - apache_manage_all_user_content(useradd_t) > + apache_manage_all_content(useradd_t) > ') > > optional_policy(` I disagree with this change. Useradd should only be creating user content, e.g. ~/public_html. This change would provide too much access. -- Chris PeBenito Tresys Technology, LLC www.tresys.com | oss.tresys.com