2008-09-24 19:57:39

by Daniel Walsh

[permalink] [raw]
Subject: [refpolicy] services_soundserver.patch

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

http://people.fedoraproject.org/~dwalsh/SELinux/F10/services_soundserver.patch

Add initrc script support

allow admin to start/stop service

Admin needs admin_pattern on all file types

soundd_etc_t is a confif file

soundd needs dac_override privs

communicates on a unix_stream_socket

Does a getattr on all file systems

starts the alsa command

creates a soundd_var_run_t directory and creates sock_files in it

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.9 (GNU/Linux)
Comment: Using GnuPG with Fedora - http://enigmail.mozdev.org

iEYEARECAAYFAkjam7MACgkQrlYvE4MpobN4owCgvSzFc26tedKYMY5aIFqfNqoW
YnoAn3zRpA0E7nv1dV3+mnnQpkEJthtB
=pb+c
-----END PGP SIGNATURE-----


2008-10-08 15:54:12

by cpebenito

[permalink] [raw]
Subject: [refpolicy] services_soundserver.patch

On Wed, 2008-09-24 at 15:57 -0400, Daniel J Walsh wrote:
> http://people.fedoraproject.org/~dwalsh/SELinux/F10/services_soundserver.patch
>
> Add initrc script support
>
> allow admin to start/stop service
>
> Admin needs admin_pattern on all file types
>
> soundd_etc_t is a confif file
>
> soundd needs dac_override privs
>
> communicates on a unix_stream_socket
>
> Does a getattr on all file systems
>
> starts the alsa command
>
> creates a soundd_var_run_t directory and creates sock_files in it

Merged except for the redundant +fs_getattr_all_fs(soundd_t).

--
Chris PeBenito
Tresys Technology, LLC
(410) 290-1411 x150