All of lore.kernel.org
 help / color / mirror / Atom feed
* [refpolicy] [PATCH/RFC 8/19]: patch set to update the git reference policy
@ 2011-01-24  0:44 Guido Trentalancia
  2011-01-24 14:04 ` Dominick Grift
  0 siblings, 1 reply; 23+ messages in thread
From: Guido Trentalancia @ 2011-01-24  0:44 UTC (permalink / raw)
  To: refpolicy

--- refpolicy-git-18012011-dbus-messaging/policy/modules/services/dbus.te	2011-01-23 23:13:48.168284256 +0100
+++ refpolicy-git-18012011-dbus/policy/modules/services/dbus.te	2011-01-23 23:11:46.430346876 +0100
@@ -52,7 +52,7 @@ ifdef(`enable_mls',`
 
 # dac_override: /var/run/dbus is owned by messagebus on Debian
 # cjp: dac_override should probably go in a distro_debian
-allow system_dbusd_t self:capability { dac_override setgid setpcap setuid };
+allow system_dbusd_t self:capability { dac_override setgid setpcap setuid sys_ptrace };
 dontaudit system_dbusd_t self:capability sys_tty_config;
 allow system_dbusd_t self:process { getattr getsched signal_perms setpgid getcap setcap };
 allow system_dbusd_t self:fifo_file rw_fifo_file_perms;
@@ -111,13 +111,20 @@ auth_read_pam_console_data(system_dbusd_
 corecmd_list_bin(system_dbusd_t)
 corecmd_read_bin_pipes(system_dbusd_t)
 corecmd_read_bin_sockets(system_dbusd_t)
+# needed for system-tools-backends
+corecmd_exec_shell(system_dbusd_t)
 
 domain_use_interactive_fds(system_dbusd_t)
 domain_read_all_domains_state(system_dbusd_t)
 
+files_search_default(system_dbusd_t)
+files_read_default_files(system_dbusd_t)
 files_read_etc_files(system_dbusd_t)
 files_list_home(system_dbusd_t)
-files_read_usr_files(system_dbusd_t)
+files_exec_bin_files(system_dbusd_t)
+files_exec_usr_files(system_dbusd_t)
+files_read_var_lib_files(system_dbusd_t)
+files_var_log_append(system_dbusd_t)
 
 init_use_fds(system_dbusd_t)
 init_use_script_ptys(system_dbusd_t)
@@ -141,6 +148,7 @@ optional_policy(`
 ')
 
 optional_policy(`
+	consolekit_read_pid_files(system_dbusd_t)
 	consolekit_dbus_send(system_dbusd_t)
 ')
 

^ permalink raw reply	[flat|nested] 23+ messages in thread

end of thread, other threads:[~2011-01-29  8:31 UTC | newest]

Thread overview: 23+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2011-01-24  0:44 [refpolicy] [PATCH/RFC 8/19]: patch set to update the git reference policy Guido Trentalancia
2011-01-24 14:04 ` Dominick Grift
2011-01-25  0:03   ` Guido Trentalancia
2011-01-25  9:28     ` Dominick Grift
2011-01-25 12:05       ` Dominick Grift
2011-01-25 13:57         ` Guido Trentalancia
2011-01-25 19:05   ` Guido Trentalancia
2011-01-25 19:19     ` Dominick Grift
2011-01-26  0:41       ` Guido Trentalancia
2011-01-26  8:17         ` Dominick Grift
2011-01-26 17:28           ` Guido Trentalancia
2011-01-26 17:36             ` Dominick Grift
2011-01-27  0:37               ` Guido Trentalancia
2011-01-27  9:16                 ` Dominick Grift
2011-01-27 20:36                   ` Guido Trentalancia
2011-01-27 20:42                     ` Dominick Grift
2011-01-29  1:32                       ` Guido Trentalancia
2011-01-28 17:01                         ` Dominick Grift
2011-01-28 18:38                           ` Guido Trentalancia
2011-01-28 18:47                             ` Dominick Grift
2011-01-29  3:49                               ` Guido Trentalancia
2011-01-29  8:31                                 ` Dominick Grift
2011-01-26 17:49             ` Dominick Grift

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.