Gentoo Archives: gentoo-commits

From: Sven Vermeulen <swift@g.o>
To: gentoo-commits@l.g.o
Subject: [gentoo-commits] proj/hardened-refpolicy:master commit in: policy/modules/services/
Date: Fri, 06 Dec 2013 17:33:21
Message-Id: 1386351014.a8b24b78cfd0b208f8d092ca53b29cc4cb322e4b.swift@gentoo
1 commit: a8b24b78cfd0b208f8d092ca53b29cc4cb322e4b
2 Author: Dominick Grift <dominick.grift <AT> gmail <DOT> com>
3 AuthorDate: Sat Nov 9 09:45:18 2013 +0000
4 Commit: Sven Vermeulen <swift <AT> gentoo <DOT> org>
5 CommitDate: Fri Dec 6 17:30:14 2013 +0000
6 URL: http://git.overlays.gentoo.org/gitweb/?p=proj/hardened-refpolicy.git;a=commit;h=a8b24b78
7
8 xserver: already allowed by auth_login_pgm_domain(xdm_t)
9
10 Signed-off-by: Dominick Grift <dominick.grift <AT> gmail.com>
11
12 ---
13 policy/modules/services/xserver.te | 2 +-
14 1 file changed, 1 insertion(+), 1 deletion(-)
15
16 diff --git a/policy/modules/services/xserver.te b/policy/modules/services/xserver.te
17 index 969ed6c..8e0d2d4 100644
18 --- a/policy/modules/services/xserver.te
19 +++ b/policy/modules/services/xserver.te
20 @@ -305,7 +305,7 @@ optional_policy(`
21 #
22
23 allow xdm_t self:capability { setgid setuid sys_resource kill sys_tty_config mknod chown dac_override dac_read_search fowner fsetid ipc_owner sys_nice sys_rawio net_bind_service };
24 -allow xdm_t self:process { setexec setpgid getsched setsched setrlimit signal_perms setkeycreate };
25 +allow xdm_t self:process { setexec setpgid getsched setsched setrlimit signal_perms };
26 allow xdm_t self:fifo_file rw_fifo_file_perms;
27 allow xdm_t self:shm create_shm_perms;
28 allow xdm_t self:sem create_sem_perms;