1 |
commit: a8b24b78cfd0b208f8d092ca53b29cc4cb322e4b |
2 |
Author: Dominick Grift <dominick.grift <AT> gmail <DOT> com> |
3 |
AuthorDate: Sat Nov 9 09:45:18 2013 +0000 |
4 |
Commit: Sven Vermeulen <swift <AT> gentoo <DOT> org> |
5 |
CommitDate: Fri Dec 6 17:30:14 2013 +0000 |
6 |
URL: http://git.overlays.gentoo.org/gitweb/?p=proj/hardened-refpolicy.git;a=commit;h=a8b24b78 |
7 |
|
8 |
xserver: already allowed by auth_login_pgm_domain(xdm_t) |
9 |
|
10 |
Signed-off-by: Dominick Grift <dominick.grift <AT> gmail.com> |
11 |
|
12 |
--- |
13 |
policy/modules/services/xserver.te | 2 +- |
14 |
1 file changed, 1 insertion(+), 1 deletion(-) |
15 |
|
16 |
diff --git a/policy/modules/services/xserver.te b/policy/modules/services/xserver.te |
17 |
index 969ed6c..8e0d2d4 100644 |
18 |
--- a/policy/modules/services/xserver.te |
19 |
+++ b/policy/modules/services/xserver.te |
20 |
@@ -305,7 +305,7 @@ optional_policy(` |
21 |
# |
22 |
|
23 |
allow xdm_t self:capability { setgid setuid sys_resource kill sys_tty_config mknod chown dac_override dac_read_search fowner fsetid ipc_owner sys_nice sys_rawio net_bind_service }; |
24 |
-allow xdm_t self:process { setexec setpgid getsched setsched setrlimit signal_perms setkeycreate }; |
25 |
+allow xdm_t self:process { setexec setpgid getsched setsched setrlimit signal_perms }; |
26 |
allow xdm_t self:fifo_file rw_fifo_file_perms; |
27 |
allow xdm_t self:shm create_shm_perms; |
28 |
allow xdm_t self:sem create_sem_perms; |