Gentoo Archives: gentoo-commits

From: Sven Vermeulen <sven.vermeulen@××××××.be>
To: gentoo-commits@l.g.o
Subject: [gentoo-commits] proj/hardened-refpolicy:master commit in: policy/modules/contrib/
Date: Thu, 27 Sep 2012 18:07:25
Message-Id: 1348768507.dae00b7c1f3b7f921fa9fa819f832a8f8f77f46e.SwifT@gentoo
1 commit: dae00b7c1f3b7f921fa9fa819f832a8f8f77f46e
2 Author: Dominick Grift <dominick.grift <AT> gmail <DOT> com>
3 AuthorDate: Wed Sep 26 10:28:36 2012 +0000
4 Commit: Sven Vermeulen <sven.vermeulen <AT> siphos <DOT> be>
5 CommitDate: Thu Sep 27 17:55:07 2012 +0000
6 URL: http://git.overlays.gentoo.org/gitweb/?p=proj/hardened-refpolicy.git;a=commit;h=dae00b7c
7
8 Remove redundant rules from apache_admin()
9
10 ps_process_patterm() already provides this access
11
12 Signed-off-by: Dominick Grift <dominick.grift <AT> gmail.com>
13 Signed-off-by: Sven Vermeulen <sven.vermeulen <AT> siphos.be>
14
15 ---
16 policy/modules/contrib/apache.if | 5 -----
17 policy/modules/contrib/apache.te | 2 +-
18 2 files changed, 1 insertions(+), 6 deletions(-)
19
20 diff --git a/policy/modules/contrib/apache.if b/policy/modules/contrib/apache.if
21 index c7835a8..166bce6 100644
22 --- a/policy/modules/contrib/apache.if
23 +++ b/policy/modules/contrib/apache.if
24 @@ -1382,11 +1382,6 @@ interface(`apache_admin',`
25 admin_pattern($1, httpd_var_run_t)
26 files_pid_filetrans($1, httpd_var_run_t, file)
27
28 - kernel_search_proc($1)
29 - allow $1 httpd_t:dir list_dir_perms;
30 -
31 - read_lnk_files_pattern($1, httpd_t, httpd_t)
32 -
33 admin_pattern($1, httpdcontent)
34 admin_pattern($1, httpd_script_exec_type)
35 admin_pattern($1, httpd_tmp_t)
36
37 diff --git a/policy/modules/contrib/apache.te b/policy/modules/contrib/apache.te
38 index 1450b4b..18c433c 100644
39 --- a/policy/modules/contrib/apache.te
40 +++ b/policy/modules/contrib/apache.te
41 @@ -1,4 +1,4 @@
42 -policy_module(apache, 2.5.2)
43 +policy_module(apache, 2.5.3)
44
45 #
46 # NOTES: