1 |
commit: dae00b7c1f3b7f921fa9fa819f832a8f8f77f46e |
2 |
Author: Dominick Grift <dominick.grift <AT> gmail <DOT> com> |
3 |
AuthorDate: Wed Sep 26 10:28:36 2012 +0000 |
4 |
Commit: Sven Vermeulen <sven.vermeulen <AT> siphos <DOT> be> |
5 |
CommitDate: Thu Sep 27 17:55:07 2012 +0000 |
6 |
URL: http://git.overlays.gentoo.org/gitweb/?p=proj/hardened-refpolicy.git;a=commit;h=dae00b7c |
7 |
|
8 |
Remove redundant rules from apache_admin() |
9 |
|
10 |
ps_process_patterm() already provides this access |
11 |
|
12 |
Signed-off-by: Dominick Grift <dominick.grift <AT> gmail.com> |
13 |
Signed-off-by: Sven Vermeulen <sven.vermeulen <AT> siphos.be> |
14 |
|
15 |
--- |
16 |
policy/modules/contrib/apache.if | 5 ----- |
17 |
policy/modules/contrib/apache.te | 2 +- |
18 |
2 files changed, 1 insertions(+), 6 deletions(-) |
19 |
|
20 |
diff --git a/policy/modules/contrib/apache.if b/policy/modules/contrib/apache.if |
21 |
index c7835a8..166bce6 100644 |
22 |
--- a/policy/modules/contrib/apache.if |
23 |
+++ b/policy/modules/contrib/apache.if |
24 |
@@ -1382,11 +1382,6 @@ interface(`apache_admin',` |
25 |
admin_pattern($1, httpd_var_run_t) |
26 |
files_pid_filetrans($1, httpd_var_run_t, file) |
27 |
|
28 |
- kernel_search_proc($1) |
29 |
- allow $1 httpd_t:dir list_dir_perms; |
30 |
- |
31 |
- read_lnk_files_pattern($1, httpd_t, httpd_t) |
32 |
- |
33 |
admin_pattern($1, httpdcontent) |
34 |
admin_pattern($1, httpd_script_exec_type) |
35 |
admin_pattern($1, httpd_tmp_t) |
36 |
|
37 |
diff --git a/policy/modules/contrib/apache.te b/policy/modules/contrib/apache.te |
38 |
index 1450b4b..18c433c 100644 |
39 |
--- a/policy/modules/contrib/apache.te |
40 |
+++ b/policy/modules/contrib/apache.te |
41 |
@@ -1,4 +1,4 @@ |
42 |
-policy_module(apache, 2.5.2) |
43 |
+policy_module(apache, 2.5.3) |
44 |
|
45 |
# |
46 |
# NOTES: |