1 |
commit: 30a012aabb170a3570d6f1b6db26e684754f0609 |
2 |
Author: Jason Zaman <jason <AT> perfinion <DOT> com> |
3 |
AuthorDate: Sun Sep 10 12:55:13 2017 +0000 |
4 |
Commit: Jason Zaman <perfinion <AT> gentoo <DOT> org> |
5 |
CommitDate: Sun Sep 10 12:55:13 2017 +0000 |
6 |
URL: https://gitweb.gentoo.org/proj/hardened-refpolicy.git/commit/?id=30a012aa |
7 |
|
8 |
xserver: add map perms |
9 |
|
10 |
policy/modules/services/xserver.te | 2 ++ |
11 |
1 file changed, 2 insertions(+) |
12 |
|
13 |
diff --git a/policy/modules/services/xserver.te b/policy/modules/services/xserver.te |
14 |
index a88e4af5..fe100b06 100644 |
15 |
--- a/policy/modules/services/xserver.te |
16 |
+++ b/policy/modules/services/xserver.te |
17 |
@@ -667,6 +667,7 @@ files_tmp_filetrans(xserver_t, xserver_tmp_t, { file dir sock_file }) |
18 |
|
19 |
filetrans_pattern(xserver_t, xserver_tmp_t, xserver_tmp_t, sock_file) |
20 |
|
21 |
+allow xserver_t xserver_tmpfs_t:file map; |
22 |
manage_dirs_pattern(xserver_t, xserver_tmpfs_t, xserver_tmpfs_t) |
23 |
manage_files_pattern(xserver_t, xserver_tmpfs_t, xserver_tmpfs_t) |
24 |
manage_lnk_files_pattern(xserver_t, xserver_tmpfs_t, xserver_tmpfs_t) |
25 |
@@ -779,6 +780,7 @@ userdom_use_user_ttys(xserver_t) |
26 |
userdom_setattr_user_ttys(xserver_t) |
27 |
userdom_read_user_tmp_files(xserver_t) |
28 |
userdom_rw_user_tmpfs_files(xserver_t) |
29 |
+userdom_map_user_tmpfs_files(xserver_t) |
30 |
|
31 |
xserver_use_user_fonts(xserver_t) |