Gentoo Archives: gentoo-commits

From: Jason Zaman <perfinion@g.o>
To: gentoo-commits@l.g.o
Subject: [gentoo-commits] proj/hardened-refpolicy:next commit in: policy/modules/services/
Date: Sun, 10 Sep 2017 14:03:56
Message-Id: 1505048113.30a012aabb170a3570d6f1b6db26e684754f0609.perfinion@gentoo
1 commit: 30a012aabb170a3570d6f1b6db26e684754f0609
2 Author: Jason Zaman <jason <AT> perfinion <DOT> com>
3 AuthorDate: Sun Sep 10 12:55:13 2017 +0000
4 Commit: Jason Zaman <perfinion <AT> gentoo <DOT> org>
5 CommitDate: Sun Sep 10 12:55:13 2017 +0000
6 URL: https://gitweb.gentoo.org/proj/hardened-refpolicy.git/commit/?id=30a012aa
7
8 xserver: add map perms
9
10 policy/modules/services/xserver.te | 2 ++
11 1 file changed, 2 insertions(+)
12
13 diff --git a/policy/modules/services/xserver.te b/policy/modules/services/xserver.te
14 index a88e4af5..fe100b06 100644
15 --- a/policy/modules/services/xserver.te
16 +++ b/policy/modules/services/xserver.te
17 @@ -667,6 +667,7 @@ files_tmp_filetrans(xserver_t, xserver_tmp_t, { file dir sock_file })
18
19 filetrans_pattern(xserver_t, xserver_tmp_t, xserver_tmp_t, sock_file)
20
21 +allow xserver_t xserver_tmpfs_t:file map;
22 manage_dirs_pattern(xserver_t, xserver_tmpfs_t, xserver_tmpfs_t)
23 manage_files_pattern(xserver_t, xserver_tmpfs_t, xserver_tmpfs_t)
24 manage_lnk_files_pattern(xserver_t, xserver_tmpfs_t, xserver_tmpfs_t)
25 @@ -779,6 +780,7 @@ userdom_use_user_ttys(xserver_t)
26 userdom_setattr_user_ttys(xserver_t)
27 userdom_read_user_tmp_files(xserver_t)
28 userdom_rw_user_tmpfs_files(xserver_t)
29 +userdom_map_user_tmpfs_files(xserver_t)
30
31 xserver_use_user_fonts(xserver_t)