1 |
commit: eb7f919fae509df9aa4f003cd69208e62346c92b |
2 |
Author: Dominick Grift <dac.override <AT> gmail <DOT> com> |
3 |
AuthorDate: Thu Jul 28 19:44:46 2016 +0000 |
4 |
Commit: Sven Vermeulen <swift <AT> gentoo <DOT> org> |
5 |
CommitDate: Sun Jul 31 10:37:35 2016 +0000 |
6 |
URL: https://gitweb.gentoo.org/proj/hardened-refpolicy.git/commit/?id=eb7f919f |
7 |
|
8 |
Revert "dbus: allow system, and session bus clients to answer to dbus unconfined domains" |
9 |
|
10 |
Is considered a "security hole" |
11 |
|
12 |
This reverts commit 6bef7a14757124c56fadc08c255e9dd6c29a15f9. |
13 |
|
14 |
policy/modules/contrib/dbus.te | 4 ++-- |
15 |
1 file changed, 2 insertions(+), 2 deletions(-) |
16 |
|
17 |
diff --git a/policy/modules/contrib/dbus.te b/policy/modules/contrib/dbus.te |
18 |
index 0f1d8a7..255b860 100644 |
19 |
--- a/policy/modules/contrib/dbus.te |
20 |
+++ b/policy/modules/contrib/dbus.te |
21 |
@@ -260,5 +260,5 @@ optional_policy(` |
22 |
# Unconfined access to this module |
23 |
# |
24 |
|
25 |
-allow dbusd_unconfined { system_dbusd_t session_bus_type dbusd_session_bus_client dbusd_system_bus_client }:dbus all_dbus_perms; |
26 |
-allow { dbusd_session_bus_client dbusd_system_bus_client } dbusd_unconfined:dbus send_msg; |
27 |
+allow dbusd_unconfined { dbusd_session_bus_client dbusd_system_bus_client }:dbus send_msg; |
28 |
+allow dbusd_unconfined { system_dbusd_t session_bus_type }:dbus all_dbus_perms; |