Gentoo Archives: gentoo-commits

From: Sven Vermeulen <swift@g.o>
To: gentoo-commits@l.g.o
Subject: [gentoo-commits] proj/hardened-refpolicy:master commit in: policy/modules/contrib/
Date: Sun, 31 Jul 2016 10:38:25
Message-Id: 1469961455.eb7f919fae509df9aa4f003cd69208e62346c92b.swift@gentoo
1 commit: eb7f919fae509df9aa4f003cd69208e62346c92b
2 Author: Dominick Grift <dac.override <AT> gmail <DOT> com>
3 AuthorDate: Thu Jul 28 19:44:46 2016 +0000
4 Commit: Sven Vermeulen <swift <AT> gentoo <DOT> org>
5 CommitDate: Sun Jul 31 10:37:35 2016 +0000
6 URL: https://gitweb.gentoo.org/proj/hardened-refpolicy.git/commit/?id=eb7f919f
7
8 Revert "dbus: allow system, and session bus clients to answer to dbus unconfined domains"
9
10 Is considered a "security hole"
11
12 This reverts commit 6bef7a14757124c56fadc08c255e9dd6c29a15f9.
13
14 policy/modules/contrib/dbus.te | 4 ++--
15 1 file changed, 2 insertions(+), 2 deletions(-)
16
17 diff --git a/policy/modules/contrib/dbus.te b/policy/modules/contrib/dbus.te
18 index 0f1d8a7..255b860 100644
19 --- a/policy/modules/contrib/dbus.te
20 +++ b/policy/modules/contrib/dbus.te
21 @@ -260,5 +260,5 @@ optional_policy(`
22 # Unconfined access to this module
23 #
24
25 -allow dbusd_unconfined { system_dbusd_t session_bus_type dbusd_session_bus_client dbusd_system_bus_client }:dbus all_dbus_perms;
26 -allow { dbusd_session_bus_client dbusd_system_bus_client } dbusd_unconfined:dbus send_msg;
27 +allow dbusd_unconfined { dbusd_session_bus_client dbusd_system_bus_client }:dbus send_msg;
28 +allow dbusd_unconfined { system_dbusd_t session_bus_type }:dbus all_dbus_perms;