Gentoo Archives: gentoo-commits

From: Sven Vermeulen <sven.vermeulen@××××××.be>
To: gentoo-commits@l.g.o
Subject: [gentoo-commits] proj/hardened-refpolicy:master commit in: policy/modules/contrib/
Date: Thu, 01 Nov 2012 21:42:00
Message-Id: 1351802993.f0a503655e462176fadc4d439ece0f071e9a3aa8.SwifT@gentoo
1 commit: f0a503655e462176fadc4d439ece0f071e9a3aa8
2 Author: Sven Vermeulen <sven.vermeulen <AT> siphos <DOT> be>
3 AuthorDate: Thu Nov 1 20:49:53 2012 +0000
4 Commit: Sven Vermeulen <sven.vermeulen <AT> siphos <DOT> be>
5 CommitDate: Thu Nov 1 20:49:53 2012 +0000
6 URL: http://git.overlays.gentoo.org/gitweb/?p=proj/hardened-refpolicy.git;a=commit;h=f0a50365
7
8 Reshuffle gentoo specific consolekit changes
9
10 ---
11 policy/modules/contrib/consolekit.te | 14 ++++++++++----
12 1 files changed, 10 insertions(+), 4 deletions(-)
13
14 diff --git a/policy/modules/contrib/consolekit.te b/policy/modules/contrib/consolekit.te
15 index d8cca4a..5dce1a8 100644
16 --- a/policy/modules/contrib/consolekit.te
17 +++ b/policy/modules/contrib/consolekit.te
18 @@ -67,10 +67,7 @@ mcs_ptrace_all(consolekit_t)
19
20 term_use_all_terms(consolekit_t)
21
22 -# consolekit daemon creates /var/run/console for tagfiles
23 -auth_generic_run_filetrans_pam_console_data(consolekit_t, dir, "console")
24 auth_use_nsswitch(consolekit_t)
25 -auth_create_pam_console_data_dirs(consolekit_t)
26 auth_manage_pam_console_data(consolekit_t)
27 auth_write_login_records(consolekit_t)
28
29 @@ -82,6 +79,16 @@ miscfiles_read_localization(consolekit_t)
30 userdom_dontaudit_read_user_home_content_files(consolekit_t)
31 userdom_read_user_tmp_files(consolekit_t)
32
33 +ifdef(`distro_gentoo',`
34 + # consolekit daemon creates /var/run/console for tagfiles
35 + auth_generic_run_filetrans_pam_console_data(consolekit_t, dir, "console")
36 + auth_create_pam_console_data_dirs(consolekit_t)
37 +
38 + optional_policy(`
39 + dbus_read_lib_files(consolekit_t)
40 + ')
41 +')
42 +
43 tunable_policy(`use_nfs_home_dirs',`
44 fs_read_nfs_files(consolekit_t)
45 ')
46 @@ -92,7 +99,6 @@ tunable_policy(`use_samba_home_dirs',`
47
48 optional_policy(`
49 dbus_system_domain(consolekit_t, consolekit_exec_t)
50 - dbus_read_lib_files(consolekit_t)
51
52 optional_policy(`
53 hal_dbus_chat(consolekit_t)