1 |
commit: f0a503655e462176fadc4d439ece0f071e9a3aa8 |
2 |
Author: Sven Vermeulen <sven.vermeulen <AT> siphos <DOT> be> |
3 |
AuthorDate: Thu Nov 1 20:49:53 2012 +0000 |
4 |
Commit: Sven Vermeulen <sven.vermeulen <AT> siphos <DOT> be> |
5 |
CommitDate: Thu Nov 1 20:49:53 2012 +0000 |
6 |
URL: http://git.overlays.gentoo.org/gitweb/?p=proj/hardened-refpolicy.git;a=commit;h=f0a50365 |
7 |
|
8 |
Reshuffle gentoo specific consolekit changes |
9 |
|
10 |
--- |
11 |
policy/modules/contrib/consolekit.te | 14 ++++++++++---- |
12 |
1 files changed, 10 insertions(+), 4 deletions(-) |
13 |
|
14 |
diff --git a/policy/modules/contrib/consolekit.te b/policy/modules/contrib/consolekit.te |
15 |
index d8cca4a..5dce1a8 100644 |
16 |
--- a/policy/modules/contrib/consolekit.te |
17 |
+++ b/policy/modules/contrib/consolekit.te |
18 |
@@ -67,10 +67,7 @@ mcs_ptrace_all(consolekit_t) |
19 |
|
20 |
term_use_all_terms(consolekit_t) |
21 |
|
22 |
-# consolekit daemon creates /var/run/console for tagfiles |
23 |
-auth_generic_run_filetrans_pam_console_data(consolekit_t, dir, "console") |
24 |
auth_use_nsswitch(consolekit_t) |
25 |
-auth_create_pam_console_data_dirs(consolekit_t) |
26 |
auth_manage_pam_console_data(consolekit_t) |
27 |
auth_write_login_records(consolekit_t) |
28 |
|
29 |
@@ -82,6 +79,16 @@ miscfiles_read_localization(consolekit_t) |
30 |
userdom_dontaudit_read_user_home_content_files(consolekit_t) |
31 |
userdom_read_user_tmp_files(consolekit_t) |
32 |
|
33 |
+ifdef(`distro_gentoo',` |
34 |
+ # consolekit daemon creates /var/run/console for tagfiles |
35 |
+ auth_generic_run_filetrans_pam_console_data(consolekit_t, dir, "console") |
36 |
+ auth_create_pam_console_data_dirs(consolekit_t) |
37 |
+ |
38 |
+ optional_policy(` |
39 |
+ dbus_read_lib_files(consolekit_t) |
40 |
+ ') |
41 |
+') |
42 |
+ |
43 |
tunable_policy(`use_nfs_home_dirs',` |
44 |
fs_read_nfs_files(consolekit_t) |
45 |
') |
46 |
@@ -92,7 +99,6 @@ tunable_policy(`use_samba_home_dirs',` |
47 |
|
48 |
optional_policy(` |
49 |
dbus_system_domain(consolekit_t, consolekit_exec_t) |
50 |
- dbus_read_lib_files(consolekit_t) |
51 |
|
52 |
optional_policy(` |
53 |
hal_dbus_chat(consolekit_t) |