From 20e47b2f4e83bda68bbdb7f85c9caa1afecb26dd Mon Sep 17 00:00:00 2001 From: Laurent Bigonville Date: Mon, 14 Jan 2013 14:29:04 +0100 Subject: [PATCH] Label executables under /usr/lib/gnome-settings-daemon/ as bin_t On Debian, part of gnome-settings-daemon is installed in that directory --- policy/modules/kernel/corecommands.fc | 1 + 1 file changed, 1 insertion(+) diff --git a/policy/modules/kernel/corecommands.fc b/policy/modules/kernel/corecommands.fc index 097b2f069..ae2e2899e 100644 --- a/policy/modules/kernel/corecommands.fc +++ b/policy/modules/kernel/corecommands.fc @@ -208,6 +208,7 @@ ifdef(`distro_gentoo',` /usr/lib/dpkg/.+ -- gen_context(system_u:object_r:bin_t,s0) /usr/lib/emacsen-common/.* gen_context(system_u:object_r:bin_t,s0) /usr/lib/gimp/.*/plug-ins(/.*)? gen_context(system_u:object_r:bin_t,s0) +/usr/lib/gnome-settings-daemon/.* -- gen_context(system_u:object_r:bin_t,s0) /usr/lib/gvfs/.* -- gen_context(system_u:object_r:bin_t,s0) /usr/lib/ipsec/.* -- gen_context(system_u:object_r:bin_t,s0) /usr/lib/kde4/libexec/.* -- gen_context(system_u:object_r:bin_t,s0)