Changes to the xserver policy module

These interfaces are needed by at least plymouth

Signed-off-by: Dominick Grift <dominick.grift@gmail.com>
This commit is contained in:
Dominick Grift 2012-10-17 14:28:38 +02:00 committed by Chris PeBenito
parent 8b1aa69f1f
commit 4034f4a4b4
1 changed files with 41 additions and 0 deletions

View File

@ -711,6 +711,47 @@ interface(`xserver_dontaudit_rw_xdm_pipes',`
dontaudit $1 xdm_t:fifo_file rw_fifo_file_perms;
')
########################################
## <summary>
## Create, read, write, and delete
## xdm_spool files.
## </summary>
## <param name="domain">
## <summary>
## Domain allowed access.
## </summary>
## </param>
#
interface(`xserver_manage_spool_files_xdm',`
gen_require(`
type xdm_spool_t;
')
files_search_spool($1)
manage_files_pattern($1, xdm_spool_t, xdm_spool_t)
')
########################################
## <summary>
## Read xdm process state files.
## </summary>
## <param name="domain">
## <summary>
## Domain allowed access.
## </summary>
## </param>
#
interface(`xserver_read_state_xdm',`
gen_require(`
type xdm_t;
')
kernel_search_proc($1)
allow $1 xdm_t:dir list_dir_perms;
allow $1 xdm_t:file read_file_perms;
allow $1 xdm_t:lnk_file read_lnk_file_perms;
')
########################################
## <summary>
## Connect to XDM over a unix domain