Login take 4 from Russell Coker.

I have used optional sections for dbus and xserver as requested and also
fixed a minor issue of a rule not being in the correct section.

Please merge this.
This commit is contained in:
Chris PeBenito 2017-04-26 06:26:50 -04:00
parent 6a87c0f587
commit 61e9ec3240
3 changed files with 5 additions and 1 deletions

@ -1 +1 @@
Subproject commit f22b859da477bf59374ea572449d023fc007e957 Subproject commit 23c5c78943224a02037fa2789205183c2ff2939a

View File

@ -118,6 +118,9 @@ files_dontaudit_search_var(chkpwd_t)
fs_dontaudit_getattr_xattr_fs(chkpwd_t) fs_dontaudit_getattr_xattr_fs(chkpwd_t)
selinux_get_enforce_mode(chkpwd_t)
selinux_getattr_fs(chkpwd_t)
term_dontaudit_use_console(chkpwd_t) term_dontaudit_use_console(chkpwd_t)
term_dontaudit_use_unallocated_ttys(chkpwd_t) term_dontaudit_use_unallocated_ttys(chkpwd_t)
term_dontaudit_use_generic_ptys(chkpwd_t) term_dontaudit_use_generic_ptys(chkpwd_t)

View File

@ -33,6 +33,7 @@ role system_r types sulogin_t;
# #
allow local_login_t self:capability { chown dac_override fowner fsetid kill setgid setuid sys_nice sys_resource sys_tty_config }; allow local_login_t self:capability { chown dac_override fowner fsetid kill setgid setuid sys_nice sys_resource sys_tty_config };
dontaudit local_login_t self:capability net_admin;
allow local_login_t self:process { setexec setrlimit setsched }; allow local_login_t self:process { setexec setrlimit setsched };
allow local_login_t self:fd use; allow local_login_t self:fd use;
allow local_login_t self:fifo_file rw_fifo_file_perms; allow local_login_t self:fifo_file rw_fifo_file_perms;