selinux-refpolicy/policy/modules
Nicolas Iooss 27f4846ff8 userdomain: no longer allow unprivileged users to read kernel symbols
Unprivileged users don't need to read kallsyms and /boot/System.map.

This allow rule was introduced in the initial revision of userdomain.if in
2005, with commit b16c6b8c32a631a2e66265f6f60b664222760972:

    # cjp: why?
    bootloader_read_kernel_symbol_table($1_t)
2014-04-04 15:52:17 -04:00
..
admin Bump module versions for release. 2014-03-11 08:16:57 -04:00
apps Move modules to contrib submodule. 2011-09-09 10:10:03 -04:00
contrib@d243299725 Update contrib. 2014-03-14 11:48:15 -04:00
kernel Properly label git-shell and other git commands for Debian 2014-03-14 11:14:43 -04:00
roles Bump module versions for release. 2014-03-11 08:16:57 -04:00
services Whitespace fix in xserver.fc. 2014-03-14 11:17:44 -04:00
system userdomain: no longer allow unprivileged users to read kernel symbols 2014-04-04 15:52:17 -04:00