Remove redundant Gentoo-specific term_append_unallocated_ttys(syslogd_t)
Since commit 0fd9dc55
, logging.te contains:
term_write_all_user_ttys(syslogd_t)
As "write" is a superset of "append", this rule is no longer needed:
term_append_unallocated_ttys(syslogd_t)
While at it, add a comment which explains why
term_dontaudit_setattr_unallocated_ttys is needed.
This commit is contained in:
parent
6a201e405b
commit
0cd1ea9596
@ -483,7 +483,7 @@ userdom_dontaudit_search_user_home_dirs(syslogd_t)
|
||||
ifdef(`distro_gentoo',`
|
||||
# default gentoo syslog-ng config appends kernel
|
||||
# and high priority messages to /dev/tty12
|
||||
term_append_unallocated_ttys(syslogd_t)
|
||||
# and chown/chgrp/chmod /dev/tty12, which is denied
|
||||
term_dontaudit_setattr_unallocated_ttys(syslogd_t)
|
||||
')
|
||||
|
||||
|
Loading…
Reference in New Issue
Block a user