From 8e7d43c8ac88ded5fa17e015951dfd75bae9cf72 Mon Sep 17 00:00:00 2001 From: Chris PeBenito Date: Fri, 13 Jun 2008 13:33:36 +0000 Subject: [PATCH] trunk: additional patch from kaigai to fix up some type transitions for unpriv clients. --- policy/modules/services/postgresql.if | 9 ++++----- 1 file changed, 4 insertions(+), 5 deletions(-) diff --git a/policy/modules/services/postgresql.if b/policy/modules/services/postgresql.if index 7fbba939e..7bf8152dd 100644 --- a/policy/modules/services/postgresql.if +++ b/policy/modules/services/postgresql.if @@ -340,18 +340,17 @@ interface(`postgresql_unpriv_client',` class db_blob all_db_blob_perms; attribute sepgsql_client_type; - attribute sepgsql_database_type; - type sepgsql_table_t, sepgsql_proc_t, sepgsql_blob_t; + type sepgsql_db_t, sepgsql_table_t, sepgsql_proc_t, sepgsql_blob_t; type sepgsql_trusted_proc_t, sepgsql_trusted_domain_t; ') typeattribute $1 sepgsql_client_type; - type_transition $1 sepgsql_database_type:db_table sepgsql_table_t; - type_transition $1 sepgsql_database_type:db_procedure sepgsql_proc_t; - type_transition $1 sepgsql_database_type:db_blob sepgsql_blob_t; + type_transition $1 sepgsql_db_t:db_table sepgsql_table_t; + type_transition $1 sepgsql_db_t:db_procedure sepgsql_proc_t; + type_transition $1 sepgsql_db_t:db_blob sepgsql_blob_t; type_transition $1 sepgsql_trusted_proc_t:process sepgsql_trusted_domain_t; allow $1 sepgsql_trusted_domain_t:process transition;