selinux-refpolicy/policy
Sven Vermeulen f28f89acb8 Allow mozilla/firefox to manage tempfiles
On Wed, Mar 23, 2011 at 09:10:37AM -0400, Christopher J. PeBenito wrote:
> >  userdom_use_user_ptys(mozilla_t)
> > +userdom_manage_user_tmp_files(mozilla_t)
> > +userdom_manage_user_tmp_sockets(mozilla_t)
>
> Do you have more info on these?  Such as what files and sockets are
> being managed?

Not anymore apparently. Been running now for quite some time without these
privileges and I get no problems with it. Retry:

Mozilla/Firefox creates temporary files for its plugin support (for instance
while viewing flc streams), like /tmp/plugtmp/plugin-crossdomain.xml.

Update policy to allow it to create its own tmp type and perform a file
transition when creating a file or directory in a tmp_t location (like
/tmp).

Signed-off-by: Sven Vermeulen <sven.vermeulen@siphos.be>
2011-05-04 09:14:26 -04:00
..
flask Update access vectors. 2011-03-28 11:45:46 -04:00
modules Allow mozilla/firefox to manage tempfiles 2011-05-04 09:14:26 -04:00
support Add tun_socket ubac constraint and add tun_socket to socket_class_set. 2010-11-11 09:48:43 -05:00
constraints Add tun_socket ubac constraint and add tun_socket to socket_class_set. 2010-11-11 09:48:43 -05:00
global_booleans
global_tunables Rename allow_console tunable to console_login. 2011-01-14 11:44:42 -05:00
mcs Pull in mcs constraint changes from Fedora. 2011-03-31 08:28:01 -04:00
mls l1 domby l2 for contains MLS constraint 2011-02-16 10:00:11 -05:00
policy_capabilities
rolemap
users