diff --git a/policy-20070703.patch b/policy-20070703.patch index 8c59509..329c6e3 100644 --- a/policy-20070703.patch +++ b/policy-20070703.patch @@ -7348,7 +7348,7 @@ diff --exclude-from=exclude -N -u -r nsaserefpolicy/policy/modules/services/cons +') diff --exclude-from=exclude -N -u -r nsaserefpolicy/policy/modules/services/consolekit.te serefpolicy-3.0.8/policy/modules/services/consolekit.te --- nsaserefpolicy/policy/modules/services/consolekit.te 2007-10-22 13:21:39.000000000 -0400 -+++ serefpolicy-3.0.8/policy/modules/services/consolekit.te 2007-12-02 21:15:34.000000000 -0500 ++++ serefpolicy-3.0.8/policy/modules/services/consolekit.te 2008-01-16 16:21:21.000000000 -0500 @@ -10,7 +10,6 @@ type consolekit_exec_t; init_daemon_domain(consolekit_t, consolekit_exec_t) @@ -7392,7 +7392,7 @@ diff --exclude-from=exclude -N -u -r nsaserefpolicy/policy/modules/services/cons optional_policy(` dbus_system_bus_client_template(consolekit, consolekit_t) dbus_send_system_bus(consolekit_t) -@@ -62,9 +71,17 @@ +@@ -62,9 +71,23 @@ optional_policy(` unconfined_dbus_chat(consolekit_t) ') @@ -7403,13 +7403,19 @@ diff --exclude-from=exclude -N -u -r nsaserefpolicy/policy/modules/services/cons xserver_read_all_users_xauth(consolekit_t) xserver_stream_connect_xdm_xserver(consolekit_t) + xserver_stream_connect_xdm(consolekit_t) - ') ++') + +optional_policy(` + #reading .Xauthity + unconfined_ptrace(consolekit_t) ++ unconfined_stream_connect(consolekit_t) +') + ++optional_policy(` ++ userdom_read_user_tmp_files(consolekit_t) + ') ++ ++ diff --exclude-from=exclude -N -u -r nsaserefpolicy/policy/modules/services/courier.te serefpolicy-3.0.8/policy/modules/services/courier.te --- nsaserefpolicy/policy/modules/services/courier.te 2007-10-22 13:21:39.000000000 -0400 +++ serefpolicy-3.0.8/policy/modules/services/courier.te 2007-12-02 21:15:34.000000000 -0500 @@ -19280,7 +19286,7 @@ diff --exclude-from=exclude -N -u -r nsaserefpolicy/policy/modules/system/unconf +/usr/sbin/sysreport -- gen_context(system_u:object_r:unconfined_notrans_exec_t,s0) diff --exclude-from=exclude -N -u -r nsaserefpolicy/policy/modules/system/unconfined.if serefpolicy-3.0.8/policy/modules/system/unconfined.if --- nsaserefpolicy/policy/modules/system/unconfined.if 2007-10-22 13:21:40.000000000 -0400 -+++ serefpolicy-3.0.8/policy/modules/system/unconfined.if 2007-12-13 12:37:30.000000000 -0500 ++++ serefpolicy-3.0.8/policy/modules/system/unconfined.if 2008-01-16 16:20:55.000000000 -0500 @@ -12,14 +12,13 @@ # interface(`unconfined_domain_noaudit',`