All of lore.kernel.org
 help / color / mirror / Atom feed
From: cpebenito@tresys.com (Christopher J. PeBenito)
To: refpolicy@oss.tresys.com
Subject: [refpolicy] [ apps layer patch 1/1] apps: domain { allowed to transition, allowed access, to not audit }.
Date: Thu, 05 Aug 2010 10:03:44 -0400	[thread overview]
Message-ID: <4C5AC4C0.8050306@tresys.com> (raw)
In-Reply-To: <20100803155331.GA1609@localhost.localdomain>

On 08/03/10 11:53, Dominick Grift wrote:
> Signed-off-by: Dominick Grift<domg472@gmail.com>

Merged.

> ---
> :100644 100644 3f3bbe0... f2fae5a... M	policy/modules/apps/ada.if
> :100644 100644 d1c32ae... d28020f... M	policy/modules/apps/authbind.if
> :100644 100644 9601de0... b7bcad4... M	policy/modules/apps/gnome.if
> :100644 100644 793cde7... 40e0a2a... M	policy/modules/apps/gpg.if
> :100644 100644 9bb8f31... 0cfdf9f... M	policy/modules/apps/java.if
> :100644 100644 272e97a... 12b772f... M	policy/modules/apps/livecd.if
> :100644 100644 c3beba5... b55edd0... M	policy/modules/apps/loadkeys.if
> :100644 100644 a6af322... 1016374... M	policy/modules/apps/mono.if
> :100644 100644 344a5b3... 9a6d67d... M	policy/modules/apps/mozilla.if
> :100644 100644 c7ad0f5... d8ea41d... M	policy/modules/apps/mplayer.if
> :100644 100644 60b8bc2... 7e2092d... M	policy/modules/apps/podsleuth.if
> :100644 100644 f1c2698... 8a98580... M	policy/modules/apps/ptchown.if
> :100644 100644 9ebb373... a0c50da... M	policy/modules/apps/pulseaudio.if
> :100644 100644 255d869... c1d5f50... M	policy/modules/apps/qemu.if
> :100644 100644 3870eda... 7cdac1e... M	policy/modules/apps/rssh.if
> :100644 100644 7f47897... 1dc7a85... M	policy/modules/apps/seunshare.if
> :100644 100644 c2cc18d... a76e9f9... M	policy/modules/apps/thunderbird.if
> :100644 100644 cc4609c... 1b79617... M	policy/modules/apps/usernetctl.if
> :100644 100644 dac920d... 0412e70... M	policy/modules/apps/webalizer.if
> :100644 100644 f5217b8... c31ddb7... M	policy/modules/apps/wine.if
> :100644 100644 a7c27a5... ea6ffe6... M	policy/modules/apps/wireshark.if
> :100644 100644 5fb7790... 78543d4... M	policy/modules/apps/yam.if
>   policy/modules/apps/ada.if         |    4 ++--
>   policy/modules/apps/authbind.if    |    2 +-
>   policy/modules/apps/gnome.if       |    4 ++--
>   policy/modules/apps/gpg.if         |    2 +-
>   policy/modules/apps/java.if        |    8 ++++----
>   policy/modules/apps/livecd.if      |    2 +-
>   policy/modules/apps/loadkeys.if    |    4 ++--
>   policy/modules/apps/mono.if        |    4 ++--
>   policy/modules/apps/mozilla.if     |    6 +++---
>   policy/modules/apps/mplayer.if     |    2 +-
>   policy/modules/apps/podsleuth.if   |    2 +-
>   policy/modules/apps/ptchown.if     |    2 +-
>   policy/modules/apps/pulseaudio.if  |    4 ++--
>   policy/modules/apps/qemu.if        |    2 +-
>   policy/modules/apps/rssh.if        |    2 +-
>   policy/modules/apps/seunshare.if   |    2 +-
>   policy/modules/apps/thunderbird.if |    2 +-
>   policy/modules/apps/usernetctl.if  |    4 ++--
>   policy/modules/apps/webalizer.if   |    4 ++--
>   policy/modules/apps/wine.if        |    4 ++--
>   policy/modules/apps/wireshark.if   |    2 +-
>   policy/modules/apps/yam.if         |    4 ++--
>   22 files changed, 36 insertions(+), 36 deletions(-)
>
> diff --git a/policy/modules/apps/ada.if b/policy/modules/apps/ada.if
> index 3f3bbe0..f2fae5a 100644
> --- a/policy/modules/apps/ada.if
> +++ b/policy/modules/apps/ada.if
> @@ -6,7 +6,7 @@
>   ##</summary>
>   ##<param name="domain">
>   ##	<summary>
> -##	Domain allowed access.
> +##	Domain allowed to transition.
>   ##	</summary>
>   ##</param>
>   #
> @@ -26,7 +26,7 @@ interface(`ada_domtrans',`
>   ##</summary>
>   ##<param name="domain">
>   ##	<summary>
> -##	Domain allowed access.
> +##	Domain allowed to transition.
>   ##	</summary>
>   ##</param>
>   ##<param name="role">
> diff --git a/policy/modules/apps/authbind.if b/policy/modules/apps/authbind.if
> index d1c32ae..d28020f 100644
> --- a/policy/modules/apps/authbind.if
> +++ b/policy/modules/apps/authbind.if
> @@ -6,7 +6,7 @@
>   ##</summary>
>   ##<param name="domain">
>   ##	<summary>
> -##	Domain allowed access.
> +##	Domain allowed to transition.
>   ##	</summary>
>   ##</param>
>   #
> diff --git a/policy/modules/apps/gnome.if b/policy/modules/apps/gnome.if
> index 9601de0..b7bcad4 100644
> --- a/policy/modules/apps/gnome.if
> +++ b/policy/modules/apps/gnome.if
> @@ -41,7 +41,7 @@ interface(`gnome_role',`
>   ##</summary>
>   ##<param name="user_domain">
>   ##	<summary>
> -##	The type of the user domain.
> +##	Domain allowed access.
>   ##	</summary>
>   ##</param>
>   #
> @@ -78,7 +78,7 @@ interface(`gnome_domtrans_gconfd',`
>   ##</summary>
>   ##<param name="user_domain">
>   ##	<summary>
> -##	The type of the user domain.
> +##	Domain allowed access.
>   ##	</summary>
>   ##</param>
>   #
> diff --git a/policy/modules/apps/gpg.if b/policy/modules/apps/gpg.if
> index 793cde7..40e0a2a 100644
> --- a/policy/modules/apps/gpg.if
> +++ b/policy/modules/apps/gpg.if
> @@ -73,7 +73,7 @@ interface(`gpg_role',`
>   ##</summary>
>   ##<param name="domain">
>   ##	<summary>
> -##	Domain allowed access.
> +##	Domain allowed to transition.
>   ##	</summary>
>   ##</param>
>   #
> diff --git a/policy/modules/apps/java.if b/policy/modules/apps/java.if
> index 9bb8f31..0cfdf9f 100644
> --- a/policy/modules/apps/java.if
> +++ b/policy/modules/apps/java.if
> @@ -101,7 +101,7 @@ template(`java_role_template',`
>   ##</summary>
>   ##<param name="domain">
>   ##	<summary>
> -##	Domain allowed access.
> +##	Domain allowed to transition.
>   ##	</summary>
>   ##</param>
>   #
> @@ -120,7 +120,7 @@ template(`java_domtrans',`
>   ##</summary>
>   ##<param name="domain">
>   ##	<summary>
> -##	Domain allowed access.
> +##	Domain allowed to transition.
>   ##	</summary>
>   ##</param>
>   ##<param name="role">
> @@ -144,7 +144,7 @@ interface(`java_run',`
>   ##</summary>
>   ##<param name="domain">
>   ##	<summary>
> -##	Domain allowed access.
> +##	Domain allowed to transition.
>   ##	</summary>
>   ##</param>
>   #
> @@ -163,7 +163,7 @@ interface(`java_domtrans_unconfined',`
>   ##</summary>
>   ##<param name="domain">
>   ##	<summary>
> -##	Domain allowed access.
> +##	Domain allowed to transition.
>   ##	</summary>
>   ##</param>
>   ##<param name="role">
> diff --git a/policy/modules/apps/livecd.if b/policy/modules/apps/livecd.if
> index 272e97a..12b772f 100644
> --- a/policy/modules/apps/livecd.if
> +++ b/policy/modules/apps/livecd.if
> @@ -25,7 +25,7 @@ interface(`livecd_domtrans',`
>   ##</summary>
>   ##<param name="domain">
>   ##	<summary>
> -##	Domain allowed access.
> +##	Domain allowed to transition.
>   ##	</summary>
>   ##</param>
>   ##<param name="role">
> diff --git a/policy/modules/apps/loadkeys.if b/policy/modules/apps/loadkeys.if
> index c3beba5..b55edd0 100644
> --- a/policy/modules/apps/loadkeys.if
> +++ b/policy/modules/apps/loadkeys.if
> @@ -6,7 +6,7 @@
>   ##</summary>
>   ##<param name="domain">
>   ##	<summary>
> -##	Domain allowed access.
> +##	Domain allowed to transition.
>   ##	</summary>
>   ##</param>
>   #
> @@ -29,7 +29,7 @@ interface(`loadkeys_domtrans',`
>   ##</summary>
>   ##<param name="domain">
>   ##	<summary>
> -##	Domain allowed access.
> +##	Domain allowed to transition.
>   ##	</summary>
>   ##</param>
>   ##<param name="role">
> diff --git a/policy/modules/apps/mono.if b/policy/modules/apps/mono.if
> index a6af322..1016374 100644
> --- a/policy/modules/apps/mono.if
> +++ b/policy/modules/apps/mono.if
> @@ -62,7 +62,7 @@ template(`mono_role_template',`
>   ##</summary>
>   ##<param name="domain">
>   ##	<summary>
> -##	Domain allowed access.
> +##	Domain allowed to transition.
>   ##	</summary>
>   ##</param>
>   #
> @@ -82,7 +82,7 @@ interface(`mono_domtrans',`
>   ##</summary>
>   ##<param name="domain">
>   ##	<summary>
> -##	Domain allowed access.
> +##	Domain allowed to transition.
>   ##	</summary>
>   ##</param>
>   ##<param name="role">
> diff --git a/policy/modules/apps/mozilla.if b/policy/modules/apps/mozilla.if
> index 344a5b3..9a6d67d 100644
> --- a/policy/modules/apps/mozilla.if
> +++ b/policy/modules/apps/mozilla.if
> @@ -99,7 +99,7 @@ interface(`mozilla_write_user_home_files',`
>   ##</summary>
>   ##<param name="domain">
>   ##	<summary>
> -##	Domain allowed access.
> +##	Domain to not audit.
>   ##	</summary>
>   ##</param>
>   #
> @@ -117,7 +117,7 @@ interface(`mozilla_dontaudit_rw_user_home_files',`
>   ##</summary>
>   ##<param name="domain">
>   ##	<summary>
> -##	Domain allowed access.
> +##	Domain to not audit.
>   ##	</summary>
>   ##</param>
>   #
> @@ -154,7 +154,7 @@ interface(`mozilla_execmod_user_home_files',`
>   ##</summary>
>   ##<param name="domain">
>   ##	<summary>
> -##	Domain allowed access.
> +##	Domain allowed to transition.
>   ##	</summary>
>   ##</param>
>   #
> diff --git a/policy/modules/apps/mplayer.if b/policy/modules/apps/mplayer.if
> index c7ad0f5..d8ea41d 100644
> --- a/policy/modules/apps/mplayer.if
> +++ b/policy/modules/apps/mplayer.if
> @@ -53,7 +53,7 @@ interface(`mplayer_role',`
>   ##</summary>
>   ##<param name="domain">
>   ##	<summary>
> -##	Domain allowed access.
> +##	Domain allowed to transition.
>   ##	</summary>
>   ##</param>
>   #
> diff --git a/policy/modules/apps/podsleuth.if b/policy/modules/apps/podsleuth.if
> index 60b8bc2..7e2092d 100644
> --- a/policy/modules/apps/podsleuth.if
> +++ b/policy/modules/apps/podsleuth.if
> @@ -26,7 +26,7 @@ interface(`podsleuth_domtrans',`
>   ##</summary>
>   ##<param name="domain">
>   ##	<summary>
> -##	Domain allowed access
> +##	Domain allowed to transition.
>   ##	</summary>
>   ##</param>
>   ##<param name="role">
> diff --git a/policy/modules/apps/ptchown.if b/policy/modules/apps/ptchown.if
> index f1c2698..8a98580 100644
> --- a/policy/modules/apps/ptchown.if
> +++ b/policy/modules/apps/ptchown.if
> @@ -25,7 +25,7 @@ interface(`ptchown_domtrans',`
>   ##</summary>
>   ##<param name="domain">
>   ##	<summary>
> -##	Domain allowed access.
> +##	Domain allowed to transition.
>   ##	</summary>
>   ##</param>
>   ##<param name="role">
> diff --git a/policy/modules/apps/pulseaudio.if b/policy/modules/apps/pulseaudio.if
> index 9ebb373..a0c50da 100644
> --- a/policy/modules/apps/pulseaudio.if
> +++ b/policy/modules/apps/pulseaudio.if
> @@ -64,7 +64,7 @@ interface(`pulseaudio_domtrans',`
>   ##</summary>
>   ##<param name="domain">
>   ##	<summary>
> -##	Domain allowed access.
> +##	Domain allowed to transition.
>   ##	</summary>
>   ##</param>
>   ##<param name="role">
> @@ -88,7 +88,7 @@ interface(`pulseaudio_run',`
>   ##</summary>
>   ##<param name="domain">
>   ##<summary>
> -##	Domain allowed to transition.
> +##	Domain allowed access.
>   ##</summary>
>   ##</param>
>   #
> diff --git a/policy/modules/apps/qemu.if b/policy/modules/apps/qemu.if
> index 255d869..c1d5f50 100644
> --- a/policy/modules/apps/qemu.if
> +++ b/policy/modules/apps/qemu.if
> @@ -161,7 +161,7 @@ interface(`qemu_domtrans',`
>   ##</summary>
>   ##<param name="domain">
>   ##	<summary>
> -##	Domain allowed access.
> +##	Domain allowed to transition.
>   ##	</summary>
>   ##</param>
>   ##<param name="role">
> diff --git a/policy/modules/apps/rssh.if b/policy/modules/apps/rssh.if
> index 3870eda..7cdac1e 100644
> --- a/policy/modules/apps/rssh.if
> +++ b/policy/modules/apps/rssh.if
> @@ -33,7 +33,7 @@ interface(`rssh_role',`
>   ##</summary>
>   ##<param name="domain">
>   ##	<summary>
> -##	Domain allowed access.
> +##	Domain allowed to transition.
>   ##	</summary>
>   ##</param>
>   #
> diff --git a/policy/modules/apps/seunshare.if b/policy/modules/apps/seunshare.if
> index 7f47897..1dc7a85 100644
> --- a/policy/modules/apps/seunshare.if
> +++ b/policy/modules/apps/seunshare.if
> @@ -25,7 +25,7 @@ interface(`seunshare_domtrans',`
>   ##</summary>
>   ##<param name="domain">
>   ##	<summary>
> -##	Domain allowed access.
> +##	Domain allowed to transition.
>   ##	</summary>
>   ##</param>
>   ##<param name="role">
> diff --git a/policy/modules/apps/thunderbird.if b/policy/modules/apps/thunderbird.if
> index c2cc18d..a76e9f9 100644
> --- a/policy/modules/apps/thunderbird.if
> +++ b/policy/modules/apps/thunderbird.if
> @@ -50,7 +50,7 @@ interface(`thunderbird_role',`
>   ##</summary>
>   ##<param name="domain">
>   ##	<summary>
> -##	Domain allowed access.
> +##	Domain allowed to transition.
>   ##	</summary>
>   ##</param>
>   #
> diff --git a/policy/modules/apps/usernetctl.if b/policy/modules/apps/usernetctl.if
> index cc4609c..1b79617 100644
> --- a/policy/modules/apps/usernetctl.if
> +++ b/policy/modules/apps/usernetctl.if
> @@ -6,7 +6,7 @@
>   ##</summary>
>   ##<param name="domain">
>   ##	<summary>
> -##	Domain allowed access.
> +##	Domain allowed to transition.
>   ##	</summary>
>   ##</param>
>   #
> @@ -25,7 +25,7 @@ interface(`usernetctl_domtrans',`
>   ##</summary>
>   ##<param name="domain">
>   ##	<summary>
> -##	Domain allowed access.
> +##	Domain allowed to transition.
>   ##	</summary>
>   ##</param>
>   ##<param name="role">
> diff --git a/policy/modules/apps/webalizer.if b/policy/modules/apps/webalizer.if
> index dac920d..0412e70 100644
> --- a/policy/modules/apps/webalizer.if
> +++ b/policy/modules/apps/webalizer.if
> @@ -6,7 +6,7 @@
>   ##</summary>
>   ##<param name="domain">
>   ##	<summary>
> -##	Domain allowed access.
> +##	Domain allowed to transition.
>   ##	</summary>
>   ##</param>
>   #
> @@ -25,7 +25,7 @@ interface(`webalizer_domtrans',`
>   ##</summary>
>   ##<param name="domain">
>   ##	<summary>
> -##	Domain allowed access.
> +##	Domain allowed to transition.
>   ##	</summary>
>   ##</param>
>   ##<param name="role">
> diff --git a/policy/modules/apps/wine.if b/policy/modules/apps/wine.if
> index f5217b8..c31ddb7 100644
> --- a/policy/modules/apps/wine.if
> +++ b/policy/modules/apps/wine.if
> @@ -116,7 +116,7 @@ template(`wine_role_template',`
>   ##</summary>
>   ##<param name="domain">
>   ##	<summary>
> -##	Domain allowed access.
> +##	Domain allowed to transition.
>   ##	</summary>
>   ##</param>
>   #
> @@ -136,7 +136,7 @@ interface(`wine_domtrans',`
>   ##</summary>
>   ##<param name="domain">
>   ##	<summary>
> -##	Domain allowed access.
> +##	Domain allowed to transition.
>   ##	</summary>
>   ##</param>
>   ##<param name="role">
> diff --git a/policy/modules/apps/wireshark.if b/policy/modules/apps/wireshark.if
> index a7c27a5..ea6ffe6 100644
> --- a/policy/modules/apps/wireshark.if
> +++ b/policy/modules/apps/wireshark.if
> @@ -42,7 +42,7 @@ interface(`wireshark_role',`
>   ##</summary>
>   ##<param name="domain">
>   ##	<summary>
> -##	Domain allowed access.
> +##	Domain allowed to transition.
>   ##	</summary>
>   ##</param>
>   #
> diff --git a/policy/modules/apps/yam.if b/policy/modules/apps/yam.if
> index 5fb7790..78543d4 100644
> --- a/policy/modules/apps/yam.if
> +++ b/policy/modules/apps/yam.if
> @@ -6,7 +6,7 @@
>   ##</summary>
>   ##<param name="domain">
>   ##	<summary>
> -##	Domain allowed access.
> +##	Domain allowed to transition.
>   ##	</summary>
>   ##</param>
>   #
> @@ -26,7 +26,7 @@ interface(`yam_domtrans',`
>   ##</summary>
>   ##<param name="domain">
>   ##	<summary>
> -##	Domain allowed access.
> +##	Domain allowed to transition.
>   ##	</summary>
>   ##</param>
>   ##<param name="role">
>
>
>
> _______________________________________________
> refpolicy mailing list
> refpolicy at oss.tresys.com
> http://oss.tresys.com/mailman/listinfo/refpolicy


-- 
Chris PeBenito
Tresys Technology, LLC
www.tresys.com | oss.tresys.com

      reply	other threads:[~2010-08-05 14:03 UTC|newest]

Thread overview: 2+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2010-08-03 15:53 [refpolicy] [ apps layer patch 1/1] apps: domain { allowed to transition, allowed access, to not audit } Dominick Grift
2010-08-05 14:03 ` Christopher J. PeBenito [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=4C5AC4C0.8050306@tresys.com \
    --to=cpebenito@tresys.com \
    --cc=refpolicy@oss.tresys.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.