All of lore.kernel.org
 help / color / mirror / Atom feed
* [refpolicy] [PATCH] Add system_r role to unconfined_u and staff_u users
@ 2012-09-22 13:21 Laurent Bigonville
  2012-10-08 21:21 ` Laurent Bigonville
  0 siblings, 1 reply; 5+ messages in thread
From: Laurent Bigonville @ 2012-09-22 13:21 UTC (permalink / raw)
  To: refpolicy

From: Laurent Bigonville <bigon@bigon.be>

This is necessary for at least pulseaudio and libvirtd running in the
user session.
---
 policy/users |    4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)

diff --git a/policy/users b/policy/users
index c4ebc7e..8d13fbc 100644
--- a/policy/users
+++ b/policy/users
@@ -25,11 +25,11 @@ gen_user(system_u,, system_r, s0, s0 - mls_systemhigh, mcs_allcats)
 # permit any access to such users, then remove this entry.
 #
 gen_user(user_u, user, user_r, s0, s0)
-gen_user(staff_u, staff, staff_r sysadm_r ifdef(`enable_mls',`secadm_r auditadm_r'), s0, s0 - mls_systemhigh, mcs_allcats)
+gen_user(staff_u, staff, staff_r sysadm_r system_r ifdef(`enable_mls',`secadm_r auditadm_r'), s0, s0 - mls_systemhigh, mcs_allcats)
 gen_user(sysadm_u, sysadm, sysadm_r, s0, s0 - mls_systemhigh, mcs_allcats)
 
 # Until order dependence is fixed for users:
-gen_user(unconfined_u, unconfined, unconfined_r, s0, s0 - mls_systemhigh, mcs_allcats)
+gen_user(unconfined_u, unconfined, unconfined_r system_r, s0, s0 - mls_systemhigh, mcs_allcats)
 
 #
 # The following users correspond to Unix identities.
-- 
1.7.10.4

^ permalink raw reply related	[flat|nested] 5+ messages in thread

end of thread, other threads:[~2012-10-09 19:01 UTC | newest]

Thread overview: 5+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2012-09-22 13:21 [refpolicy] [PATCH] Add system_r role to unconfined_u and staff_u users Laurent Bigonville
2012-10-08 21:21 ` Laurent Bigonville
2012-10-09 14:00   ` Christopher J. PeBenito
2012-10-09 18:57     ` Laurent Bigonville
2012-10-09 19:01       ` Sven Vermeulen

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.