forked from pool/selinux-policy
42 lines
1.5 KiB
Diff
42 lines
1.5 KiB
Diff
|
Index: fedora-policy/policy/modules/contrib/java.te
|
||
|
===================================================================
|
||
|
--- fedora-policy.orig/policy/modules/contrib/java.te 2019-08-05 13:50:32.925673660 +0200
|
||
|
+++ fedora-policy/policy/modules/contrib/java.te 2019-08-05 14:06:51.896425229 +0200
|
||
|
@@ -21,6 +21,7 @@ roleattribute system_r java_roles;
|
||
|
attribute_role unconfined_java_roles;
|
||
|
|
||
|
type java_t, java_domain;
|
||
|
+typealias java_t alias java_domain_t;
|
||
|
type java_exec_t;
|
||
|
userdom_user_application_domain(java_t, java_exec_t)
|
||
|
typealias java_t alias { staff_javaplugin_t user_javaplugin_t sysadm_javaplugin_t };
|
||
|
@@ -71,19 +72,9 @@ can_exec(java_domain, { java_exec_t java
|
||
|
kernel_read_all_sysctls(java_domain)
|
||
|
kernel_search_vm_sysctl(java_domain)
|
||
|
kernel_read_network_state(java_domain)
|
||
|
-kernel_read_system_state(java_domain)
|
||
|
|
||
|
corecmd_search_bin(java_domain)
|
||
|
|
||
|
-corenet_all_recvfrom_unlabeled(java_domain)
|
||
|
-corenet_all_recvfrom_netlabel(java_domain)
|
||
|
-corenet_tcp_sendrecv_generic_if(java_domain)
|
||
|
-corenet_tcp_sendrecv_generic_node(java_domain)
|
||
|
-
|
||
|
-corenet_sendrecv_all_client_packets(java_domain)
|
||
|
-corenet_tcp_connect_all_ports(java_domain)
|
||
|
-corenet_tcp_sendrecv_all_ports(java_domain)
|
||
|
-
|
||
|
dev_read_sound(java_domain)
|
||
|
dev_write_sound(java_domain)
|
||
|
dev_read_urand(java_domain)
|
||
|
@@ -95,8 +86,6 @@ files_read_etc_runtime_files(java_domain
|
||
|
fs_getattr_all_fs(java_domain)
|
||
|
fs_dontaudit_rw_tmpfs_files(java_domain)
|
||
|
|
||
|
-logging_send_syslog_msg(java_domain)
|
||
|
-
|
||
|
miscfiles_read_localization(java_domain)
|
||
|
miscfiles_read_fonts(java_domain)
|
||
|
|