commit: 7802f6b2a69eefd11feb78859d2feb58be59a99b
Author: Sven Vermeulen <swift <AT> gentoo <DOT> org>
AuthorDate: Mon Oct 24 16:41:27 2016 +0000
Commit: Sven Vermeulen <swift <AT> gentoo <DOT> org>
CommitDate: Mon Oct 24 16:41:27 2016 +0000
URL:
https://gitweb.gentoo.org/proj/hardened-refpolicy.git/commit/?id=7802f6b2
Switch from cert_home_t to user_cert_t
The type for user home certificate directories (and files) is
user_cert_t. Remove all references to its code, and instead use the new
type.
Keep an alias at hand for third party SELinux policy modules though.
policy/modules/system/miscfiles.fc | 2 --
policy/modules/system/miscfiles.if | 40 ++-----------------------------------
policy/modules/system/miscfiles.te | 7 -------
policy/modules/system/userdomain.if | 2 --
policy/modules/system/userdomain.te | 7 +++++++
5 files changed, 9 insertions(+), 49 deletions(-)
diff --git a/policy/modules/system/miscfiles.fc
b/policy/modules/system/miscfiles.fc
index be0b6a1..42ac30b 100644
--- a/policy/modules/system/miscfiles.fc
+++ b/policy/modules/system/miscfiles.fc
@@ -103,8 +103,6 @@ ifdef(`distro_redhat',`
/var/spool/postfix/etc/localtime -- gen_context(system_u:object_r:locale_t,s0)
')
-HOME_DIR/.pki(/.*)? gen_context(system_u:object_r:cert_home_t,s0)
-
ifdef(`distro_gentoo',`
/etc/fonts(/.*)? gen_context(system_u:object_r:fonts_t,s0)
')
diff --git a/policy/modules/system/miscfiles.if
b/policy/modules/system/miscfiles.if
index 63ed47f..93e6acb 100644
--- a/policy/modules/system/miscfiles.if
+++ b/policy/modules/system/miscfiles.if
@@ -97,15 +97,8 @@ interface(`miscfiles_read_generic_certs',`
## </param>
#
interface(`miscfiles_manage_user_certs',`
- gen_require(`
- type cert_home_t;
- ')
-
- manage_dirs_pattern($1, cert_home_t, cert_home_t)
- manage_files_pattern($1, cert_home_t, cert_home_t)
- manage_lnk_files_pattern($1, cert_home_t, cert_home_t)
-
- userdom_search_user_home_dirs($1)
+ userdom_manage_user_certs($1)
+ refpolicywarn(`$0() has been deprecated, please use
userdom_manage_user_certs() instead.')
')
########################################
@@ -213,35 +206,6 @@ interface(`miscfiles_manage_cert_files',`
########################################
## <summary>
-## Automatically use the cert_home_t label for selected resources created
-## in a users home directory
-## </summary>
-## <param name="domain">
-## <summary>
-## Domain allowed access
-## </summary>
-## </param>
-## <param name="class">
-## <summary>
-## Resource type(s) for which the label should be used
-## </summary>
-## </param>
-## <param name="filename" optional="true">
-## <summary>
-## Name of the resource that is being created
-## </summary>
-## </param>
-#
-interface(`miscfiles_user_home_dir_filetrans_cert_home',`
- gen_require(`
- type cert_home_t;
- ')
-
- userdom_user_home_dir_filetrans($1, cert_home_t, $2, $3)
-')
-
-########################################
-## <summary>
## Read fonts.
## </summary>
## <param name="domain">
diff --git a/policy/modules/system/miscfiles.te
b/policy/modules/system/miscfiles.te
index 246ac6a..85a29e3 100644
--- a/policy/modules/system/miscfiles.te
+++ b/policy/modules/system/miscfiles.te
@@ -14,13 +14,6 @@ type cert_t;
miscfiles_cert_type(cert_t)
#
-# cert_home_t is the type of files in the users' home directories.
-#
-type cert_home_t;
-miscfiles_cert_type(cert_home_t)
-userdom_user_home_content(cert_home_t)
-
-#
# fonts_t is the type of various font
# files in /usr
#
diff --git a/policy/modules/system/userdomain.if
b/policy/modules/system/userdomain.if
index 7c0d914..879ab82 100644
--- a/policy/modules/system/userdomain.if
+++ b/policy/modules/system/userdomain.if
@@ -272,8 +272,6 @@ interface(`userdom_manage_home_role',`
')
ifdef(`distro_gentoo',`
- miscfiles_manage_user_certs($2)
- miscfiles_relabel_user_certs($2)
optional_policy(`
flash_manage_home($2)
diff --git a/policy/modules/system/userdomain.te
b/policy/modules/system/userdomain.te
index 0b0eb60..94b068e 100644
--- a/policy/modules/system/userdomain.te
+++ b/policy/modules/system/userdomain.te
@@ -128,3 +128,10 @@ files_poly(user_runtime_t)
files_poly_member(user_runtime_t)
files_poly_parent(user_runtime_t)
ubac_constrained(user_runtime_t)
+
+ifdef(`distro_gentoo',`
+ # We used to use cert_home_t but an upstream commit introduced the same
+ # concept as user_cert_t. Enabling an alias to keep custom modules from
+ # users running.
+ type user_cert_t alias cert_home_t;
+')