commit:     b822b1181b81fd74038c8987162a1cfe86611720
Author:     Guido Trentalancia <guido <AT> trentalancia <DOT> net>
AuthorDate: Fri Nov 25 22:14:47 2016 +0000
Commit:     Jason Zaman <perfinion <AT> gentoo <DOT> org>
CommitDate: Tue Dec  6 13:19:40 2016 +0000
URL:        
https://gitweb.gentoo.org/proj/hardened-refpolicy.git/commit/?id=b822b118

cups: descend "rw" directories when reading configuration files

When reading CUPS configuration files under /etc, let the caller
search (i.e. descend into) "rw" directories (such as "ppd").

Signed-off-by: Guido Trentalancia <guido <AT> trentalancia.net>

 policy/modules/contrib/cups.if | 4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)

diff --git a/policy/modules/contrib/cups.if b/policy/modules/contrib/cups.if
index cad7df2..a6bcb68 100644
--- a/policy/modules/contrib/cups.if
+++ b/policy/modules/contrib/cups.if
@@ -203,7 +203,7 @@ interface(`cups_read_config',`
        ')
 
        files_search_etc($1)
-       read_files_pattern($1, cupsd_etc_t, { cupsd_etc_t cupsd_rw_etc_t })
+       read_files_pattern($1, { cupsd_etc_t cupsd_rw_etc_t }, { cupsd_etc_t 
cupsd_rw_etc_t })
 ')
 
 ########################################
@@ -223,7 +223,7 @@ interface(`cups_read_rw_config',`
        ')
 
        files_search_etc($1)
-       read_files_pattern($1, cupsd_etc_t, cupsd_rw_etc_t)
+       read_files_pattern($1, { cupsd_etc_t cupsd_rw_etc_t }, cupsd_rw_etc_t)
 ')
 
 ########################################

Reply via email to