diff --git a/recipes-security/refpolicy/refpolicy/0001-refpolicy-minimum-make-sysadmin-module-optional.patch b/recipes-security/refpolicy/refpolicy/0001-refpolicy-minimum-make-sysadmin-module-optional.patch index 73e6b48..e4d12a9 100644 --- a/recipes-security/refpolicy/refpolicy/0001-refpolicy-minimum-make-sysadmin-module-optional.patch +++ b/recipes-security/refpolicy/refpolicy/0001-refpolicy-minimum-make-sysadmin-module-optional.patch @@ -1,4 +1,4 @@ -From 923dec0f0231024680bb6f7d48ff7edf82ed8082 Mon Sep 17 00:00:00 2001 +From d169945ca712626b0e445e9818cd2eaece37ab38 Mon Sep 17 00:00:00 2001 From: Joe MacDonald Date: Fri, 5 Apr 2019 11:53:28 -0400 Subject: [PATCH] refpolicy-minimum: make sysadmin module optional @@ -22,10 +22,10 @@ Signed-off-by: Yi Zhao 2 files changed, 11 insertions(+), 7 deletions(-) diff --git a/policy/modules/system/init.te b/policy/modules/system/init.te -index 8af34aa7e..fdd64fb5b 100644 +index 026f77c16..386cb478a 100644 --- a/policy/modules/system/init.te +++ b/policy/modules/system/init.te -@@ -653,13 +653,15 @@ ifdef(`init_systemd',` +@@ -654,13 +654,15 @@ ifdef(`init_systemd',` unconfined_write_keys(init_t) ') ',` @@ -48,12 +48,12 @@ index 8af34aa7e..fdd64fb5b 100644 ') ') diff --git a/policy/modules/system/locallogin.te b/policy/modules/system/locallogin.te -index 4ba131d29..9c4b0a1d8 100644 +index c370caf2b..7d5e7b54f 100644 --- a/policy/modules/system/locallogin.te +++ b/policy/modules/system/locallogin.te -@@ -277,7 +277,9 @@ userdom_use_unpriv_users_fds(sulogin_t) +@@ -278,7 +278,9 @@ userdom_use_unpriv_users_fds(sulogin_t) userdom_search_user_home_dirs(sulogin_t) - userdom_use_user_ptys(sulogin_t) + userdom_use_user_terminals(sulogin_t) -sysadm_shell_domtrans(sulogin_t) +optional_policy(`