Skip to content

Commit d81aace

Browse files
committed
Tighten auth_rw_shadow_lock permission
There are no directories labeled shadow_lock_t, and therefore is no reason to grant dir:search on shadow_lock_t. Signed-off-by: Antonio Enrico Russo <aerusso@aerusso.net>
1 parent 6bd432e commit d81aace

1 file changed

Lines changed: 1 addition & 1 deletion

File tree

policy/modules/system/authlogin.if

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -862,7 +862,7 @@ interface(`auth_rw_shadow_lock',`
862862
type shadow_lock_t;
863863
')
864864

865-
rw_files_pattern($1, shadow_lock_t, shadow_lock_t)
865+
allow $1 shadow_lock_t:file rw_file_perms;
866866
')
867867

868868
########################################

0 commit comments

Comments
 (0)