diff options
author | Eric Paris <eparis@redhat.com> | 2009-06-02 17:01:16 -0400 |
---|---|---|
committer | James Morris <jmorris@namei.org> | 2009-06-03 07:44:53 +1000 |
commit | 850b0cee165576f969363a8c52021b5cf9ecbe67 (patch) | |
tree | 47d8da2840492950b89a8a1a597c8c18b7cccff8 | |
parent | fe67e6f2d6df371b58ba721954d45a196df5e8b8 (diff) | |
download | op-kernel-dev-850b0cee165576f969363a8c52021b5cf9ecbe67.zip op-kernel-dev-850b0cee165576f969363a8c52021b5cf9ecbe67.tar.gz |
SELinux: define audit permissions for audit tree netlink messages
Audit trees defined 2 new netlink messages but the netlink mapping tables for
selinux permissions were not set up. This patch maps these 2 new operations
to AUDIT_WRITE.
Signed-off-by: Eric Paris <eparis@redhat.com>
Signed-off-by: James Morris <jmorris@namei.org>
-rw-r--r-- | security/selinux/nlmsgtab.c | 2 |
1 files changed, 2 insertions, 0 deletions
diff --git a/security/selinux/nlmsgtab.c b/security/selinux/nlmsgtab.c index c6875fd..dd7cc6d 100644 --- a/security/selinux/nlmsgtab.c +++ b/security/selinux/nlmsgtab.c @@ -112,6 +112,8 @@ static struct nlmsg_perm nlmsg_audit_perms[] = { AUDIT_DEL_RULE, NETLINK_AUDIT_SOCKET__NLMSG_WRITE }, { AUDIT_USER, NETLINK_AUDIT_SOCKET__NLMSG_RELAY }, { AUDIT_SIGNAL_INFO, NETLINK_AUDIT_SOCKET__NLMSG_READ }, + { AUDIT_TRIM, NETLINK_AUDIT_SOCKET__NLMSG_WRITE }, + { AUDIT_MAKE_EQUIV, NETLINK_AUDIT_SOCKET__NLMSG_WRITE }, { AUDIT_TTY_GET, NETLINK_AUDIT_SOCKET__NLMSG_READ }, { AUDIT_TTY_SET, NETLINK_AUDIT_SOCKET__NLMSG_TTY_AUDIT }, }; |