浏览代码

unconfined_additional: remove sysadm transitions

Helmut Pozimski 3 年之前
父节点
当前提交
ce690fde97
共有 1 个文件被更改,包括 1 次插入6 次删除
  1. 1 6
      unconfined_additional.te

+ 1 - 6
unconfined_additional.te

@@ -1,9 +1,8 @@
-policy_module(unconfined_additional, 0.0.4)
+policy_module(unconfined_additional, 0.0.5)
 
 require {
   type unconfined_t;
   type portage_sandbox_t;
-  type sysadm_t;
   type atop_t;
   type atop_initrc_exec_t;
   type atop_unit_t;
@@ -19,10 +18,6 @@ require {
 allow unconfined_t portage_sandbox_t:process transition;
 allow unconfined_t self:process execmem;
 
-allow unconfined_t sysadm_t:process transition;
-sysadm_role_change(unconfined_r)
-sysadm_shell_domtrans(unconfined_t)
-
 init_startstop_service(unconfined_t, unconfined_r, atop_t, atop_initrc_exec_t, atop_unit_t)
 init_startstop_service(unconfined_t, unconfined_r, spamd_t, spamd_initrc_exec_t, spamd_unit_t)
 init_startstop_service(unconfined_t, unconfined_r, phpfpm_t, phpfpm_initrc_exec_t, phpfpm_unit_t)