diff options
author | Guido Trentalancia <guido@trentalancia.net> | 2017-05-13 17:55:57 +0200 |
---|---|---|
committer | Sven Vermeulen <swift@gentoo.org> | 2017-05-18 19:01:56 +0200 |
commit | a02b60e38aeebbef9175e93856bf455eef0a7ebc (patch) | |
tree | be6c1a02ec3ae2ba72aa3b28ebe253062b76ee41 | |
parent | Module version bump for chronyd changes from Luis Ressel. (diff) | |
download | hardened-refpolicy-a02b60e38aeebbef9175e93856bf455eef0a7ebc.tar.gz hardened-refpolicy-a02b60e38aeebbef9175e93856bf455eef0a7ebc.tar.bz2 hardened-refpolicy-a02b60e38aeebbef9175e93856bf455eef0a7ebc.zip |
openoffice: open files retrieved using mozilla
Let openoffice open files retrieved from the network using mozilla.
Signed-off-by: Guido Trentalancia <guido at trentalancia.net>
-rw-r--r-- | policy/modules/contrib/mozilla.if | 18 | ||||
-rw-r--r-- | policy/modules/contrib/openoffice.te | 1 |
2 files changed, 19 insertions, 0 deletions
diff --git a/policy/modules/contrib/mozilla.if b/policy/modules/contrib/mozilla.if index ffda45d3..70390632 100644 --- a/policy/modules/contrib/mozilla.if +++ b/policy/modules/contrib/mozilla.if @@ -309,6 +309,24 @@ interface(`mozilla_execmod_user_plugin_home_files',` allow $1 mozilla_plugin_home_t:file execmod; ') +####################################### +## <summary> +## Read temporary mozilla files. +## </summary> +## <param name="domain"> +## <summary> +## Domain allowed access. +## </summary> +## </param> +# +interface(`mozilla_read_tmp_files',` + gen_require(` + type mozilla_tmp_t; + ') + + read_files_pattern($1, mozilla_tmp_t, mozilla_tmp_t) +') + ######################################## ## <summary> ## Run mozilla in the mozilla domain. diff --git a/policy/modules/contrib/openoffice.te b/policy/modules/contrib/openoffice.te index 0be66b6f..40e3d97f 100644 --- a/policy/modules/contrib/openoffice.te +++ b/policy/modules/contrib/openoffice.te @@ -128,6 +128,7 @@ optional_policy(` optional_policy(` mozilla_domtrans(ooffice_t) + mozilla_read_tmp_files(ooffice_t) ') optional_policy(` |