Skip to content

Commit a0f93bd

Browse files
committed
[refactoring] Non-base interfaces should be in an optional block
(sysnet, logging, auth, userdom, usermanage) Synchronize indentation Interfaces in optional blocks sorted alphabetically
1 parent 2f83277 commit a0f93bd

File tree

1 file changed

+24
-14
lines changed

1 file changed

+24
-14
lines changed

mysql.te

+24-14
Original file line numberDiff line numberDiff line change
@@ -110,10 +110,6 @@ manage_files_pattern(mysqld_t, mysqld_var_run_t, mysqld_var_run_t)
110110
manage_sock_files_pattern(mysqld_t, mysqld_var_run_t, mysqld_var_run_t)
111111
files_pid_filetrans(mysqld_t, mysqld_var_run_t, { dir file sock_file })
112112

113-
usermanage_read_crack_db(mysqld_t)
114-
115-
userdom_dontaudit_use_unpriv_user_fds(mysqld_t)
116-
117113
kernel_read_network_state(mysqld_t)
118114
kernel_read_system_state(mysqld_t)
119115
kernel_read_kernel_sysctls(mysqld_t)
@@ -154,13 +150,6 @@ files_search_var_lib(mysqld_t)
154150
files_search_pids(mysqld_t)
155151
files_getattr_all_sockets(mysqld_t)
156152

157-
auth_use_pam(mysqld_t)
158-
159-
logging_send_syslog_msg(mysqld_t)
160-
161-
sysnet_read_config(mysqld_t)
162-
sysnet_domtrans_ifconfig(mysqld_t)
163-
164153
ifdef(`distro_redhat',`
165154
filetrans_pattern(mysqld_t, mysqld_db_t, mysqld_var_run_t, sock_file)
166155
')
@@ -174,6 +163,10 @@ tunable_policy(`mysql_connect_http',`
174163
corenet_tcp_connect_http_port(mysqld_t)
175164
')
176165

166+
optional_policy(`
167+
auth_use_pam(mysqld_t)
168+
')
169+
177170
optional_policy(`
178171
daemontools_service_domain(mysqld_t, mysqld_exec_t)
179172
')
@@ -183,23 +176,40 @@ optional_policy(`
183176
')
184177

185178
optional_policy(`
186-
openshift_search_lib(mysqld_t)
179+
logging_send_syslog_msg(mysqld_t)
180+
')
181+
182+
optional_policy(`
183+
openshift_search_lib(mysqld_t)
187184
')
188185

189186
optional_policy(`
190-
rhcs_manage_cluster_pid_files(mysqld_t)
187+
rhcs_manage_cluster_pid_files(mysqld_t)
188+
')
189+
190+
optional_policy(`
191+
rsync_exec(mysqld_t)
191192
')
192193

193194
optional_policy(`
194195
seutil_sigchld_newrole(mysqld_t)
195196
')
196197

198+
optional_policy(`
199+
sysnet_read_config(mysqld_t)
200+
sysnet_domtrans_ifconfig(mysqld_t)
201+
')
202+
197203
optional_policy(`
198204
udev_read_db(mysqld_t)
199205
')
200206

201207
optional_policy(`
202-
rsync_exec(mysqld_t)
208+
userdom_dontaudit_use_unpriv_user_fds(mysqld_t)
209+
')
210+
211+
optional_policy(`
212+
usermanage_read_crack_db(mysqld_t)
203213
')
204214

205215
#######################################

0 commit comments

Comments
 (0)