Skip to content

Commit

Permalink
Allow winbind_rpcd_t processes access when samba_export_all_* is on
Browse files Browse the repository at this point in the history
This commit expand the commit 7367896 to include winbind_rpcd_t process to access all samba shares when boolean
samba_export_all_rw or samba_export_all_ro is enabled.

Signed-off-by: Lukas Vrabec <[email protected]>
  • Loading branch information
wrabcak authored and zpytela committed Nov 1, 2023
1 parent 5f6b4ed commit bb517fb
Showing 1 changed file with 11 additions and 0 deletions.
11 changes: 11 additions & 0 deletions policy/modules/contrib/samba.te
Original file line number Diff line number Diff line change
Expand Up @@ -604,6 +604,11 @@ tunable_policy(`samba_export_all_ro',`
files_dontaudit_list_security_dirs(nmbd_t)
files_dontaudit_search_security_files(nmbd_t)
files_dontaudit_read_security_files(nmbd_t)
fs_read_noxattr_fs_files(winbind_rpcd_t)
files_read_non_security_files(winbind_rpcd_t)
files_dontaudit_list_security_dirs(winbind_rpcd_t)
files_dontaudit_search_security_files(winbind_rpcd_t)
files_dontaudit_read_security_files(winbind_rpcd_t)
')

tunable_policy(`samba_export_all_rw',`
Expand All @@ -620,6 +625,12 @@ tunable_policy(`samba_export_all_rw',`
files_dontaudit_list_security_dirs(nmbd_t)
files_dontaudit_search_security_files(nmbd_t)
files_dontaudit_read_security_files(nmbd_t)
fs_manage_noxattr_fs_files(winbind_rpcd_t)
files_manage_non_security_files(winbind_rpcd_t)
files_manage_non_security_dirs(winbind_rpcd_t)
files_dontaudit_list_security_dirs(winbind_rpcd_t)
files_dontaudit_search_security_files(winbind_rpcd_t)
files_dontaudit_read_security_files(winbind_rpcd_t)
')

userdom_filetrans_home_content(nmbd_t)
Expand Down

0 comments on commit bb517fb

Please sign in to comment.