From Debian package 0.0.20080702-14 Dontaudit logrotate search access to unconfined_home_dir_t. Unnecessary with UBAC? Retained in 0.0.20090621-1 Index: policy/modules/admin/logrotate.te =================================================================== --- policy/modules/admin/logrotate.te.orig +++ policy/modules/admin/logrotate.te @@ -145,6 +145,10 @@ ') optional_policy(` + unconfined_dontaudit_search_home_dirs(logrotate_t) +') + +optional_policy(` acct_domtrans(logrotate_t) acct_manage_data(logrotate_t) acct_exec_data(logrotate_t) Index: policy/modules/system/unconfined.if =================================================================== --- policy/modules/system/unconfined.if.orig +++ policy/modules/system/unconfined.if @@ -608,3 +608,22 @@ read_files_pattern($1, { unconfined_home_dir_t unconfined_home_t }, unconfined_home_t) read_lnk_files_pattern($1, { unconfined_home_dir_t unconfined_home_t }, unconfined_home_t) ') + +######################################## +## +## Do not audit attempts to search the unconfined +## users home directory. +## +## +## +## Domain to not audit. +## +## +# +interface(`unconfined_dontaudit_search_home_dirs',` + gen_require(` + type unconfined_home_dir_t; + ') + + dontaudit $1 unconfined_home_dir_t:dir search_dir_perms; +')