diff --git a/roles/distgit/files/upload_cgi.pp b/roles/distgit/files/upload_cgi.pp index 2b472f7aab..870267272e 100644 Binary files a/roles/distgit/files/upload_cgi.pp and b/roles/distgit/files/upload_cgi.pp differ diff --git a/roles/distgit/files/upload_cgi.te b/roles/distgit/files/upload_cgi.te index f58050d1dc..bd87580806 100644 --- a/roles/distgit/files/upload_cgi.te +++ b/roles/distgit/files/upload_cgi.te @@ -1,11 +1,13 @@ -policy_module(upload_cgi,1.0.0) +policy_module(upload_cgi,1.1.0) -gen_require(` type httpd_git_script_t ; ') -type upload_cgi_tmp_t; -files_tmp_file(upload_cgi_tmp_t); -allow httpd_git_script_t upload_cgi_tmp_t:file manage_file_perms; -files_tmp_filetrans(httpd_git_script_t, upload_cgi_tmp_t, file); +require { + type httpd_git_script_t; + type git_script_tmp_t; +} + +files_tmp_file(git_script_tmp_t) +allow httpd_git_script_t git_script_tmp_t:file manage_file_perms; # Do not audit attempts to read the process state (/proc/pid) of all domains.