601a16
From faf81b4b238e24fe29eb53f885a25367e212dd7b Mon Sep 17 00:00:00 2001
601a16
From: Zdenek Pytela <zpytela@redhat.com>
601a16
Date: Mon, 7 Feb 2022 10:45:41 +0100
601a16
Subject: [PATCH] SELinux: use /root/.vnc in file context specification
601a16
601a16
Instead of HOME_ROOT/.vnc, /root/.vnc should be used
601a16
for user root's home to specify default file context
601a16
as HOME_ROOT actually means base for home dirs (usually /home).
601a16
---
601a16
 unix/vncserver/selinux/vncsession.fc | 2 +-
601a16
 1 file changed, 1 insertion(+), 1 deletion(-)
601a16
601a16
diff --git a/unix/vncserver/selinux/vncsession.fc b/unix/vncserver/selinux/vncsession.fc
d7e56c
index 6aaf4b1f4..bc81f8f25 100644
601a16
--- a/unix/vncserver/selinux/vncsession.fc
601a16
+++ b/unix/vncserver/selinux/vncsession.fc
601a16
@@ -18,7 +18,7 @@
601a16
 #
601a16
d7e56c
 HOME_DIR/\.vnc(/.*)?      gen_context(system_u:object_r:vnc_home_t,s0)
d7e56c
-HOME_ROOT/\.vnc(/.*)?      gen_context(system_u:object_r:vnc_home_t,s0)
d7e56c
+/root/\.vnc(/.*)?      gen_context(system_u:object_r:vnc_home_t,s0)
601a16
601a16
 /usr/sbin/vncsession			--	gen_context(system_u:object_r:vnc_session_exec_t,s0)
601a16
 /usr/libexec/vncsession-start		--	gen_context(system_u:object_r:vnc_session_exec_t,s0)