Blame mls/domains/program/roundup.te
|
Chris PeBenito |
31b7c0 |
# Roundup Issue Tracking System
|
|
Chris PeBenito |
31b7c0 |
#
|
|
Chris PeBenito |
31b7c0 |
# Authors: W. Michael Petullo
|
|
Chris PeBenito |
31b7c0 |
#
|
|
Chris PeBenito |
31b7c0 |
daemon_domain(roundup)
|
|
Chris PeBenito |
31b7c0 |
var_lib_domain(roundup)
|
|
Chris PeBenito |
31b7c0 |
can_network(roundup_t)
|
|
Chris PeBenito |
31b7c0 |
allow roundup_t http_cache_port_t:tcp_socket name_bind;
|
|
Chris PeBenito |
31b7c0 |
allow roundup_t smtp_port_t:tcp_socket name_connect;
|
|
Chris PeBenito |
31b7c0 |
|
|
Chris PeBenito |
31b7c0 |
# execute python
|
|
Chris PeBenito |
31b7c0 |
allow roundup_t bin_t:dir r_dir_perms;
|
|
Chris PeBenito |
31b7c0 |
can_exec(roundup_t, bin_t)
|
|
Chris PeBenito |
31b7c0 |
allow roundup_t bin_t:lnk_file read;
|
|
Chris PeBenito |
31b7c0 |
|
|
Chris PeBenito |
31b7c0 |
allow roundup_t self:capability { setgid setuid };
|
|
Chris PeBenito |
31b7c0 |
|
|
Chris PeBenito |
31b7c0 |
allow roundup_t self:unix_stream_socket create_stream_socket_perms;
|
|
Chris PeBenito |
31b7c0 |
|
|
Chris PeBenito |
31b7c0 |
ifdef(`mysqld.te', `
|
|
Chris PeBenito |
31b7c0 |
allow roundup_t mysqld_db_t:dir search;
|
|
Chris PeBenito |
31b7c0 |
allow roundup_t mysqld_var_run_t:sock_file write;
|
|
Chris PeBenito |
31b7c0 |
allow roundup_t mysqld_t:unix_stream_socket connectto;
|
|
Chris PeBenito |
31b7c0 |
')
|
|
Chris PeBenito |
31b7c0 |
|
|
Chris PeBenito |
31b7c0 |
# /usr/share/mysql/charsets/Index.xml
|
|
Chris PeBenito |
31b7c0 |
allow roundup_t usr_t:file { getattr read };
|
|
Chris PeBenito |
31b7c0 |
allow roundup_t urandom_device_t:chr_file { getattr read };
|
|
Chris PeBenito |
31b7c0 |
allow roundup_t etc_t:file { getattr read };
|