Blame policy/modules/apps/cdrecord.te
|
Chris PeBenito |
4ec694 |
|
|
Chris PeBenito |
d46cfe |
policy_module(cdrecord,1.2.1)
|
|
Chris PeBenito |
4ec694 |
|
|
Chris PeBenito |
4ec694 |
########################################
|
|
Chris PeBenito |
4ec694 |
#
|
|
Chris PeBenito |
4ec694 |
# Declarations
|
|
Chris PeBenito |
4ec694 |
#
|
|
Chris PeBenito |
4ec694 |
|
|
Chris PeBenito |
56e1b3 |
ifdef(`strict_policy',`
|
|
Chris PeBenito |
56e1b3 |
## <desc>
|
|
Chris PeBenito |
56e1b3 |
##
|
|
Chris PeBenito |
56e1b3 |
## Allow cdrecord to read various content.
|
|
Chris PeBenito |
56e1b3 |
## nfs, samba, removable devices, user temp
|
|
Chris PeBenito |
56e1b3 |
## and untrusted content files
|
|
Chris PeBenito |
56e1b3 |
##
|
|
Chris PeBenito |
56e1b3 |
## </desc>
|
|
Chris PeBenito |
56e1b3 |
gen_tunable(cdrecord_read_content,false)
|
|
Chris PeBenito |
56e1b3 |
')
|
|
Chris PeBenito |
56e1b3 |
|
|
Chris PeBenito |
4ec694 |
type cdrecord_exec_t;
|
|
Chris PeBenito |
d46cfe |
application_executable_file(cdrecord_exec_t)
|