Chris PeBenito 22a287
policy_module(dbadm, 1.0.0)
Chris PeBenito 22a287
Chris PeBenito 22a287
########################################
Chris PeBenito 22a287
#
Chris PeBenito 22a287
# Declarations
Chris PeBenito 22a287
#
Chris PeBenito 22a287
Chris PeBenito c62f1b
## <desc>
Chris PeBenito c62f1b
## 

Chris PeBenito c62f1b
## Allow dbadm to manage files in users home directories
Chris PeBenito c62f1b
## 

Chris PeBenito c62f1b
## </desc>
Chris PeBenito c62f1b
gen_tunable(dbadm_manage_user_files, false)
Chris PeBenito c62f1b
Chris PeBenito c62f1b
## <desc>
Chris PeBenito c62f1b
## 

Chris PeBenito c62f1b
## Allow dbadm to read files in users home directories
Chris PeBenito c62f1b
## 

Chris PeBenito c62f1b
## </desc>
Chris PeBenito c62f1b
gen_tunable(dbadm_read_user_files, false)
Chris PeBenito c62f1b
Chris PeBenito 22a287
role dbadm_r;
Chris PeBenito 22a287
Chris PeBenito c62f1b
userdom_base_user_template(dbadm)
Chris PeBenito 22a287
Chris PeBenito 22a287
########################################
Chris PeBenito 22a287
#
Chris PeBenito 22a287
# database admin local policy
Chris PeBenito 22a287
#
Chris PeBenito 22a287
Chris PeBenito c62f1b
allow dbadm_t self:capability { dac_override dac_read_search sys_ptrace };
Chris PeBenito c62f1b
Chris PeBenito c62f1b
files_dontaudit_search_all_dirs(dbadm_t)
Chris PeBenito c62f1b
files_delete_generic_locks(dbadm_t)
Chris PeBenito c62f1b
files_list_var(dbadm_t)
Chris PeBenito c62f1b
Chris PeBenito c62f1b
selinux_get_enforce_mode(dbadm_t)
Chris PeBenito c62f1b
Chris PeBenito c62f1b
logging_send_syslog_msg(dbadm_t)
Chris PeBenito c62f1b
Chris PeBenito c62f1b
userdom_dontaudit_search_user_home_dirs(dbadm_t)
Chris PeBenito c62f1b
Chris PeBenito c62f1b
tunable_policy(`dbadm_manage_user_files',`
Chris PeBenito c62f1b
	userdom_manage_user_home_content_files(dbadm_t)
Chris PeBenito c62f1b
	userdom_read_user_tmp_files(dbadm_t)
Chris PeBenito c62f1b
	userdom_write_user_tmp_files(dbadm_t)
Chris PeBenito 22a287
')
Chris PeBenito 22a287
Chris PeBenito c62f1b
tunable_policy(`dbadm_read_user_files',`
Chris PeBenito c62f1b
	userdom_read_user_home_content_files(dbadm_t)
Chris PeBenito c62f1b
	userdom_read_user_tmp_files(dbadm_t)
Chris PeBenito 22a287
')
Chris PeBenito 22a287
Chris PeBenito 22a287
optional_policy(`
Chris PeBenito c62f1b
	mysql_admin(dbadm_t, dbadm_r)
Chris PeBenito 22a287
')
Chris PeBenito 22a287
Chris PeBenito 22a287
optional_policy(`
Chris PeBenito c62f1b
	postgresql_admin(dbadm_t, dbadm_r)
Chris PeBenito 22a287
')