|
Chris PeBenito |
08690c |
policy_module(staff, 2.1.1)
|
|
Chris PeBenito |
e9c6cd |
|
|
Chris PeBenito |
e9c6cd |
########################################
|
|
Chris PeBenito |
e9c6cd |
#
|
|
Chris PeBenito |
e9c6cd |
# Declarations
|
|
Chris PeBenito |
e9c6cd |
#
|
|
Chris PeBenito |
e9c6cd |
|
|
Chris PeBenito |
e9c6cd |
role staff_r;
|
|
Chris PeBenito |
e9c6cd |
|
|
Chris PeBenito |
e9c6cd |
userdom_unpriv_user_template(staff)
|
|
Dan Walsh |
3eaa99 |
fs_exec_noxattr(staff_t)
|
|
Dan Walsh |
3eaa99 |
|
|
Dan Walsh |
3eaa99 |
# needed for sandbox
|
|
Dan Walsh |
3eaa99 |
allow staff_t self:process setexec;
|
|
Chris PeBenito |
e9c6cd |
|
|
Chris PeBenito |
e9c6cd |
########################################
|
|
Chris PeBenito |
e9c6cd |
#
|
|
Chris PeBenito |
e9c6cd |
# Local policy
|
|
Chris PeBenito |
e9c6cd |
#
|
|
Chris PeBenito |
e9c6cd |
|
|
Dan Walsh |
3eaa99 |
kernel_read_ring_buffer(staff_usertype)
|
|
Dan Walsh |
3eaa99 |
kernel_getattr_core_if(staff_usertype)
|
|
Dan Walsh |
3eaa99 |
kernel_getattr_message_if(staff_usertype)
|
|
Dan Walsh |
3eaa99 |
kernel_read_software_raid_state(staff_usertype)
|
|
Dan Walsh |
2968e0 |
kernel_read_fs_sysctls(staff_usertype)
|
|
Dan Walsh |
2968e0 |
|
|
Dan Walsh |
2968e0 |
domain_read_all_domains_state(staff_usertype)
|
|
Dan Walsh |
2968e0 |
domain_getattr_all_domains(staff_usertype)
|
|
Dan Walsh |
2968e0 |
domain_obj_id_change_exemption(staff_t)
|
|
Dan Walsh |
2968e0 |
|
|
Dan Walsh |
2968e0 |
files_read_kernel_modules(staff_usertype)
|
|
Dan Walsh |
2968e0 |
|
|
Dan Walsh |
2968e0 |
seutil_read_module_store(staff_t)
|
|
Dan Walsh |
2968e0 |
seutil_run_newrole(staff_t, staff_r)
|
|
Dan Walsh |
2968e0 |
|
|
Dan Walsh |
2968e0 |
term_use_unallocated_ttys(staff_usertype)
|
|
Dan Walsh |
3eaa99 |
|
|
Dan Walsh |
3eaa99 |
auth_domtrans_pam_console(staff_t)
|
|
Dan Walsh |
3eaa99 |
|
|
Dan Walsh |
3eaa99 |
init_dbus_chat(staff_t)
|
|
Dan Walsh |
3eaa99 |
init_dbus_chat_script(staff_t)
|
|
Dan Walsh |
3eaa99 |
|
|
Dan Walsh |
2968e0 |
miscfiles_read_hwdata(staff_usertype)
|
|
Dan Walsh |
2968e0 |
|
|
Dan Walsh |
2968e0 |
modutils_read_module_config(staff_usertype)
|
|
Dan Walsh |
2968e0 |
modutils_read_module_deps(staff_usertype)
|
|
Dan Walsh |
2968e0 |
|
|
Dan Walsh |
3eaa99 |
netutils_run_ping(staff_t, staff_r)
|
|
Dan Walsh |
3eaa99 |
netutils_signal_ping(staff_t)
|
|
Dan Walsh |
3eaa99 |
|
|
Chris PeBenito |
e9c6cd |
optional_policy(`
|
|
Chris PeBenito |
296273 |
apache_role(staff_r, staff_t)
|
|
Chris PeBenito |
e9c6cd |
')
|
|
Chris PeBenito |
e9c6cd |
|
|
Chris PeBenito |
e9c6cd |
optional_policy(`
|
|
Dan Walsh |
3eaa99 |
mozilla_run_plugin(staff_t, staff_r)
|
|
Dan Walsh |
3eaa99 |
')
|
|
Dan Walsh |
3eaa99 |
|
|
Dan Walsh |
3eaa99 |
optional_policy(`
|
|
Chris PeBenito |
296273 |
auditadm_role_change(staff_r)
|
|
Chris PeBenito |
e9c6cd |
')
|
|
Chris PeBenito |
e9c6cd |
|
|
Chris PeBenito |
296273 |
optional_policy(`
|
|
Dan Walsh |
2968e0 |
dbadm_role_change(staff_r)
|
|
Dan Walsh |
3eaa99 |
')
|
|
Dan Walsh |
3eaa99 |
|
|
Dan Walsh |
3eaa99 |
optional_policy(`
|
|
Dan Walsh |
3eaa99 |
logadm_role_change(staff_r)
|
|
Dan Walsh |
3eaa99 |
')
|
|
Dan Walsh |
3eaa99 |
|
|
Dan Walsh |
3eaa99 |
optional_policy(`
|
|
Dan Walsh |
2968e0 |
webadm_role_change(staff_r)
|
|
Dan Walsh |
3eaa99 |
')
|
|
Dan Walsh |
3eaa99 |
|
|
Dan Walsh |
3eaa99 |
optional_policy(`
|
|
Dan Walsh |
2968e0 |
kerneloops_manage_tmp_files(staff_t)
|
|
Dan Walsh |
3eaa99 |
')
|
|
Dan Walsh |
3eaa99 |
|
|
Dan Walsh |
3eaa99 |
optional_policy(`
|
|
Dan Walsh |
366396 |
oident_manage_user_content(staff_t)
|
|
Dan Walsh |
366396 |
oident_relabel_user_content(staff_t)
|
|
Dan Walsh |
366396 |
')
|
|
Dan Walsh |
366396 |
|
|
Dan Walsh |
366396 |
optional_policy(`
|
|
Dan Walsh |
2968e0 |
postgresql_role(staff_r, staff_t)
|
|
Dan Walsh |
3eaa99 |
')
|
|
Dan Walsh |
3eaa99 |
|
|
Dan Walsh |
3eaa99 |
optional_policy(`
|
|
Dan Walsh |
2968e0 |
secadm_role_change(staff_r)
|
|
Dan Walsh |
3eaa99 |
')
|
|
Dan Walsh |
3eaa99 |
|
|
Dan Walsh |
3eaa99 |
optional_policy(`
|
|
Dan Walsh |
2968e0 |
unconfined_role_change(staff_r)
|
|
Dan Walsh |
3eaa99 |
')
|
|
Dan Walsh |
3eaa99 |
|
|
Dan Walsh |
3eaa99 |
optional_policy(`
|
|
Dan Walsh |
2968e0 |
rtkit_scheduled(staff_t)
|
|
Dan Walsh |
3eaa99 |
')
|
|
Dan Walsh |
3eaa99 |
|
|
Dan Walsh |
3eaa99 |
optional_policy(`
|
|
Dan Walsh |
2968e0 |
screen_role_template(staff, staff_r, staff_t)
|
|
Dan Walsh |
3eaa99 |
')
|
|
Dan Walsh |
3eaa99 |
|
|
Dan Walsh |
3eaa99 |
optional_policy(`
|
|
Dan Walsh |
2968e0 |
ssh_role_template(staff, staff_r, staff_t)
|
|
Dan Walsh |
3eaa99 |
')
|
|
Dan Walsh |
3eaa99 |
|
|
Dan Walsh |
3eaa99 |
optional_policy(`
|
|
Dan Walsh |
2968e0 |
sudo_role_template(staff, staff_r, staff_t)
|
|
Dan Walsh |
3eaa99 |
')
|
|
Dan Walsh |
3eaa99 |
|
|
Dan Walsh |
3eaa99 |
optional_policy(`
|
|
Dan Walsh |
2968e0 |
sysadm_role_change(staff_r)
|
|
Dan Walsh |
2968e0 |
userdom_dontaudit_use_user_terminals(staff_t)
|
|
Chris PeBenito |
c62f1b |
')
|
|
Chris PeBenito |
c62f1b |
|
|
Chris PeBenito |
c62f1b |
optional_policy(`
|
|
Dan Walsh |
2968e0 |
telepathy_dbus_session_role(staff_r, staff_t)
|
|
Chris PeBenito |
296273 |
')
|
|
Chris PeBenito |
296273 |
|
|
Chris PeBenito |
296273 |
optional_policy(`
|
|
Dan Walsh |
2968e0 |
xserver_role(staff_r, staff_t)
|
|
Dan Walsh |
3eaa99 |
')
|
|
Dan Walsh |
3eaa99 |
|
|
Dan Walsh |
3eaa99 |
ifndef(`distro_redhat',`
|
|
Dan Walsh |
2968e0 |
optional_policy(`
|
|
Dan Walsh |
2968e0 |
auth_role(staff_r, staff_t)
|
|
Dan Walsh |
2968e0 |
')
|
|
Dan Walsh |
2968e0 |
|
|
Dan Walsh |
2968e0 |
optional_policy(`
|
|
Dan Walsh |
2968e0 |
bluetooth_role(staff_r, staff_t)
|
|
Dan Walsh |
2968e0 |
')
|
|
Dan Walsh |
2968e0 |
|
|
Dan Walsh |
2968e0 |
optional_policy(`
|
|
Dan Walsh |
2968e0 |
cdrecord_role(staff_r, staff_t)
|
|
Dan Walsh |
2968e0 |
')
|
|
Dan Walsh |
2968e0 |
|
|
Dan Walsh |
2968e0 |
optional_policy(`
|
|
Dan Walsh |
2968e0 |
cron_role(staff_r, staff_t)
|
|
Dan Walsh |
2968e0 |
')
|
|
Dan Walsh |
2968e0 |
|
|
Dan Walsh |
2968e0 |
optional_policy(`
|
|
Dan Walsh |
2968e0 |
dbus_role_template(staff, staff_r, staff_t)
|
|
Dan Walsh |
2968e0 |
')
|
|
Dan Walsh |
3eaa99 |
|
|
Dan Walsh |
2968e0 |
optional_policy(`
|
|
Dan Walsh |
2968e0 |
evolution_role(staff_r, staff_t)
|
|
Dan Walsh |
2968e0 |
')
|
|
Dan Walsh |
3eaa99 |
|
|
Dan Walsh |
2968e0 |
optional_policy(`
|
|
Dan Walsh |
2968e0 |
games_role(staff_r, staff_t)
|
|
Dan Walsh |
2968e0 |
')
|
|
Dan Walsh |
3eaa99 |
|
|
Dan Walsh |
2968e0 |
optional_policy(`
|
|
Dan Walsh |
2968e0 |
gift_role(staff_r, staff_t)
|
|
Dan Walsh |
2968e0 |
')
|
|
Chris PeBenito |
296273 |
|
|
Dan Walsh |
2968e0 |
optional_policy(`
|
|
Dan Walsh |
2968e0 |
gnome_role(staff_r, staff_t)
|
|
Dan Walsh |
2968e0 |
')
|
|
Dan Walsh |
3eaa99 |
|
|
Dan Walsh |
2968e0 |
optional_policy(`
|
|
Dan Walsh |
2968e0 |
gpg_role(staff_r, staff_t)
|
|
Dan Walsh |
2968e0 |
')
|
|
Chris PeBenito |
296273 |
|
|
Dan Walsh |
2968e0 |
optional_policy(`
|
|
Dan Walsh |
2968e0 |
irc_role(staff_r, staff_t)
|
|
Dan Walsh |
2968e0 |
')
|
|
Dan Walsh |
3eaa99 |
|
|
Dan Walsh |
2968e0 |
optional_policy(`
|
|
Dan Walsh |
2968e0 |
java_role(staff_r, staff_t)
|
|
Dan Walsh |
2968e0 |
')
|
|
Chris PeBenito |
296273 |
|
|
Dan Walsh |
2968e0 |
optional_policy(`
|
|
Dan Walsh |
2968e0 |
lockdev_role(staff_r, staff_t)
|
|
Dan Walsh |
2968e0 |
')
|
|
Chris PeBenito |
296273 |
|
|
Dan Walsh |
2968e0 |
optional_policy(`
|
|
Dan Walsh |
2968e0 |
lpd_role(staff_r, staff_t)
|
|
Dan Walsh |
2968e0 |
')
|
|
Chris PeBenito |
296273 |
|
|
Dan Walsh |
2968e0 |
optional_policy(`
|
|
Dan Walsh |
2968e0 |
mozilla_role(staff_r, staff_t)
|
|
Dan Walsh |
2968e0 |
')
|
|
Dan Walsh |
3eaa99 |
|
|
Dan Walsh |
2968e0 |
optional_policy(`
|
|
Dan Walsh |
2968e0 |
mplayer_role(staff_r, staff_t)
|
|
Dan Walsh |
2968e0 |
')
|
|
Dan Walsh |
3eaa99 |
|
|
Dan Walsh |
2968e0 |
optional_policy(`
|
|
Dan Walsh |
2968e0 |
mta_role(staff_r, staff_t)
|
|
Dan Walsh |
2968e0 |
')
|
|
Dan Walsh |
3eaa99 |
|
|
Dan Walsh |
2968e0 |
optional_policy(`
|
|
Dan Walsh |
2968e0 |
pyzor_role(staff_r, staff_t)
|
|
Dan Walsh |
2968e0 |
')
|
|
Dan Walsh |
3eaa99 |
|
|
Dan Walsh |
2968e0 |
optional_policy(`
|
|
Dan Walsh |
2968e0 |
razor_role(staff_r, staff_t)
|
|
Dan Walsh |
2968e0 |
')
|
|
Dan Walsh |
3eaa99 |
|
|
Dan Walsh |
2968e0 |
optional_policy(`
|
|
Dan Walsh |
2968e0 |
rssh_role(staff_r, staff_t)
|
|
Dan Walsh |
2968e0 |
')
|
|
Dan Walsh |
3eaa99 |
|
|
Dan Walsh |
2968e0 |
optional_policy(`
|
|
Dan Walsh |
2968e0 |
spamassassin_role(staff_r, staff_t)
|
|
Dan Walsh |
2968e0 |
')
|
|
Dan Walsh |
3eaa99 |
|
|
Dan Walsh |
2968e0 |
optional_policy(`
|
|
Dan Walsh |
2968e0 |
su_role_template(staff, staff_r, staff_t)
|
|
Dan Walsh |
2968e0 |
')
|
|
Dan Walsh |
3eaa99 |
|
|
Dan Walsh |
2968e0 |
optional_policy(`
|
|
Dan Walsh |
2968e0 |
thunderbird_role(staff_r, staff_t)
|
|
Dan Walsh |
2968e0 |
')
|
|
Dan Walsh |
3eaa99 |
|
|
Dan Walsh |
2968e0 |
optional_policy(`
|
|
Dan Walsh |
2968e0 |
tvtime_role(staff_r, staff_t)
|
|
Dan Walsh |
2968e0 |
')
|
|
Dan Walsh |
3eaa99 |
|
|
Dan Walsh |
2968e0 |
optional_policy(`
|
|
Dan Walsh |
2968e0 |
uml_role(staff_r, staff_t)
|
|
Dan Walsh |
2968e0 |
')
|
|
Dan Walsh |
3eaa99 |
|
|
Dan Walsh |
2968e0 |
optional_policy(`
|
|
Dan Walsh |
2968e0 |
userhelper_role_template(staff, staff_r, staff_t)
|
|
Dan Walsh |
2968e0 |
')
|
|
Dan Walsh |
3eaa99 |
|
|
Dan Walsh |
2968e0 |
optional_policy(`
|
|
Dan Walsh |
2968e0 |
vmware_role(staff_r, staff_t)
|
|
Dan Walsh |
2968e0 |
')
|
|
Dan Walsh |
3eaa99 |
|
|
Dan Walsh |
2968e0 |
optional_policy(`
|
|
Dan Walsh |
2968e0 |
wireshark_role(staff_r, staff_t)
|
|
Dan Walsh |
2968e0 |
')
|
|
Dan Walsh |
2968e0 |
')
|
|
Dan Walsh |
3eaa99 |
|
|
Dan Walsh |
3eaa99 |
optional_policy(`
|
|
Dan Walsh |
3eaa99 |
accountsd_dbus_chat(staff_t)
|
|
Dan Walsh |
3eaa99 |
accountsd_read_lib_files(staff_t)
|
|
Dan Walsh |
3eaa99 |
')
|
|
Dan Walsh |
3eaa99 |
|
|
Dan Walsh |
3eaa99 |
optional_policy(`
|
|
Dan Walsh |
3eaa99 |
gnomeclock_dbus_chat(staff_t)
|
|
Dan Walsh |
3eaa99 |
')
|
|
Dan Walsh |
3eaa99 |
|
|
Dan Walsh |
3eaa99 |
optional_policy(`
|
|
Dan Walsh |
3eaa99 |
firewallgui_dbus_chat(staff_t)
|
|
Dan Walsh |
3eaa99 |
')
|
|
Dan Walsh |
3eaa99 |
|
|
Dan Walsh |
3eaa99 |
optional_policy(`
|
|
Dan Walsh |
3eaa99 |
lpd_list_spool(staff_t)
|
|
Dan Walsh |
3eaa99 |
')
|
|
Dan Walsh |
3eaa99 |
|
|
Dan Walsh |
3eaa99 |
optional_policy(`
|
|
Dan Walsh |
3eaa99 |
kerneloops_dbus_chat(staff_t)
|
|
Dan Walsh |
3eaa99 |
')
|
|
Dan Walsh |
3eaa99 |
|
|
Dan Walsh |
3eaa99 |
optional_policy(`
|
|
Dan Walsh |
3eaa99 |
rpm_dbus_chat(staff_usertype)
|
|
Dan Walsh |
3eaa99 |
')
|
|
Dan Walsh |
3eaa99 |
|
|
Dan Walsh |
3eaa99 |
optional_policy(`
|
|
Dan Walsh |
3eaa99 |
sandbox_transition(staff_t, staff_r)
|
|
Dan Walsh |
3eaa99 |
')
|
|
Dan Walsh |
3eaa99 |
|
|
Dan Walsh |
3eaa99 |
optional_policy(`
|
|
Dan Walsh |
3eaa99 |
setroubleshoot_stream_connect(staff_t)
|
|
Dan Walsh |
3eaa99 |
setroubleshoot_dbus_chat(staff_t)
|
|
Dan Walsh |
3eaa99 |
setroubleshoot_dbus_chat_fixit(staff_t)
|
|
Dan Walsh |
3eaa99 |
')
|
|
Dan Walsh |
3eaa99 |
|
|
Dan Walsh |
3eaa99 |
optional_policy(`
|
|
Dan Walsh |
3eaa99 |
virt_stream_connect(staff_t)
|
|
Dan Walsh |
3eaa99 |
')
|
|
Dan Walsh |
3eaa99 |
|
|
Dan Walsh |
3eaa99 |
optional_policy(`
|
|
Dan Walsh |
3eaa99 |
userhelper_console_role_template(staff, staff_r, staff_usertype)
|
|
Chris PeBenito |
296273 |
')
|