Blame refpolicy/doc/example.if
|
Chris PeBenito |
6bb0da |
## <summary>Myapp example policy</summary>
|
|
Chris PeBenito |
6bb0da |
## <desc>
|
|
Chris PeBenito |
6bb0da |
##
|
|
Chris PeBenito |
6bb0da |
## More descriptive text about myapp. The <desc>
|
|
Chris PeBenito |
6bb0da |
## tag can also use ,
|
|
Chris PeBenito |
6bb0da |
## html tags for formatting.
|
|
Chris PeBenito |
6bb0da |
##
|
|
Chris PeBenito |
6bb0da |
##
|
|
Chris PeBenito |
6bb0da |
## This policy supports the following myapp features:
|
|
Chris PeBenito |
6bb0da |
##
|
|
Chris PeBenito |
6bb0da |
## Feature A
|
|
Chris PeBenito |
6bb0da |
## Feature B
|
|
Chris PeBenito |
6bb0da |
## Feature C
|
|
Chris PeBenito |
6bb0da |
##
|
|
Chris PeBenito |
6bb0da |
##
|
|
Chris PeBenito |
6bb0da |
## </desc>
|
|
Chris PeBenito |
6bb0da |
#
|
|
Chris PeBenito |
6bb0da |
|
|
Chris PeBenito |
6bb0da |
########################################
|
|
Chris PeBenito |
6bb0da |
## <summary>
|
|
Chris PeBenito |
6bb0da |
## Execute a domain transition to run myapp.
|
|
Chris PeBenito |
6bb0da |
## </summary>
|
|
Chris PeBenito |
6bb0da |
## <param name="domain">
|
|
Chris PeBenito |
6bb0da |
## Domain allowed to transition.
|
|
Chris PeBenito |
6bb0da |
## </param>
|
|
Chris PeBenito |
6bb0da |
#
|
|
Chris PeBenito |
6bb0da |
interface(`myapp_domtrans',`
|
|
Chris PeBenito |
6bb0da |
gen_requires(`
|
|
Chris PeBenito |
6bb0da |
type myapp_t, myapp_exec_t;
|
|
Chris PeBenito |
6bb0da |
')
|
|
Chris PeBenito |
6bb0da |
|
|
Chris PeBenito |
6bb0da |
domain_auto_trans($1,myapp_exec_t,myapp_t)
|
|
Chris PeBenito |
6bb0da |
|
|
Chris PeBenito |
6bb0da |
allow $1 myapp_t:fd use;
|
|
Chris PeBenito |
6bb0da |
allow myapp_t $1:fd use;
|
|
Chris PeBenito |
6bb0da |
allow $1 myapp_t:fifo_file rw_file_perms;
|
|
Chris PeBenito |
6bb0da |
allow $1 myapp_t:process sigchld;
|
|
Chris PeBenito |
6bb0da |
')
|
|
Chris PeBenito |
6bb0da |
|
|
Chris PeBenito |
6bb0da |
########################################
|
|
Chris PeBenito |
6bb0da |
## <summary>
|
|
Chris PeBenito |
6bb0da |
## Read myapp log files.
|
|
Chris PeBenito |
6bb0da |
## </summary>
|
|
Chris PeBenito |
6bb0da |
## <param name="domain">
|
|
Chris PeBenito |
6bb0da |
## Domain allowed to read the log files.
|
|
Chris PeBenito |
6bb0da |
## </param>
|
|
Chris PeBenito |
6bb0da |
#
|
|
Chris PeBenito |
6bb0da |
interface(`myapp_read_log',`
|
|
Chris PeBenito |
6bb0da |
gen_requires(`
|
|
Chris PeBenito |
6bb0da |
type myapp_log_t;
|
|
Chris PeBenito |
6bb0da |
')
|
|
Chris PeBenito |
6bb0da |
|
|
Chris PeBenito |
6bb0da |
logging_search_logs($1)
|
|
Chris PeBenito |
6bb0da |
allow $1 myapp_log_t:file r_file_perms;
|
|
Chris PeBenito |
6bb0da |
')
|