From 013d746abc2e7ec536b2c04806c16633121335de Mon Sep 17 00:00:00 2001 From: Chris PeBenito Date: May 10 2006 20:24:40 +0000 Subject: add apache_manage_all_content, bug 1602 --- diff --git a/refpolicy/policy/modules/services/apache.if b/refpolicy/policy/modules/services/apache.if index 4d17f49..a11c412 100644 --- a/refpolicy/policy/modules/services/apache.if +++ b/refpolicy/policy/modules/services/apache.if @@ -472,6 +472,26 @@ interface(`apache_dontaudit_rw_tcp_sockets',` ######################################## ## +## Create, read, write, and delete all web content. +## +## +## +## Domain allowed access. +## +## +# +interface(`apache_manage_all_content',` + gen_require(` + attribute httpdcontent; + ') + + allow $1 httpdcontent:dir manage_dir_perms; + allow $1 httpdcontent:file manage_file_perms; + allow $1 httpdcontent:lnk_file create_lnk_perms; +') + +######################################## +## ## Allow the specified domain to read ## and write Apache cache files. ##