From 8c47ad04ba43c6cc2dee341c86f6fef0d8b0e0bd Mon Sep 17 00:00:00 2001 From: Dan Walsh Date: Sep 16 2010 21:48:39 +0000 Subject: Remove accedentlay added ~ files --- diff --git a/policy/modules/services/vnstatd.if~ b/policy/modules/services/vnstatd.if~ deleted file mode 100644 index 85dba86..0000000 --- a/policy/modules/services/vnstatd.if~ +++ /dev/null @@ -1,150 +0,0 @@ - -## policy for vnstatd - - -######################################## -## -## Execute a domain transition to run vnstatd. -## -## -## -## Domain allowed access. -## -## -# -interface(`vnstatd_domtrans',` - gen_require(` - type vnstatd_t, vnstatd_exec_t; - ') - - domtrans_pattern($1, vnstatd_exec_t, vnstatd_t) -') - - - -######################################## -## -## Execute a domain transition to run vnstat. -## -## -## -## Domain allowed access. -## -## -# -interface(`vnstatd_domtrans_vnstat',` - gen_require(` - type vnstat_t, vnstat_exec_t; - ') - - domtrans_pattern($1, vnstat_exec_t, vnstat_t) -') - -######################################## -## -## Search vnstatd lib directories. -## -## -## -## Domain allowed access. -## -## -# -interface(`vnstatd_search_lib',` - gen_require(` - type vnstatd_var_lib_t; - ') - - allow $1 vnstatd_var_lib_t:dir search_dir_perms; - files_search_var_lib($1) -') - -######################################## -## -## Read vnstatd lib files. -## -## -## -## Domain allowed access. -## -## -# -interface(`vnstatd_read_lib_files',` - gen_require(` - type vnstatd_var_lib_t; - ') - - files_search_var_lib($1) - read_files_pattern($1, vnstatd_var_lib_t, vnstatd_var_lib_t) -') - -######################################## -## -## Create, read, write, and delete -## vnstatd lib files. -## -## -## -## Domain allowed access. -## -## -# -interface(`vnstatd_manage_lib_files',` - gen_require(` - type vnstatd_var_lib_t; - ') - - files_search_var_lib($1) - manage_files_pattern($1, vnstatd_var_lib_t, vnstatd_var_lib_t) -') - -######################################## -## -## Manage vnstatd lib dirs files. -## -## -## -## Domain allowed access. -## -## -# -interface(`vnstatd_manage_lib_dirs',` - gen_require(` - type vnstatd_var_lib_t; - ') - - files_search_var_lib($1) - manage_dirs_pattern($1, vnstatd_var_lib_t, vnstatd_var_lib_t) -') - - -######################################## -## -## All of the rules required to administrate -## an vnstatd environment -## -## -## -## Domain allowed access. -## -## -## -## -## Role allowed access. -## -## -## -# -interface(`vnstatd_admin',` - gen_require(` - type vnstatd_t; - type vnstatd_var_lib_t; - ') - - allow $1 vnstatd_t:process { ptrace signal_perms }; - ps_process_pattern($1, vnstatd_t) - - files_search_var_lib($1) - admin_pattern($1, vnstatd_var_lib_t) - -') diff --git a/policy/modules/services/vnstatd.te~ b/policy/modules/services/vnstatd.te~ deleted file mode 100644 index 0c18b5b..0000000 --- a/policy/modules/services/vnstatd.te~ +++ /dev/null @@ -1,76 +0,0 @@ -policy_module(vnstatd,1.0.0) - -######################################## -# -# Declarations -# - -type vnstatd_t; -type vnstatd_exec_t; -init_daemon_domain(vnstatd_t, vnstatd_exec_t) - -permissive vnstatd_t; - -type vnstatd_var_lib_t; -files_type(vnstatd_var_lib_t) - -type vnstat_t; -domain_type(vnstat_t) -type vnstat_exec_t; -domain_entry_file(vnstat_t, vnstat_exec_t) -cron_system_entry(vnstat_t, vnstat_exec_t) - -######################################## -# -# vnstatd local policy -# -allow vnstatd_t self:process { fork signal }; - -allow vnstatd_t self:fifo_file rw_fifo_file_perms; -allow vnstatd_t self:unix_stream_socket create_stream_socket_perms; - -manage_dirs_pattern(vnstatd_t, vnstatd_var_lib_t, vnstatd_var_lib_t) -manage_files_pattern(vnstatd_t, vnstatd_var_lib_t, vnstatd_var_lib_t) -files_var_lib_filetrans(vnstatd_t, vnstatd_var_lib_t, { dir file } ) - -domain_use_interactive_fds(vnstatd_t) - -files_read_etc_files(vnstatd_t) - -logging_send_syslog_msg(vnstatd_t) - -miscfiles_read_localization(vnstatd_t) - -######################################## -# -# vnstat local policy -# -allow vnstat_t self:process { signal }; - -allow vnstat_t self:fifo_file rw_fifo_file_perms; -allow vnstat_t self:unix_stream_socket create_stream_socket_perms; - -manage_dirs_pattern(vnstat_t, vnstatd_var_lib_t, vnstatd_var_lib_t) -manage_files_pattern(vnstat_t, vnstatd_var_lib_t, vnstatd_var_lib_t) -files_var_lib_filetrans(vnstat_t, vnstatd_var_lib_t, { dir file } ) - -kernel_read_network_state(vnstat_t) -kernel_read_system_state(vnstat_t) - -domain_use_interactive_fds(vnstat_t) - -files_read_etc_files(vnstat_t) - -fs_getattr_xattr_fs(vnstat_t) - -logging_send_syslog_msg(vnstat_t) - -miscfiles_read_localization(vnstat_t) - -optional_policy(` - gen_require(` - type crond_t; - ') - vnstatd_search_lib(crond_t) -') -