diff --git a/refpolicy/policy/modules/system/files.if b/refpolicy/policy/modules/system/files.if index 95d0db3..f3fbbca 100644 --- a/refpolicy/policy/modules/system/files.if +++ b/refpolicy/policy/modules/system/files.if @@ -378,15 +378,15 @@ class sock_file { getattr unlink }; ######################################## # -# files_manage_general_lock_files(domain,[`optional']) +# files_manage_system_lock_files(domain,[`optional']) # -define(`files_manage_general_lock_files',` -requires_block_template(files_manage_general_lock_files_depend,$2) +define(`files_manage_system_lock_files',` +requires_block_template(files_manage_system_lock_files_depend,$2) allow $1 var_lock_t:dir { getattr search create read write setattr add_name remove_name rmdir }; allow $1 var_lock_t:file { getattr create read write setattr unlink }; ') -define(`files_remove_general_lock_files_depend',` +define(`files_manage_system_lock_files_depend',` type var_lock_t; class dir { getattr search create read write setattr add_name remove_name rmdir }; class file { getattr create read write setattr unlink }; diff --git a/refpolicy/policy/modules/system/getty.te b/refpolicy/policy/modules/system/getty.te index d2b2ab5..5d240d6 100644 --- a/refpolicy/policy/modules/system/getty.te +++ b/refpolicy/policy/modules/system/getty.te @@ -45,7 +45,7 @@ logging_send_system_log_message(getty_t) # Write to /var/run/utmp. files_modify_system_runtime_data(getty_t) -files_manage_general_lock_files(getty_t) +files_manage_system_lock_files(getty_t) files_read_runtime_system_config(getty_t) files_read_general_system_config(getty_t) miscfiles_read_localization(getty_t) diff --git a/refpolicy/policy/modules/system/init.te b/refpolicy/policy/modules/system/init.te index d945cad..d6453cc 100644 --- a/refpolicy/policy/modules/system/init.te +++ b/refpolicy/policy/modules/system/init.te @@ -236,7 +236,7 @@ files_remove_all_lock_files(initrc_t) files_remove_all_daemon_runtime_data(initrc_t) files_read_general_system_config(initrc_t) files_create_runtime_system_config(initrc_t) -files_manage_general_lock_files(initrc_t) +files_manage_system_lock_files(initrc_t) files_execute_system_config_script(initrc_t) files_read_general_shared_resources(initrc_t) files_manage_pseudorandom_saved_seed(initrc_t)