diff --git a/doc/example.if b/doc/example.if index 48f5bc9..54d42ae 100644 --- a/doc/example.if +++ b/doc/example.if @@ -1,8 +1,8 @@ ## <summary>Myapp example policy</summary> ## <desc> ## <p> -## More descriptive text about myapp. The <desc> -## tag can also use <p>, <ul>, and <ol> +## More descriptive text about myapp. The desc +## tag can also use p, ul, and ol ## html tags for formatting. ## </p> ## <p> @@ -21,7 +21,9 @@ ## Execute a domain transition to run myapp. ## </summary> ## <param name="domain"> +## <summary> ## Domain allowed to transition. +## </summary> ## </param> # interface(`myapp_domtrans',` @@ -29,12 +31,7 @@ interface(`myapp_domtrans',` type myapp_t, myapp_exec_t; ') - domain_auto_trans($1,myapp_exec_t,myapp_t) - - allow $1 myapp_t:fd use; - allow myapp_t $1:fd use; - allow $1 myapp_t:fifo_file rw_file_perms; - allow $1 myapp_t:process sigchld; + domtrans_pattern($1,myapp_exec_t,myapp_t) ') ######################################## @@ -42,7 +39,9 @@ interface(`myapp_domtrans',` ## Read myapp log files. ## </summary> ## <param name="domain"> +## <summary> ## Domain allowed to read the log files. +## </summary> ## </param> # interface(`myapp_read_log',` @@ -51,5 +50,5 @@ interface(`myapp_read_log',` ') logging_search_logs($1) - allow $1 myapp_log_t:file r_file_perms; + allow $1 myapp_log_t:file read_file_perms; ')