diff --git a/policy/modules/roles/staff.te b/policy/modules/roles/staff.te index 0c9876c..3fed14e 100644 --- a/policy/modules/roles/staff.te +++ b/policy/modules/roles/staff.te @@ -27,6 +27,11 @@ optional_policy(` ') optional_policy(` + oident_manage_user_content(staff_t) + oident_relabel_user_content(staff_t) +') + +optional_policy(` postgresql_role(staff_r, staff_t) ') @@ -121,10 +126,6 @@ ifndef(`distro_redhat',` ') optional_policy(` - oident_manage_user_content(staff_t) - oident_relabel_user_content(staff_t) - ') - optional_policy(` pyzor_role(staff_r, staff_t) ') diff --git a/policy/modules/roles/unprivuser.te b/policy/modules/roles/unprivuser.te index e8a507d..93b9f7f 100644 --- a/policy/modules/roles/unprivuser.te +++ b/policy/modules/roles/unprivuser.te @@ -17,6 +17,11 @@ optional_policy(` ') optional_policy(` + oident_manage_user_content(user_t) + oident_relabel_user_content(user_t) +') + +optional_policy(` screen_role_template(user, user_r, user_t) ') @@ -94,11 +99,6 @@ ifndef(`distro_redhat',` ') optional_policy(` - oident_manage_user_content(user_t) - oident_relabel_user_content(user_t) - ') - - optional_policy(` postgresql_role(user_r, user_t) ')