# Declarations
#
+## <desc>
+## <p>
+## Allow colord to access cifs file systems
+## </p>
+## </desc>
+gen_tunable(colord_use_cifs, false)
+
+## <desc>
+## <p>
+## Allow colord to access nfs file systems
+## </p>
+## </desc>
+gen_tunable(colord_use_nfs, false)
+
type colord_t;
type colord_exec_t;
dbus_system_domain(colord_t, colord_exec_t)
files_read_etc_files(colord_t)
files_read_usr_files(colord_t)
+fs_getattr_all_fs(colord_t)
fs_search_all(colord_t)
fs_read_noxattr_fs_files(colord_t)
userdom_read_inherited_user_home_content_files(colord_t)
+tunable_policy(`colord_use_cifs',`
+ fs_manage_cifs_dirs(colord_t)
+ fs_manage_cifs_files(colord_t)
+')
+
+tunable_policy(`colord_use_nfs',`
+ fs_manage_nfs_dirs(colord_t)
+ fs_manage_nfs_files(colord_t)
+')
+
tunable_policy(`use_nfs_home_dirs',`
- fs_read_nfs_files(colord_t)
+ fs_read_nfs_files(colord_t)
')
tunable_policy(`use_samba_home_dirs',`
- fs_read_cifs_files(colord_t)
+ fs_read_cifs_files(colord_t)
')
optional_policy(`