(( h1 dom h2 ) or ( t1 == mcswriteall ) or
(( t1 != mcsuntrustedproc ) and (t2 == domain)));
+mlsconstrain chr_file { read getattr ioctl }
+ (( h1 dom h2 ) or ( t1 == mcswriteall ) or
+ (( t1 != mcsuntrustedproc ) and (t2 == domain)));
+
mlsconstrain dir { search read ioctl lock }
(( h1 dom h2 ) or ( t1 == mcsreadall ) or
(( t1 != mcsuntrustedproc ) and (t2 == domain)));
allow httpd_dirsrvadmin_script_t self:sem create_sem_perms;
- manage_files_pattern(httpd_dirsrvadmin_script_t_t, dirsrvadmin_lock_t, dirsrvadmin_lock_t)
+ manage_files_pattern(httpd_dirsrvadmin_script_t, dirsrvadmin_lock_t, dirsrvadmin_lock_t)
files_lock_filetrans(httpd_dirsrvadmin_script_t, dirsrvadmin_lock_t, { file })
kernel_read_kernel_sysctls(httpd_dirsrvadmin_script_t)