]>
Commit | Line | Data |
---|---|---|
826d0142 | 1 | policy_module(gitosis, 1.2.0) |
dbed9536 CP |
2 | |
3 | ######################################## | |
4 | # | |
5 | # Declarations | |
6 | # | |
7 | ||
8 | type gitosis_t; | |
9 | type gitosis_exec_t; | |
10 | application_domain(gitosis_t, gitosis_exec_t) | |
11 | role system_r types gitosis_t; | |
12 | ||
13 | type gitosis_var_lib_t; | |
14 | files_type(gitosis_var_lib_t) | |
15 | ||
16 | ######################################## | |
17 | # | |
18 | # gitosis local policy | |
19 | # | |
20 | ||
21 | allow gitosis_t self:fifo_file rw_fifo_file_perms; | |
22 | ||
23 | exec_files_pattern(gitosis_t, gitosis_var_lib_t, gitosis_var_lib_t) | |
24 | manage_files_pattern(gitosis_t, gitosis_var_lib_t, gitosis_var_lib_t) | |
25 | manage_lnk_files_pattern(gitosis_t, gitosis_var_lib_t, gitosis_var_lib_t) | |
26 | manage_dirs_pattern(gitosis_t, gitosis_var_lib_t, gitosis_var_lib_t) | |
27 | ||
5f04c91f JS |
28 | kernel_read_system_state(gitosis_t) |
29 | ||
30 | corecmd_exec_bin(gitosis_t) | |
dbed9536 CP |
31 | corecmd_exec_shell(gitosis_t) |
32 | ||
5f04c91f | 33 | dev_read_urand(gitosis_t) |
dbed9536 | 34 | |
5f04c91f | 35 | files_read_etc_files(gitosis_t) |
dbed9536 CP |
36 | files_read_usr_files(gitosis_t) |
37 | files_search_var_lib(gitosis_t) | |
38 | ||
39 | miscfiles_read_localization(gitosis_t) | |
5f04c91f JS |
40 | |
41 | sysnet_read_config(gitosis_t) |