userdom: add interfaces to relabel generic user home content

Signed-off-by: Kenton Groombridge <me@concord.sh>
This commit is contained in:
Kenton Groombridge 2021-11-13 14:45:40 -05:00
parent b2ed289221
commit 00d16e45f8
1 changed files with 36 additions and 0 deletions

View File

@ -2344,6 +2344,42 @@ interface(`userdom_delete_user_home_content_files',`
allow $1 user_home_t:file delete_file_perms;
')
########################################
## <summary>
## Relabel generic user home dirs.
## </summary>
## <param name="domain">
## <summary>
## Domain allowed access.
## </summary>
## </param>
#
interface(`userdom_relabel_generic_user_home_dirs',`
gen_require(`
type user_home_t;
')
allow $1 user_home_t:dir relabel_dir_perms;
')
########################################
## <summary>
## Relabel generic user home files.
## </summary>
## <param name="domain">
## <summary>
## Domain allowed access.
## </summary>
## </param>
#
interface(`userdom_relabel_generic_user_home_files',`
gen_require(`
type user_home_t;
')
allow $1 user_home_t:file relabel_file_perms;
')
########################################
## <summary>
## Do not audit attempts to relabel user home files.