diff --git a/policy/modules/system/miscfiles.if b/policy/modules/system/miscfiles.if index 783f38ef4..5b840aa41 100644 --- a/policy/modules/system/miscfiles.if +++ b/policy/modules/system/miscfiles.if @@ -211,13 +211,25 @@ interface(`miscfiles_setattr_localization',` ######################################## ## -## Allow process to read localization info +## Allow process to read localization information. ## +## +##

+## Allow the specified domain to read the localization files. +## This is typically for time zone configuration files, such as +## /etc/localtime and files in /usr/share/zoneinfo. +## Typically, any domain which needs to know the GMT/UTC +## offset of the current timezone will need access +## to these files. Generally, it should be safe for any +## domain to read these files. +##

+##
## ## ## Domain allowed access. ## ## +## # interface(`miscfiles_read_localization',` gen_require(`