From fc2de5c21cc27d938a7f051a9f1f3ebaac237c08 Mon Sep 17 00:00:00 2001 From: Chris PeBenito Date: Tue, 20 Oct 2015 12:53:58 -0400 Subject: [PATCH] Add rules for sysadm_r to manage the services. --- policy/modules/roles/sysadm.te | 9 +++++++++ 1 file changed, 9 insertions(+) diff --git a/policy/modules/roles/sysadm.te b/policy/modules/roles/sysadm.te index 4b24ac3ee..54e30d841 100644 --- a/policy/modules/roles/sysadm.te +++ b/policy/modules/roles/sysadm.te @@ -34,6 +34,15 @@ ubac_file_exempt(sysadm_t) ubac_fd_exempt(sysadm_t) init_exec(sysadm_t) +init_get_system_status(sysadm_t) +init_disable(sysadm_t) +init_enable(sysadm_t) +init_reload(sysadm_t) +init_reboot_system(sysadm_t) +init_shutdown_system(sysadm_t) +init_start_generic_units(sysadm_t) +init_stop_generic_units(sysadm_t) +init_reload_generic_units(sysadm_t) # Add/remove user home directories userdom_manage_user_home_dirs(sysadm_t)