## IRC client policy. ######################################## ## ## Role access for IRC. ## ## ## ## Role allowed access. ## ## ## ## ## User domain for the role. ## ## # interface(`irc_role',` gen_require(` attribute_role irc_roles; type irc_t, irc_exec_t, irc_home_t; type irc_tmp_t, irc_log_home_t; ') ######################################## # # Declarations # roleattribute $1 irc_roles; ######################################## # # Policy # domtrans_pattern($2, irc_exec_t, irc_t) ps_process_pattern($2, irc_t) allow $2 irc_t:process { ptrace signal_perms }; allow $2 { irc_home_t irc_log_home_t irc_tmp_t }:dir { manage_dir_perms relabel_dir_perms }; allow $2 { irc_home_t irc_log_home_t irc_tmp_t }:file { manage_file_perms relabel_file_perms }; allow $2 { irc_home_t irc_log_home_t irc_tmp_t }:lnk_file { manage_lnk_file_perms relabel_lnk_file_perms }; userdom_user_home_dir_filetrans($2, irc_home_t, dir, ".irssi") userdom_user_home_dir_filetrans($2, irc_home_t, file, ".ircmotd") userdom_user_home_dir_filetrans($2, irc_log_home_t, dir, "irclogs") ')