fstools: Move lines.
Signed-off-by: Chris PeBenito <chpebeni@linux.microsoft.com>
This commit is contained in:
parent
3c93ad9d70
commit
eca2a04638
@ -19,14 +19,14 @@ files_tmp_file(fsadm_tmp_t)
|
|||||||
type fsadm_run_t;
|
type fsadm_run_t;
|
||||||
files_runtime_file(fsadm_run_t)
|
files_runtime_file(fsadm_run_t)
|
||||||
|
|
||||||
ifdef(`distro_gentoo',`
|
|
||||||
type fsadm_db_t;
|
|
||||||
files_type(fsadm_db_t)
|
|
||||||
')
|
|
||||||
|
|
||||||
type swapfile_t; # customizable
|
type swapfile_t; # customizable
|
||||||
files_type(swapfile_t)
|
files_type(swapfile_t)
|
||||||
|
|
||||||
|
ifdef(`distro_gentoo',`
|
||||||
|
type fsadm_db_t;
|
||||||
|
files_type(fsadm_db_t)
|
||||||
|
')
|
||||||
|
|
||||||
########################################
|
########################################
|
||||||
#
|
#
|
||||||
# local policy
|
# local policy
|
||||||
@ -60,10 +60,6 @@ allow fsadm_t fsadm_run_t:dir manage_dir_perms;
|
|||||||
allow fsadm_t fsadm_run_t:file manage_file_perms;
|
allow fsadm_t fsadm_run_t:file manage_file_perms;
|
||||||
files_runtime_filetrans(fsadm_t, fsadm_run_t, dir)
|
files_runtime_filetrans(fsadm_t, fsadm_run_t, dir)
|
||||||
|
|
||||||
ifdef(`distro_gentoo',`
|
|
||||||
manage_files_pattern(fsadm_t, fsadm_db_t, fsadm_db_t)
|
|
||||||
')
|
|
||||||
|
|
||||||
# log files
|
# log files
|
||||||
allow fsadm_t fsadm_log_t:dir setattr;
|
allow fsadm_t fsadm_log_t:dir setattr;
|
||||||
manage_files_pattern(fsadm_t, fsadm_log_t, fsadm_log_t)
|
manage_files_pattern(fsadm_t, fsadm_log_t, fsadm_log_t)
|
||||||
@ -178,6 +174,10 @@ ifdef(`distro_debian',`
|
|||||||
term_dontaudit_use_unallocated_ttys(fsadm_t)
|
term_dontaudit_use_unallocated_ttys(fsadm_t)
|
||||||
')
|
')
|
||||||
|
|
||||||
|
ifdef(`distro_gentoo',`
|
||||||
|
manage_files_pattern(fsadm_t, fsadm_db_t, fsadm_db_t)
|
||||||
|
')
|
||||||
|
|
||||||
ifdef(`distro_redhat',`
|
ifdef(`distro_redhat',`
|
||||||
optional_policy(`
|
optional_policy(`
|
||||||
unconfined_domain(fsadm_t)
|
unconfined_domain(fsadm_t)
|
||||||
|
Loading…
Reference in New Issue
Block a user