selinux-refpolicy/policy/modules/roles/guest.te
Kenton Groombridge 76a6ee4fb9 apache, roles: use user exec domain attribute
Signed-off-by: Kenton Groombridge <me@concord.sh>
2021-10-13 19:07:12 -04:00

28 lines
442 B
Plaintext

policy_module(guest, 1.4.0)
########################################
#
# Declarations
#
role guest_r;
userdom_restricted_user_template(guest)
kernel_read_system_state(guest_t)
########################################
#
# Local policy
#
optional_policy(`
apache_role(guest, guest_t, guest_application_exec_domain, guest_r)
')
optional_policy(`
dbus_role_template(guest, guest_r, guest_t)
')
#gen_user(guest_u, user, guest_r, s0, s0)