From 013d746abc2e7ec536b2c04806c16633121335de Mon Sep 17 00:00:00 2001 From: Chris PeBenito Date: Wed, 10 May 2006 20:24:40 +0000 Subject: [PATCH] add apache_manage_all_content, bug 1602 --- refpolicy/policy/modules/services/apache.if | 20 ++++++++++++++++++++ 1 file changed, 20 insertions(+) diff --git a/refpolicy/policy/modules/services/apache.if b/refpolicy/policy/modules/services/apache.if index 4d17f490d..a11c412b5 100644 --- a/refpolicy/policy/modules/services/apache.if +++ b/refpolicy/policy/modules/services/apache.if @@ -470,6 +470,26 @@ interface(`apache_dontaudit_rw_tcp_sockets',` dontaudit $1 httpd_t:tcp_socket { read write }; ') +######################################## +## +## Create, read, write, and delete all web content. +## +## +## +## Domain allowed access. +## +## +# +interface(`apache_manage_all_content',` + gen_require(` + attribute httpdcontent; + ') + + allow $1 httpdcontent:dir manage_dir_perms; + allow $1 httpdcontent:file manage_file_perms; + allow $1 httpdcontent:lnk_file create_lnk_perms; +') + ######################################## ## ## Allow the specified domain to read