selinux-refpolicy/udica-templates/config_container.cil
Kenton Groombridge f95131dadf udica-templates: initial commit of udica templates
Signed-off-by: Kenton Groombridge <me@concord.sh>
2022-05-07 09:20:55 -04:00

34 lines
820 B
Plaintext

(block config_container
(blockabstract config_container)
(optional config_container_optional
(allow process configfile list_dir_perms)
(allow process configfile read_file_perms)
(allow process configfile read_lnk_file_perms)
)
)
(block config_rw_container
(blockabstract config_rw_container)
(blockinherit config_container)
(optional config_rw_container_optional
(allow process configfile rw_dir_perms)
(allow process configfile rw_file_perms)
(allow process configfile rw_lnk_file_perms)
)
)
(block config_manage_container
(blockabstract config_manage_container)
(blockinherit config_rw_container)
(optional config_manage_container_optional
(allow process configfile manage_dir_perms)
(allow process configfile manage_file_perms)
(allow process configfile manage_lnk_file_perms)
)
)