641ac05468
* a pass cleaning up the style. * adjusted some regular expressions in the file contexts: .* is the same as (.*)? since * means 0 or more matches. * renamed a few interfaces * two rules that I dropped as they require further explanation > +files_read_all_files(hadoop_t) A very big privilege. and > +fs_associate(hadoop_tasktracker_t) This is a domain, so the only files with this type should be the /proc/pid ones, which don't require associate permissions. |
||
---|---|---|
.. | ||
admin | ||
apps | ||
kernel | ||
roles | ||
services | ||
system |