selinux-refpolicy/policy/modules
Sven Vermeulen d4dad1950d helper interfaces to read/manage all user content
To facilitate handling user home content (through the
user_home_content_type attribute) the following interfaces are provided:

- userdom_read_all_user_home_content
- userdom_manage_all_user_home_content

Domains that are granted these privileges are able to read (or manage)
all user home content, so not only the generic one (user_home_t) but all
types that have been assigned the user_home_content_type attribute. This
is more than just user_home_t and the XDG types, so the use should not
be granted automatically.

As part of the larger XDG patch set, these interfaces are called through
the *_read_all_user_content and *_manage_all_user_content booleans which
are by default not enabled.

Changes since v2:
- Fix typo in pattern call

Signed-off-by: Sven Vermeulen <sven.vermeulen@siphos.be>
2018-06-10 13:23:01 -04:00
..
admin Bump module versions for release. 2018-01-14 14:08:09 -05:00
apps Bump module versions for release. 2017-08-05 12:59:42 -04:00
contrib@f39e8bd2eb corecommands: Module version bump. 2018-06-10 13:19:13 -04:00
kernel corecommands: Module version bump. 2018-06-10 13:19:13 -04:00
roles Bump module versions for release. 2018-01-14 14:08:09 -05:00
services Allow X server users to manage all xdg resources 2018-06-10 13:23:01 -04:00
system helper interfaces to read/manage all user content 2018-06-10 13:23:01 -04:00