anvil/selinux/anvil-subnode.te.in

30 lines
511 B
Plaintext
Raw Normal View History

2024-03-07 04:29:05 +00:00
policy_module(anvil-subnode, 1.0.0)
########################################
#
# Declarations
#
########################################
#
# Local policy
#
# Use existing types; don't declare unless it's new.
#
require {
type mnt_t;
type virsh_t;
class file { open read };
2024-03-07 04:29:05 +00:00
}
#============= drbd_t ==============
# drbd rules will be provided by drbd-utils package.
2024-03-07 04:29:05 +00:00
#============= virsh_t ==============
# Needed for virsh to access the domain XMLs under /mnt.
2024-03-07 04:29:05 +00:00
allow virsh_t mnt_t:file { open read };