policy_module(anvil-subnode, 1.0.0) ######################################## # # Declarations # ######################################## # # Local policy # # Use existing types; don't declare unless it's new. # require { type mnt_t; type var_lock_t; type virsh_t; } #============= drbd_t ============== # drbd policy will be provided by drbd-utils package #============= virsh_t ============== allow virsh_t mnt_t:file { open read };