## High quality television application. ######################################## ## ## Role access for tvtime ## ## ## ## The prefix of the user role (e.g., user ## is the prefix for user_r). ## ## ## ## ## User domain for the role. ## ## ## ## ## User exec domain for execute and transition access. ## ## ## ## ## Role allowed access ## ## # template(`tvtime_role',` gen_require(` attribute_role tvtime_roles; type tvtime_t, tvtime_exec_t, tvtime_tmp_t; type tvtime_home_t, tvtime_tmpfs_t; ') roleattribute $4 tvtime_roles; domtrans_pattern($3, tvtime_exec_t, tvtime_t) ps_process_pattern($3, tvtime_t) allow $3 tvtime_t:process { ptrace signal_perms }; allow $2 { tvtime_home_t tvtime_tmp_t }:dir { manage_dir_perms relabel_dir_perms }; allow $2 { tvtime_home_t tvtime_tmpfs_t tvtime_tmp_t }:file { manage_file_perms relabel_file_perms }; allow $2 { tvtime_home_t tvtime_tmpfs_t }:lnk_file { manage_lnk_file_perms relabel_lnk_file_perms }; allow $2 tvtime_tmpfs_t:fifo_file { manage_fifo_file_perms relabel_fifo_file_perms }; allow $2 tvtime_tmpfs_t:sock_file { manage_sock_file_perms relabel_sock_file_perms }; userdom_user_home_dir_filetrans($2, tvtime_home_t, dir, ".tvtime") optional_policy(` systemd_user_app_status($1, tvtime_t) ') ')