%PDF- %PDF-
Direktori : /usr/share/selinux/devel/include/services/ |
Current File : //usr/share/selinux/devel/include/services/aide.if |
## <summary>Aide filesystem integrity checker</summary> ######################################## ## <summary> ## Execute aide in the aide domain ## </summary> ## <param name="domain"> ## <summary> ## Domain allowed access. ## </summary> ## </param> # interface(`aide_domtrans',` gen_require(` type aide_t, aide_exec_t; ') corecmd_search_bin($1) domtrans_pattern($1, aide_exec_t, aide_t) ') ######################################## ## <summary> ## Execute aide programs in the AIDE domain. ## </summary> ## <param name="domain"> ## <summary> ## Domain allowed access. ## </summary> ## </param> ## <param name="role"> ## <summary> ## The role to allow the AIDE domain. ## </summary> ## </param> # interface(`aide_run',` gen_require(` type aide_t; ') aide_domtrans($1) role $2 types aide_t; ') ######################################## ## <summary> ## All of the rules required to administrate ## an aide environment ## </summary> ## <param name="domain"> ## <summary> ## Domain allowed access. ## </summary> ## </param> ## <rolecap/> # interface(`aide_admin',` gen_require(` type aide_t, aide_db_t, aide_log_t; ') allow $1 aide_t:process { ptrace signal_perms }; ps_process_pattern($1, aide_t) files_list_etc($1) admin_pattern($1, aide_db_t) logging_list_logs($1) admin_pattern($1, aide_log_t) ')