diff --git a/refpolicy/policy/modules/services/cron.fc b/refpolicy/policy/modules/services/cron.fc new file mode 100644 index 00000000..13eb62c6 --- /dev/null +++ b/refpolicy/policy/modules/services/cron.fc @@ -0,0 +1,41 @@ +# Copyright (C) 2005 Tresys Technology, LLC + +/etc/cron\.d(/.*)? system_u:object_r:system_cron_spool_t +/etc/crontab -- system_u:object_r:system_cron_spool_t + +/usr/bin/at -- system_u:object_r:crontab_exec_t +/usr/bin/(f)?crontab -- system_u:object_r:crontab_exec_t + +/usr/sbin/anacron -- system_u:object_r:anacron_exec_t +/usr/sbin/atd -- system_u:object_r:crond_exec_t +/usr/sbin/cron(d)? -- system_u:object_r:crond_exec_t +/usr/sbin/fcron -- system_u:object_r:crond_exec_t + +/var/log/cron.* -- system_u:object_r:crond_log_t + +/var/run/atd\.pid -- system_u:object_r:crond_var_run_t +/var/run/crond?\.pid -- system_u:object_r:crond_var_run_t +/var/run/crond\.reboot -- system_u:object_r:crond_var_run_t +/var/run/fcron\.fifo -s system_u:object_r:crond_var_run_t +/var/run/fcron\.pid -- system_u:object_r:crond_var_run_t + +/var/spool/at -d system_u:object_r:cron_spool_t +/var/spool/at/spool -d system_u:object_r:cron_spool_t +/var/spool/at/[^/]* -- <> + +/var/spool/cron -d system_u:object_r:cron_spool_t +/var/spool/cron/root -- system_u:object_r:sysadm_cron_spool_t + +/var/spool/cron/[^/]* -- <> + +/var/spool/cron/crontabs -d system_u:object_r:cron_spool_t +/var/spool/cron/crontabs/.* -- <> +/var/spool/cron/crontabs/root -- system_u:object_r:sysadm_cron_spool_t + +/var/spool/fcron -d system_u:object_r:cron_spool_t +/var/spool/fcron/.* <> +/var/spool/fcron/systab\.orig -- system_u:object_r:system_cron_spool_t +/var/spool/fcron/systab -- system_u:object_r:system_cron_spool_t +/var/spool/fcron/new\.systab -- system_u:object_r:system_cron_spool_t + +