# HOME_ROOT expands to all valid home directory prefixes found in /etc/passwd # HOME_DIR expands to each users home directory, # and to HOME_ROOT/[^/]+ for each HOME_ROOT. # ROLE expands to each users role when role != user_r, and to "user" otherwise. HOME_ROOT -d system_u:object_r:home_root_t:s0 HOME_DIR -d system_u:object_r:ROLE_home_dir_t:s0-s15:c0.c255 HOME_DIR/.+ <> HOME_ROOT/\.journal <> HOME_ROOT/lost\+found -d system_u:object_r:lost_found_t:s15:c0.c255 HOME_ROOT/lost\+found/.* <> HOME_DIR/((www)|(web)|(public_html))(/.+)? system_u:object_r:httpd_ROLE_content_t:s0 HOME_DIR/\.gnupg(/.+)? system_u:object_r:ROLE_gpg_secret_t:s0 HOME_DIR/\.ircmotd -- system_u:object_r:ROLE_irc_home_t:s0 /tmp/orbit-USER(-.*)? -d system_u:object_r:ROLE_orbit_tmp_t:s0 /tmp/orbit-USER(-.*)?/linc.* -s <> /tmp/orbit-USER(-.*)?/bonobo.* -- system_u:object_r:ROLE_orbit_tmp_t:s0 HOME_ROOT/a?quota\.(user|group) -- system_u:object_r:quota_db_t:s0 HOME_DIR/\.screenrc -- system_u:object_r:ROLE_screen_ro_home_t:s0 HOME_DIR/\.spamassassin(/.*)? system_u:object_r:ROLE_spamassassin_home_t:s0 HOME_DIR/\.ssh(/.*)? system_u:object_r:ROLE_home_ssh_t:s0 HOME_DIR/.*/plugins/libflashplayer\.so.* -- system_u:object_r:texrel_shlib_t:s0