selinux-policy/strict/file_contexts/homedir_template
2005-04-29 17:45:15 +00:00

33 lines
1.9 KiB
Plaintext

# HOME_ROOT expands to all valid home directory prefixes found in /etc/passwd
# HOME_DIR expands to each user's home directory,
# and to HOME_ROOT/[^/]+ for each HOME_ROOT.
# ROLE expands to each user's role when role != user_r, and to "user" otherwise.
HOME_ROOT -d system_u:object_r:home_root_t
HOME_DIR -d system_u:object_r:ROLE_home_dir_t
HOME_DIR/.+ system_u:object_r:ROLE_home_t
HOME_ROOT/\.journal <<none>>
HOME_ROOT/lost\+found(/.*)? system_u:object_r:lost_found_t
HOME_DIR/((www)|(web)|(public_html))(/.+)? system_u:object_r:httpd_ROLE_content_t
HOME_DIR/\.gnupg(/.+)? system_u:object_r:ROLE_gpg_secret_t
HOME_DIR/\.ircmotd -- system_u:object_r:ROLE_home_irc_t
HOME_DIR/\.galeon(/.*)? system_u:object_r:ROLE_mozilla_home_t
HOME_DIR/\.netscape(/.*)? system_u:object_r:ROLE_mozilla_home_t
HOME_DIR/\.mozilla(/.*)? system_u:object_r:ROLE_mozilla_home_t
HOME_DIR/\.phoenix(/.*)? system_u:object_r:ROLE_mozilla_home_t
HOME_DIR/\.gconfd(/.*)? system_u:object_r:ROLE_mozilla_home_t
HOME_DIR/\.gconf(/.*)? system_u:object_r:ROLE_mozilla_home_t
HOME_DIR/\.gnome2/epiphany(/.*)? system_u:object_r:ROLE_mozilla_home_t
HOME_DIR/My.Downloads(/.*)? system_u:object_r:ROLE_mozilla_home_t
HOME_DIR/\.java(/.*)? system_u:object_r:ROLE_mozilla_home_t
HOME_DIR/\.mplayer(/.*)? system_u:object_r:ROLE_mplayer_home_t
HOME_ROOT/a?quota\.(user|group) -- system_u:object_r:quota_db_t
HOME_DIR/\.screenrc -- system_u:object_r:ROLE_screen_ro_home_t
HOME_DIR/\.spamassassin(/.*)? system_u:object_r:ROLE_spamassassin_home_t
HOME_DIR/\.ssh(/.*)? system_u:object_r:ROLE_home_ssh_t
HOME_DIR/\.uml(/.*)? system_u:object_r:ROLE_uml_rw_t
HOME_DIR/\.vmware(/.*)? system_u:object_r:ROLE_vmware_file_t
HOME_DIR/vmware(/.*)? system_u:object_r:ROLE_vmware_file_t
HOME_DIR/\.vmware[^/]*/.*\.cfg -- system_u:object_r:ROLE_vmware_conf_t
HOME_DIR/\.Xauthority.* -- system_u:object_r:ROLE_xauth_home_t
HOME_DIR/.*/plugins/libflashplayer\.so.* -- system_u:object_r:texrel_shlib_t