Oreon-Lime-R2/selinux-policy/selinux-policy-d9f4a2b/selinux-policy-d9f4a2bbeb91fd95d0c35a90936efb9ea99d2455/policy/modules/roles/unprivuser.if

50 lines
885 B
Text

## <summary>Generic unprivileged user</summary>
########################################
## <summary>
## Change to the generic user role.
## </summary>
## <param name="role">
## <summary>
## Role allowed access.
## </summary>
## </param>
## <rolecap/>
#
interface(`unprivuser_role_change',`
gen_require(`
role user_r;
')
allow $1 user_r;
')
########################################
## <summary>
## Change from the generic user role.
## </summary>
## <desc>
## <p>
## Change from the generic user role to
## the specified role.
## </p>
## <p>
## This is an interface to support third party modules
## and its use is not allowed in upstream reference
## policy.
## </p>
## </desc>
## <param name="role">
## <summary>
## Role allowed access.
## </summary>
## </param>
## <rolecap/>
#
interface(`unprivuser_role_change_to',`
gen_require(`
role user_r;
')
allow user_r $1;
')