Move base directories to /var/games
[selinux.git] / cod4 / cod4.te
1 policy_module(cod4, 0.1.38)
2
3 require {
4     type games_data_t;
5 }
6
7 # File context for the executable process
8 type cod4_t;
9 type cod4_exec_t;
10
11 type cod4_rw_t;
12 files_type(cod4_rw_t)
13
14 type cod4_ro_t;
15 files_type(cod4_ro_t)
16
17 init_domain(cod4_t, cod4_exec_t)
18 init_daemon_domain(cod4_t, cod4_exec_t)
19
20 corenet_udp_sendrecv_generic_port(cod4_t)
21 corenet_udp_bind_generic_port(cod4_t)
22 corenet_udp_bind_generic_node(cod4_t)
23
24 read_files_pattern(cod4_t, cod4_ro_t, cod4_ro_t)
25 list_dirs_pattern(cod4_t, cod4_ro_t, cod4_ro_t)
26
27 manage_files_pattern(cod4_t, cod4_rw_t, cod4_rw_t)
28 manage_dirs_pattern(cod4_t, cod4_rw_t, cod4_rw_t)
29 setattr_files_pattern(cod4_t, cod4_rw_t, cod4_rw_t)
30
31 sysnet_dns_name_resolve(cod4_t)
32
33 allow init_t cod4_t:process { noatsecure };
34
35 list_dirs_pattern(cod4_t, games_data_t, games_data_t)