/usr/share/selinux/ubuntu/include/roles/webadm.if is in selinux-policy-ubuntu-dev 0.2.20091117-0ubuntu2.
This file is owned by root:root, with mode 0o644.
The actual contents of the file can be viewed below.
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 | ## <summary>Web administrator role</summary>
########################################
## <summary>
## Change to the web administrator role.
## </summary>
## <param name="role">
## <summary>
## Role allowed access.
## </summary>
## </param>
## <rolecap/>
#
interface(`webadm_role_change',`
gen_require(`
role webadm_r;
')
allow $1 webadm_r;
')
########################################
## <summary>
## Change from the web administrator role.
## </summary>
## <desc>
## <p>
## Change from the web administrator role to
## the specified role.
## </p>
## <p>
## This is an interface to support third party modules
## and its use is not allowed in upstream reference
## policy.
## </p>
## </desc>
## <param name="role">
## <summary>
## Role allowed access.
## </summary>
## </param>
## <rolecap/>
#
interface(`webadm_role_change_to',`
gen_require(`
role webadm_r;
')
allow webadm_r $1;
')
|