## A scalable high-availability cluster resource manager. ######################################## ## ## All of the rules required to ## administrate an pacemaker environment. ## ## ## ## Domain allowed access. ## ## ## ## ## Role allowed access. ## ## ## # interface(`pacemaker_admin',` gen_require(` type pacemaker_t, pacemaker_initrc_exec_t, pacemaker_var_lib_t; type pacemaker_var_run_t; ') allow $1 pacemaker_t:process { ptrace signal_perms }; ps_process_pattern($1, pacemaker_t) init_startstop_service($1, $2, pacemaker_t, pacemaker_initrc_exec_t) files_search_var_lib($1) admin_pattern($1, pacemaker_var_lib_t) files_search_pids($1) admin_pattern($1, pacemaker_var_run_t) ')