Index: fedora-policy-20221019/policy/modules/contrib/apache.if =================================================================== --- fedora-policy-20221019.orig/policy/modules/contrib/apache.if +++ fedora-policy-20221019/policy/modules/contrib/apache.if @@ -2007,3 +2007,25 @@ interface(`apache_read_semaphores',` allow $1 httpd_t:sem r_sem_perms; ') + +####################################### +## +## Allow the specified domain to execute +## httpd_sys_content_t and manage httpd_sys_rw_content_t +## +## +## +## Domain allowed access. +## +## +# +interface(`apache_exec_sys_content',` + gen_require(` + type httpd_sys_content_t; + type httpd_sys_rw_content_t; + ') + + apache_manage_sys_content_rw($1) + filetrans_pattern($1, httpd_sys_content_t, httpd_sys_rw_content_t, { file dir lnk_file }) + can_exec($1, httpd_sys_content_t) +')