> > +## Determine whether gssd can write > > +## generic user temporary content. > > +##
> > +##> > ## Determine whether nfs can modify > > ## public files used for public file > > ## transfer services. Directories/Files must > > @@ -309,6 +317,11 @@ tunable_policy(`allow_gssd_read_tmp',` > > userdom_read_user_tmp_symlinks(gssd_t) > > ') > > > > +tunable_policy(`allow_gssd_write_tmp',` > > + userdom_list_user_tmp(gssd_t) > > + userdom_write_user_tmp_files(gssd_t) > > +') > > + > > optional_policy(` > > automount_signal(gssd_t) > > ') > We probably want to think about better boolean name for this one. Maybe > > gssd_write_user_tmp_files That does sound better yes. I was basing it off the already existing read boolean. The original read one should be renamed too then probably. In that case, do these sound better? gssd_write_user_tmp_files gssd_read_user_tmp_files I can send a patch that renames the read one and adds the new write bool.