File: //usr/share/udica/templates/config_container.cil
(block config_container
	(optional config_container_optional
		(allow process configfile (dir (ioctl read getattr lock search open)))
		(allow process configfile (file (ioctl read getattr lock open)))
		(allow process configfile (lnk_file (read getattr)))
	)
)
(block config_rw_container
	(blockinherit config_container)
	(optional config_rw_container_optional
		(allow process configfile (dir (ioctl read write getattr lock append open)))
		(allow process configfile (file (ioctl read write getattr lock append open)))
		(allow process configfile (lnk_file (ioctl read write getattr lock append open)))
	)
)
(block config_manage_container
	(optional config_manage_container_optional
		(allow process configfile (dir (ioctl read write create getattr setattr lock unlink link rename add_name remove_name reparent search rmdir open)))
		(allow process configfile (file (ioctl read write create getattr setattr lock append unlink link rename open)))
		(allow process configfile (lnk_file (ioctl read write create getattr setattr lock append unlink link rename open)))
	)
)