module vmdriver 1.0; require { type virt_var_lib_t; type svirt_tcg_t; class sock_file { create unlink }; class dir { write remove_name add_name }; } #============= svirt_tcg_t ============== allow svirt_tcg_t virt_var_lib_t:dir { write remove_name add_name }; allow svirt_tcg_t virt_var_lib_t:sock_file { create unlink };