Blame mls/domains/program/unused/dante.te
|
Chris PeBenito |
31b7c0 |
#DESC dante - socks daemon
|
|
Chris PeBenito |
31b7c0 |
#
|
|
Chris PeBenito |
31b7c0 |
# Author: petre rodan <kaiowas@gentoo.org>
|
|
Chris PeBenito |
31b7c0 |
#
|
|
Chris PeBenito |
31b7c0 |
|
|
Chris PeBenito |
31b7c0 |
type dante_conf_t, file_type, sysadmfile;
|
|
Chris PeBenito |
31b7c0 |
|
|
Chris PeBenito |
31b7c0 |
daemon_domain(dante)
|
|
Chris PeBenito |
31b7c0 |
can_network_server(dante_t)
|
|
Chris PeBenito |
31b7c0 |
|
|
Chris PeBenito |
31b7c0 |
allow dante_t self:fifo_file { read write };
|
|
Chris PeBenito |
31b7c0 |
allow dante_t self:capability { setuid setgid };
|
|
Chris PeBenito |
31b7c0 |
allow dante_t self:unix_dgram_socket { connect create write };
|
|
Chris PeBenito |
31b7c0 |
allow dante_t self:unix_stream_socket { connect create read setopt write };
|
|
Chris PeBenito |
31b7c0 |
allow dante_t self:tcp_socket connect;
|
|
Chris PeBenito |
31b7c0 |
|
|
Chris PeBenito |
31b7c0 |
allow dante_t socks_port_t:tcp_socket name_bind;
|
|
Chris PeBenito |
31b7c0 |
|
|
Chris PeBenito |
31b7c0 |
allow dante_t { etc_t etc_runtime_t }:file r_file_perms;
|
|
Chris PeBenito |
31b7c0 |
r_dir_file(dante_t, dante_conf_t)
|
|
Chris PeBenito |
31b7c0 |
|
|
Chris PeBenito |
31b7c0 |
allow dante_t initrc_var_run_t:file { getattr write };
|
|
Chris PeBenito |
31b7c0 |
|