Blame mls/domains/program/unused/distcc.te
|
Chris PeBenito |
31b7c0 |
#DESC distcc - Distributed compiler daemon
|
|
Chris PeBenito |
31b7c0 |
#
|
|
Chris PeBenito |
31b7c0 |
# Author: Chris PeBenito <pebenito@gentoo.org>
|
|
Chris PeBenito |
31b7c0 |
#
|
|
Chris PeBenito |
31b7c0 |
|
|
Chris PeBenito |
31b7c0 |
daemon_domain(distccd)
|
|
Chris PeBenito |
31b7c0 |
can_network_server(distccd_t)
|
|
Chris PeBenito |
31b7c0 |
can_ypbind(distccd_t)
|
|
Chris PeBenito |
31b7c0 |
log_domain(distccd)
|
|
Chris PeBenito |
31b7c0 |
tmp_domain(distccd)
|
|
Chris PeBenito |
31b7c0 |
|
|
Chris PeBenito |
31b7c0 |
allow distccd_t distccd_port_t:tcp_socket name_bind;
|
|
Chris PeBenito |
31b7c0 |
allow distccd_t self:capability { setgid setuid };
|
|
Chris PeBenito |
31b7c0 |
|
|
Chris PeBenito |
31b7c0 |
# distccd can renice
|
|
Chris PeBenito |
31b7c0 |
allow distccd_t self:process setsched;
|
|
Chris PeBenito |
31b7c0 |
|
|
Chris PeBenito |
31b7c0 |
# compiler stuff
|
|
Chris PeBenito |
31b7c0 |
allow distccd_t { bin_t sbin_t }:dir { search getattr };
|
|
Chris PeBenito |
31b7c0 |
allow distccd_t { bin_t sbin_t }:lnk_file { getattr read };
|
|
Chris PeBenito |
31b7c0 |
can_exec(distccd_t,bin_t)
|
|
Chris PeBenito |
31b7c0 |
can_exec(distccd_t,lib_t)
|
|
Chris PeBenito |
31b7c0 |
|
|
Chris PeBenito |
31b7c0 |
# comm stuff
|
|
Chris PeBenito |
31b7c0 |
allow distccd_t net_conf_t:file r_file_perms;
|
|
Chris PeBenito |
31b7c0 |
allow distccd_t self:{ unix_stream_socket unix_dgram_socket } { create connect read write };
|
|
Chris PeBenito |
31b7c0 |
allow distccd_t self:fifo_file { read write getattr };
|
|
Chris PeBenito |
31b7c0 |
|
|
Chris PeBenito |
31b7c0 |
# config access
|
|
Chris PeBenito |
31b7c0 |
allow distccd_t { etc_t etc_runtime_t }:file r_file_perms;
|
|
Chris PeBenito |
31b7c0 |
allow distccd_t proc_t:file r_file_perms;
|
|
Chris PeBenito |
31b7c0 |
|
|
Chris PeBenito |
31b7c0 |
allow distccd_t var_t:dir search;
|
|
Chris PeBenito |
31b7c0 |
allow distccd_t admin_tty_type:chr_file { ioctl read write };
|