Blame policy/modules/kernel/mcs.te
|
Chris PeBenito |
17de1b |
|
|
Chris PeBenito |
8708d9 |
policy_module(mcs,1.0.4)
|
|
Chris PeBenito |
17de1b |
|
|
Chris PeBenito |
17de1b |
########################################
|
|
Chris PeBenito |
17de1b |
#
|
|
Chris PeBenito |
17de1b |
# Declarations
|
|
Chris PeBenito |
17de1b |
#
|
|
Chris PeBenito |
17de1b |
|
|
Chris PeBenito |
17de1b |
attribute mcskillall;
|
|
Chris PeBenito |
465510 |
attribute mcsptraceall;
|
|
Chris PeBenito |
17de1b |
attribute mcssetcats;
|
|
Chris PeBenito |
17de1b |
|
|
Chris PeBenito |
17de1b |
########################################
|
|
Chris PeBenito |
17de1b |
#
|
|
Chris PeBenito |
17de1b |
# THIS IS A HACK
|
|
Chris PeBenito |
17de1b |
#
|
|
Chris PeBenito |
17de1b |
# Only the base module can have range_transitions, so we
|
|
Chris PeBenito |
17de1b |
# temporarily have to break encapsulation to work around this.
|
|
Chris PeBenito |
17de1b |
#
|
|
Chris PeBenito |
17de1b |
|
|
Chris PeBenito |
17de1b |
type auditd_exec_t;
|
|
Chris PeBenito |
17de1b |
type crond_exec_t;
|
|
Chris PeBenito |
17de1b |
type cupsd_exec_t;
|
|
Chris PeBenito |
17de1b |
type getty_t;
|
|
Chris PeBenito |
17de1b |
type init_t;
|
|
Chris PeBenito |
17de1b |
type init_exec_t;
|
|
Chris PeBenito |
17de1b |
type initrc_t;
|
|
Chris PeBenito |
17de1b |
type initrc_exec_t;
|
|
Chris PeBenito |
17de1b |
type login_exec_t;
|
|
Chris PeBenito |
17de1b |
type sshd_exec_t;
|
|
Chris PeBenito |
17de1b |
type udev_exec_t;
|
|
Chris PeBenito |
17de1b |
type unconfined_t;
|
|
Chris PeBenito |
17de1b |
type xdm_exec_t;
|
|
Chris PeBenito |
17de1b |
|
|
Chris PeBenito |
17de1b |
ifdef(`enable_mcs',`
|
|
Chris PeBenito |
17de1b |
# The eventual plan is to have a range_transition to s0 for the daemon by
|
|
Chris PeBenito |
17de1b |
# default and have the daemons which need to run with all categories be
|
|
Chris PeBenito |
17de1b |
# exceptions. But while range_transitions have to be in the base module
|
|
Chris PeBenito |
17de1b |
# this is not possible.
|
|
Chris PeBenito |
17de1b |
range_transition getty_t login_exec_t s0 - s0:c0.c255;
|
|
Chris PeBenito |
17de1b |
range_transition init_t xdm_exec_t s0 - s0:c0.c255;
|
|
Chris PeBenito |
17de1b |
range_transition initrc_t crond_exec_t s0 - s0:c0.c255;
|
|
Chris PeBenito |
17de1b |
range_transition initrc_t cupsd_exec_t s0 - s0:c0.c255;
|
|
Chris PeBenito |
17de1b |
range_transition initrc_t sshd_exec_t s0 - s0:c0.c255;
|
|
Chris PeBenito |
17de1b |
range_transition initrc_t udev_exec_t s0 - s0:c0.c255;
|
|
Chris PeBenito |
8708d9 |
range_transition initrc_t setrans_exec_t s0 - s0:c0.c255;
|
|
Chris PeBenito |
17de1b |
range_transition initrc_t xdm_exec_t s0 - s0:c0.c255;
|
|
Chris PeBenito |
17de1b |
range_transition kernel_t udev_exec_t s0 - s0:c0.c255;
|
|
Chris PeBenito |
17de1b |
|
|
Chris PeBenito |
17de1b |
# these might be targeted_policy only
|
|
Chris PeBenito |
17de1b |
range_transition unconfined_t initrc_exec_t s0;
|
|
Chris PeBenito |
17de1b |
')
|