Chris PeBenito a08248
ifdef(`enable_mcs',`
Chris PeBenito a08248
#
Chris PeBenito a08248
# Define sensitivities 
Chris PeBenito a08248
#
Chris PeBenito a08248
# Each sensitivity has a name and zero or more aliases.
Chris PeBenito a08248
#
Chris PeBenito a08248
# MCS is single-sensitivity.
Chris PeBenito a08248
#
Chris PeBenito a08248
sensitivity s0;
Chris PeBenito a08248
Chris PeBenito a08248
#
Chris PeBenito a08248
# Define the ordering of the sensitivity levels (least to greatest)
Chris PeBenito a08248
#
Chris PeBenito a08248
dominance { s0 }
Chris PeBenito a08248
Chris PeBenito a08248
Chris PeBenito a08248
#
Chris PeBenito a08248
# Define the categories
Chris PeBenito a08248
#
Chris PeBenito a08248
# Each category has a name and zero or more aliases.
Chris PeBenito a08248
#
Chris PeBenito a08248
category c0;
Chris PeBenito a08248
category c1;
Chris PeBenito a08248
category c2;
Chris PeBenito a08248
category c3;
Chris PeBenito a08248
category c4;
Chris PeBenito a08248
category c5;
Chris PeBenito a08248
category c6;
Chris PeBenito a08248
category c7;
Chris PeBenito a08248
category c8;
Chris PeBenito a08248
category c9;
Chris PeBenito a08248
category c10;
Chris PeBenito a08248
category c11;
Chris PeBenito a08248
category c12;
Chris PeBenito a08248
category c13;
Chris PeBenito a08248
category c14;
Chris PeBenito a08248
category c15;
Chris PeBenito a08248
category c16;
Chris PeBenito a08248
category c17;
Chris PeBenito a08248
category c18;
Chris PeBenito a08248
category c19;
Chris PeBenito a08248
category c20;
Chris PeBenito a08248
category c21;
Chris PeBenito a08248
category c22;
Chris PeBenito a08248
category c23;
Chris PeBenito a08248
category c24;
Chris PeBenito a08248
category c25;
Chris PeBenito a08248
category c26;
Chris PeBenito a08248
category c27;
Chris PeBenito a08248
category c28;
Chris PeBenito a08248
category c29;
Chris PeBenito a08248
category c30;
Chris PeBenito a08248
category c31;
Chris PeBenito a08248
category c32;
Chris PeBenito a08248
category c33;
Chris PeBenito a08248
category c34;
Chris PeBenito a08248
category c35;
Chris PeBenito a08248
category c36;
Chris PeBenito a08248
category c37;
Chris PeBenito a08248
category c38;
Chris PeBenito a08248
category c39;
Chris PeBenito a08248
category c40;
Chris PeBenito a08248
category c41;
Chris PeBenito a08248
category c42;
Chris PeBenito a08248
category c43;
Chris PeBenito a08248
category c44;
Chris PeBenito a08248
category c45;
Chris PeBenito a08248
category c46;
Chris PeBenito a08248
category c47;
Chris PeBenito a08248
category c48;
Chris PeBenito a08248
category c49;
Chris PeBenito a08248
category c50;
Chris PeBenito a08248
category c51;
Chris PeBenito a08248
category c52;
Chris PeBenito a08248
category c53;
Chris PeBenito a08248
category c54;
Chris PeBenito a08248
category c55;
Chris PeBenito a08248
category c56;
Chris PeBenito a08248
category c57;
Chris PeBenito a08248
category c58;
Chris PeBenito a08248
category c59;
Chris PeBenito a08248
category c60;
Chris PeBenito a08248
category c61;
Chris PeBenito a08248
category c62;
Chris PeBenito a08248
category c63;
Chris PeBenito a08248
category c64;
Chris PeBenito a08248
category c65;
Chris PeBenito a08248
category c66;
Chris PeBenito a08248
category c67;
Chris PeBenito a08248
category c68;
Chris PeBenito a08248
category c69;
Chris PeBenito a08248
category c70;
Chris PeBenito a08248
category c71;
Chris PeBenito a08248
category c72;
Chris PeBenito a08248
category c73;
Chris PeBenito a08248
category c74;
Chris PeBenito a08248
category c75;
Chris PeBenito a08248
category c76;
Chris PeBenito a08248
category c77;
Chris PeBenito a08248
category c78;
Chris PeBenito a08248
category c79;
Chris PeBenito a08248
category c80;
Chris PeBenito a08248
category c81;
Chris PeBenito a08248
category c82;
Chris PeBenito a08248
category c83;
Chris PeBenito a08248
category c84;
Chris PeBenito a08248
category c85;
Chris PeBenito a08248
category c86;
Chris PeBenito a08248
category c87;
Chris PeBenito a08248
category c88;
Chris PeBenito a08248
category c89;
Chris PeBenito a08248
category c90;
Chris PeBenito a08248
category c91;
Chris PeBenito a08248
category c92;
Chris PeBenito a08248
category c93;
Chris PeBenito a08248
category c94;
Chris PeBenito a08248
category c95;
Chris PeBenito a08248
category c96;
Chris PeBenito a08248
category c97;
Chris PeBenito a08248
category c98;
Chris PeBenito a08248
category c99;
Chris PeBenito a08248
category c100;
Chris PeBenito a08248
category c101;
Chris PeBenito a08248
category c102;
Chris PeBenito a08248
category c103;
Chris PeBenito a08248
category c104;
Chris PeBenito a08248
category c105;
Chris PeBenito a08248
category c106;
Chris PeBenito a08248
category c107;
Chris PeBenito a08248
category c108;
Chris PeBenito a08248
category c109;
Chris PeBenito a08248
category c110;
Chris PeBenito a08248
category c111;
Chris PeBenito a08248
category c112;
Chris PeBenito a08248
category c113;
Chris PeBenito a08248
category c114;
Chris PeBenito a08248
category c115;
Chris PeBenito a08248
category c116;
Chris PeBenito a08248
category c117;
Chris PeBenito a08248
category c118;
Chris PeBenito a08248
category c119;
Chris PeBenito a08248
category c120;
Chris PeBenito a08248
category c121;
Chris PeBenito a08248
category c122;
Chris PeBenito a08248
category c123;
Chris PeBenito a08248
category c124;
Chris PeBenito a08248
category c125;
Chris PeBenito a08248
category c126;
Chris PeBenito a08248
category c127;
Chris PeBenito a08248
Chris PeBenito a08248
Chris PeBenito a08248
#
Chris PeBenito a08248
# Each MCS level specifies a sensitivity and zero or more categories which may
Chris PeBenito a08248
# be associated with that sensitivity.
Chris PeBenito a08248
#
Chris PeBenito a08248
level s0:c0.c127;
Chris PeBenito a08248
Chris PeBenito a08248
#
Chris PeBenito a08248
# Define the MCS policy
Chris PeBenito a08248
#
Chris PeBenito a08248
# mlsconstrain class_set perm_set expression ;
Chris PeBenito a08248
#
Chris PeBenito a08248
# mlsvalidatetrans class_set expression ;
Chris PeBenito a08248
#
Chris PeBenito a08248
# expression : ( expression )
Chris PeBenito a08248
#	     | not expression
Chris PeBenito a08248
#	     | expression and expression
Chris PeBenito a08248
#	     | expression or expression
Chris PeBenito a08248
#	     | u1 op u2
Chris PeBenito a08248
#	     | r1 role_mls_op r2
Chris PeBenito a08248
#	     | t1 op t2
Chris PeBenito a08248
#	     | l1 role_mls_op l2
Chris PeBenito a08248
#	     | l1 role_mls_op h2
Chris PeBenito a08248
#	     | h1 role_mls_op l2
Chris PeBenito a08248
#	     | h1 role_mls_op h2
Chris PeBenito a08248
#	     | l1 role_mls_op h1
Chris PeBenito a08248
#	     | l2 role_mls_op h2
Chris PeBenito a08248
#	     | u1 op names
Chris PeBenito a08248
#	     | u2 op names
Chris PeBenito a08248
#	     | r1 op names
Chris PeBenito a08248
#	     | r2 op names
Chris PeBenito a08248
#	     | t1 op names
Chris PeBenito a08248
#	     | t2 op names
Chris PeBenito a08248
#	     | u3 op names (NOTE: this is only available for mlsvalidatetrans)
Chris PeBenito a08248
#	     | r3 op names (NOTE: this is only available for mlsvalidatetrans)
Chris PeBenito a08248
#	     | t3 op names (NOTE: this is only available for mlsvalidatetrans)
Chris PeBenito a08248
#
Chris PeBenito a08248
# op : == | !=
Chris PeBenito a08248
# role_mls_op : == | != | eq | dom | domby | incomp
Chris PeBenito a08248
#
Chris PeBenito a08248
# names : name | { name_list }
Chris PeBenito a08248
# name_list : name | name_list name
Chris PeBenito a08248
#
Chris PeBenito a08248
Chris PeBenito a08248
#
Chris PeBenito a08248
# MCS policy for the file classes
Chris PeBenito a08248
#
Chris PeBenito a08248
# Constrain file access so that the high range of the process dominates
Chris PeBenito a08248
# the high range of the file.  We use the high range of the process so
Chris PeBenito a08248
# that processes can always simply run at s0.
Chris PeBenito a08248
#
Chris PeBenito a08248
# Only files are constrained by MCS at this stage.
Chris PeBenito a08248
#
Chris PeBenito a08248
mlsconstrain file { read write setattr append unlink link rename
Chris PeBenito a08248
		    create ioctl lock execute } (h1 dom h2);
Chris PeBenito a08248
Chris PeBenito a08248
Chris PeBenito a08248
# XXX
Chris PeBenito a08248
#
Chris PeBenito a08248
# For some reason, we need to reference the mlsfileread attribute
Chris PeBenito a08248
# or we get a build error.  Below is a dummy entry to do this.
Chris PeBenito a08248
mlsconstrain xextension query ( t1 == mlsfileread );
Chris PeBenito a08248
Chris PeBenito a08248
') dnl end enable_mcs