Chris PeBenito f0574f
Chris PeBenito 955019
policy_module(mls,1.2.1)
Chris PeBenito f0574f
Chris PeBenito f0574f
########################################
Chris PeBenito f0574f
#
Chris PeBenito f0574f
# Declarations
Chris PeBenito f0574f
#
Chris PeBenito f0574f
Chris PeBenito f0574f
attribute mlsfileread;
Chris PeBenito f0574f
attribute mlsfilereadtoclr;
Chris PeBenito f0574f
attribute mlsfilewrite;
Chris PeBenito f0574f
attribute mlsfilewritetoclr;
Chris PeBenito f0574f
attribute mlsfileupgrade;
Chris PeBenito f0574f
attribute mlsfiledowngrade;
Chris PeBenito f0574f
Chris PeBenito f0574f
attribute mlsnetread;
Chris PeBenito f0574f
attribute mlsnetreadtoclr;
Chris PeBenito f0574f
attribute mlsnetwrite;
Chris PeBenito f0574f
attribute mlsnetwritetoclr;
Chris PeBenito f0574f
attribute mlsnetupgrade;
Chris PeBenito f0574f
attribute mlsnetdowngrade;
Chris PeBenito f0574f
attribute mlsnetrecvall;
Chris PeBenito f0574f
Chris PeBenito f0574f
attribute mlsipcread;
Chris PeBenito f0574f
attribute mlsipcreadtoclr;
Chris PeBenito f0574f
attribute mlsipcwrite;
Chris PeBenito f0574f
attribute mlsipcwritetoclr;
Chris PeBenito f0574f
Chris PeBenito f0574f
attribute mlsprocread;
Chris PeBenito f0574f
attribute mlsprocreadtoclr;
Chris PeBenito f0574f
attribute mlsprocwrite;
Chris PeBenito f0574f
attribute mlsprocwritetoclr;
Chris PeBenito f0574f
attribute mlsprocsetsl;
Chris PeBenito f0574f
Chris PeBenito f0574f
attribute mlsxwinread;
Chris PeBenito f0574f
attribute mlsxwinreadtoclr;
Chris PeBenito f0574f
attribute mlsxwinwrite;
Chris PeBenito f0574f
attribute mlsxwinwritetoclr;
Chris PeBenito bf080a
attribute mlsxwinreadproperty;
Chris PeBenito bf080a
attribute mlsxwinwriteproperty;
Chris PeBenito bf080a
attribute mlsxwinreadcolormap;
Chris PeBenito bf080a
attribute mlsxwinwritecolormap;
Chris PeBenito bf080a
attribute mlsxwinwritexinput;
Chris PeBenito f0574f
Chris PeBenito f0574f
attribute mlstrustedobject;
Chris PeBenito f0574f
Chris PeBenito f0574f
attribute privrangetrans;
Chris PeBenito f0574f
attribute mlsrangetrans;
Chris PeBenito 77f6e2
Chris PeBenito 77f6e2
########################################
Chris PeBenito 77f6e2
#
Chris PeBenito 77f6e2
# THIS IS A HACK
Chris PeBenito 77f6e2
#
Chris PeBenito 77f6e2
# Only the base module can have range_transitions, so we
Chris PeBenito 77f6e2
# temporarily have to break encapsulation to work around this.
Chris PeBenito 77f6e2
#
Chris PeBenito 77f6e2
Chris PeBenito b389cd
type auditd_exec_t;
Chris PeBenito b389cd
type crond_exec_t;
Chris PeBenito b389cd
type cupsd_exec_t;
Chris PeBenito b389cd
type getty_t;
Chris PeBenito b389cd
type init_t;
Chris PeBenito b389cd
type init_exec_t;
Chris PeBenito b389cd
type initrc_t;
Chris PeBenito b389cd
type initrc_exec_t;
Chris PeBenito b389cd
type login_exec_t;
Chris PeBenito 955019
type lvm_exec_t;
Chris PeBenito b389cd
type sshd_exec_t;
Chris PeBenito b389cd
type su_exec_t;
Chris PeBenito b389cd
type udev_exec_t;
Chris PeBenito b389cd
type unconfined_t;
Chris PeBenito b389cd
type xdm_exec_t;
Chris PeBenito b389cd
Chris PeBenito b389cd
ifdef(`enable_mcs',`
Chris PeBenito b389cd
range_transition getty_t login_exec_t s0 - s0:c0.c255;
Chris PeBenito b389cd
range_transition init_t xdm_exec_t s0 - s0:c0.c255;
Chris PeBenito b389cd
range_transition initrc_t crond_exec_t s0 - s0:c0.c255;
Chris PeBenito b389cd
range_transition initrc_t cupsd_exec_t s0 - s0:c0.c255;
Chris PeBenito b389cd
range_transition initrc_t sshd_exec_t s0 - s0:c0.c255;
Chris PeBenito b389cd
range_transition initrc_t udev_exec_t s0 - s0:c0.c255;
Chris PeBenito b389cd
range_transition initrc_t xdm_exec_t s0 - s0:c0.c255;
Chris PeBenito b389cd
range_transition kernel_t udev_exec_t s0 - s0:c0.c255;
Chris PeBenito b389cd
Chris PeBenito b389cd
# these might be targeted_policy only
Chris PeBenito b389cd
range_transition unconfined_t su_exec_t s0 - s0:c0.c255;
Chris PeBenito b389cd
range_transition unconfined_t initrc_exec_t s0;
Chris PeBenito b389cd
')
Chris PeBenito 77f6e2
Chris PeBenito 23a444
ifdef(`enable_mls',`
Chris PeBenito 93727e
range_transition initrc_t auditd_exec_t s15:c0.c255;
Chris PeBenito 955019
range_transition kernel_t init_exec_t s0 - s15:c0.c255;
Chris PeBenito 955019
range_transition kernel_t lvm_exec_t s0 - s15:c0.c255;
Chris PeBenito 77f6e2
')