Chris PeBenito ff7bc1
## <module name="selinux" layer="kernel">
Chris PeBenito ff7bc1
## <summary>
Chris PeBenito ff7bc1
##	Policy for kernel security interface, in particular, selinuxfs.
Chris PeBenito ff7bc1
## </summary>
Chris PeBenito ff7bc1
Chris PeBenito ff7bc1
########################################
Chris PeBenito ff7bc1
## <interface name="selinux_get_fs_mount">
Chris PeBenito ff7bc1
##	<description>
Chris PeBenito ff7bc1
## 		Gets the caller the mountpoint of the selinuxfs filesystem.
Chris PeBenito ff7bc1
##	</description>
Chris PeBenito ff7bc1
##	<parameter name="domain">
Chris PeBenito ff7bc1
##		The process type requesting the selinuxfs mountpoint.
Chris PeBenito ff7bc1
##	</parameter>
Chris PeBenito ff7bc1
## </interface>
Chris PeBenito ff7bc1
#
Chris PeBenito ff7bc1
define(`selinux_get_fs_mount',`
Chris PeBenito ff7bc1
	# read /proc/filesystems to see if selinuxfs is supported
Chris PeBenito ff7bc1
	# then read /proc/self/mount to see where selinuxfs is mounted
Chris PeBenito ff7bc1
	kernel_read_system_state($1)
Chris PeBenito ff7bc1
')
Chris PeBenito ff7bc1
Chris PeBenito ff7bc1
########################################
Chris PeBenito ff7bc1
## <interface name="selinux_get_enforce_mode">
Chris PeBenito ff7bc1
##	<description>
Chris PeBenito ff7bc1
## 		Allows the caller to get the mode of policy enforcement
Chris PeBenito ff7bc1
## 		(enforcing or permissive mode).
Chris PeBenito ff7bc1
##	</description>
Chris PeBenito ff7bc1
##	<parameter name="domain">
Chris PeBenito ff7bc1
##		The process type to allow to get the enforcing mode.
Chris PeBenito ff7bc1
##	</parameter>
Chris PeBenito ff7bc1
## </interface>
Chris PeBenito ff7bc1
#
Chris PeBenito ff7bc1
define(`selinux_get_enforce_mode',`
Chris PeBenito ff7bc1
	gen_require(`$0'_depend)
Chris PeBenito ff7bc1
Chris PeBenito ff7bc1
	allow $1 security_t:dir { read search getattr };
Chris PeBenito ff7bc1
	allow $1 security_t:file { getattr read };
Chris PeBenito ff7bc1
')
Chris PeBenito ff7bc1
Chris PeBenito ff7bc1
define(`selinux_get_enforce_mode_depend',`
Chris PeBenito ff7bc1
	type security_t;
Chris PeBenito ff7bc1
Chris PeBenito ff7bc1
	class dir { read search getattr };
Chris PeBenito ff7bc1
	class file { getattr read };
Chris PeBenito ff7bc1
')
Chris PeBenito ff7bc1
Chris PeBenito ff7bc1
########################################
Chris PeBenito ff7bc1
## <interface name="selinux_set_enforce_mode">
Chris PeBenito ff7bc1
##	<description>
Chris PeBenito ff7bc1
## 		Allow caller to set the mode of policy enforcement
Chris PeBenito ff7bc1
## 		(enforcing or permissive mode).
Chris PeBenito ff7bc1
##	</description>
Chris PeBenito ff7bc1
##	<parameter name="domain">
Chris PeBenito ff7bc1
##		The process type to allow to set the enforcement mode.
Chris PeBenito ff7bc1
##	</parameter>
Chris PeBenito ff7bc1
## </interface>
Chris PeBenito ff7bc1
#
Chris PeBenito ff7bc1
define(`selinux_set_enforce_mode',`
Chris PeBenito ff7bc1
	gen_require(`$0'_depend)
Chris PeBenito ff7bc1
Chris PeBenito ff7bc1
	allow $1 security_t:dir { read search getattr };
Chris PeBenito ff7bc1
	allow $1 security_t:file { getattr read write };
Chris PeBenito ff7bc1
	allow $1 security_t:security setenforce;
Chris PeBenito ff7bc1
	auditallow $1 security_t:security setenforce;
Chris PeBenito ff7bc1
	typeattribute $1 can_setenforce;
Chris PeBenito ff7bc1
')
Chris PeBenito ff7bc1
Chris PeBenito ff7bc1
define(`selinux_set_enforce_mode_depend',`
Chris PeBenito ff7bc1
	type security_t;
Chris PeBenito ff7bc1
Chris PeBenito ff7bc1
	attribute can_setenforce;
Chris PeBenito ff7bc1
Chris PeBenito ff7bc1
	class dir { read search getattr };
Chris PeBenito ff7bc1
	class file { getattr read write };
Chris PeBenito ff7bc1
	class security setenforce;
Chris PeBenito ff7bc1
')
Chris PeBenito ff7bc1
Chris PeBenito ff7bc1
########################################
Chris PeBenito ff7bc1
## <interface name="selinux_load_policy">
Chris PeBenito ff7bc1
##	<description>
Chris PeBenito ff7bc1
## 		Allow caller to load the policy into the kernel.
Chris PeBenito ff7bc1
##	</description>
Chris PeBenito ff7bc1
##	<parameter name="domain">
Chris PeBenito ff7bc1
##		The process type that will load the policy.
Chris PeBenito ff7bc1
##	</parameter>
Chris PeBenito ff7bc1
## </interface>
Chris PeBenito ff7bc1
#
Chris PeBenito ff7bc1
define(`selinux_load_policy',`
Chris PeBenito ff7bc1
	gen_require(`$0'_depend)
Chris PeBenito ff7bc1
Chris PeBenito ff7bc1
	allow $1 security_t:dir { read search getattr };
Chris PeBenito ff7bc1
	allow $1 security_t:file { getattr read write };
Chris PeBenito ff7bc1
	allow $1 security_t:security load_policy;
Chris PeBenito ff7bc1
	auditallow $1 security_t:security load_policy;
Chris PeBenito ff7bc1
	typeattribute $1 can_load_policy;
Chris PeBenito ff7bc1
')
Chris PeBenito ff7bc1
Chris PeBenito ff7bc1
define(`selinux_load_policy_depend',`
Chris PeBenito ff7bc1
	type security_t;
Chris PeBenito ff7bc1
Chris PeBenito ff7bc1
	attribute can_load_policy;
Chris PeBenito ff7bc1
Chris PeBenito ff7bc1
	class dir { read search getattr };
Chris PeBenito ff7bc1
	class file { getattr read write };
Chris PeBenito ff7bc1
	class security load_policy;
Chris PeBenito ff7bc1
')
Chris PeBenito ff7bc1
Chris PeBenito ff7bc1
########################################
Chris PeBenito ff7bc1
## <interface name="selinux_set_boolean">
Chris PeBenito ff7bc1
##	<description>
Chris PeBenito ff7bc1
## 		Allow caller to set the state of Booleans to
Chris PeBenito ff7bc1
## 		enable or disable conditional portions of the policy.
Chris PeBenito ff7bc1
##	</description>
Chris PeBenito ff7bc1
##	<parameter name="domain">
Chris PeBenito ff7bc1
##		The process type allowed to set the Boolean.
Chris PeBenito ff7bc1
##	</parameter>
Chris PeBenito ff7bc1
##	<parameter name="booltype" optional="true">
Chris PeBenito ff7bc1
##		The type of Booleans the caller is allowed to set.
Chris PeBenito ff7bc1
##	</parameter>
Chris PeBenito ff7bc1
## </interface>
Chris PeBenito ff7bc1
#
Chris PeBenito ff7bc1
define(`selinux_set_boolean',`
Chris PeBenito ff7bc1
	gen_require(`$0'_depend)
Chris PeBenito ff7bc1
Chris PeBenito ff7bc1
	ifelse(`$2',`',`
Chris PeBenito ff7bc1
		allow $1 security_t:dir { getattr search read };
Chris PeBenito ff7bc1
		allow $1 security_t:file { getattr read write };
Chris PeBenito ff7bc1
	',`
Chris PeBenito ff7bc1
		allow $1 $2:dir { getattr search read };
Chris PeBenito ff7bc1
		allow $1 $2:file { getattr read write };
Chris PeBenito ff7bc1
	')
Chris PeBenito ff7bc1
Chris PeBenito ff7bc1
	allow $1 security_t:dir search;
Chris PeBenito ff7bc1
	allow $1 security_t:security setbool;
Chris PeBenito ff7bc1
	auditallow $1 security_t:security setbool;
Chris PeBenito ff7bc1
')
Chris PeBenito ff7bc1
Chris PeBenito ff7bc1
define(`selinux_set_boolean_depend',`
Chris PeBenito ff7bc1
	type security_t;
Chris PeBenito ff7bc1
Chris PeBenito ff7bc1
	class dir { read search getattr };
Chris PeBenito ff7bc1
	class file { getattr read write };
Chris PeBenito ff7bc1
	class security setbool;
Chris PeBenito ff7bc1
')
Chris PeBenito ff7bc1
Chris PeBenito ff7bc1
########################################
Chris PeBenito ff7bc1
## <interface name="selinux_set_parameters">
Chris PeBenito ff7bc1
##	<description>
Chris PeBenito ff7bc1
## 		Allow caller to set selinux security parameters.
Chris PeBenito ff7bc1
##	</description>
Chris PeBenito ff7bc1
##	<parameter name="domain">
Chris PeBenito ff7bc1
##		The process type to allow to set security parameters.
Chris PeBenito ff7bc1
##	</parameter>
Chris PeBenito ff7bc1
## </interface>
Chris PeBenito ff7bc1
#
Chris PeBenito ff7bc1
define(`selinux_set_parameters',`
Chris PeBenito ff7bc1
	gen_require(`$0'_depend)
Chris PeBenito ff7bc1
Chris PeBenito ff7bc1
	allow $1 security_t:dir { read search getattr };
Chris PeBenito ff7bc1
	allow $1 security_t:file { getattr read write };
Chris PeBenito ff7bc1
	allow $1 security_t:security setsecparam;
Chris PeBenito ff7bc1
	auditallow $1 security_t:security setsecparam;
Chris PeBenito ff7bc1
	typeattribute $1 can_setsecparam;
Chris PeBenito ff7bc1
')
Chris PeBenito ff7bc1
Chris PeBenito ff7bc1
define(`selinux_set_parameters_depend',`
Chris PeBenito ff7bc1
	type security_t;
Chris PeBenito ff7bc1
Chris PeBenito ff7bc1
	attribute can_setsecparam;
Chris PeBenito ff7bc1
Chris PeBenito ff7bc1
	class dir { read search getattr };
Chris PeBenito ff7bc1
	class file { getattr read write };
Chris PeBenito ff7bc1
	class security setsecparam;
Chris PeBenito ff7bc1
')
Chris PeBenito ff7bc1
Chris PeBenito ff7bc1
########################################
Chris PeBenito ff7bc1
## <interface name="selinux_validate_context">
Chris PeBenito ff7bc1
##	<description>
Chris PeBenito ff7bc1
## 		Allows caller to validate security contexts.
Chris PeBenito ff7bc1
##	</description>
Chris PeBenito ff7bc1
##	<parameter name="domain">
Chris PeBenito ff7bc1
##		The process type permitted to validate contexts.
Chris PeBenito ff7bc1
##	</parameter>
Chris PeBenito ff7bc1
## </interface>
Chris PeBenito ff7bc1
#
Chris PeBenito ff7bc1
define(`selinux_validate_context',`
Chris PeBenito ff7bc1
	gen_require(`$0'_depend)
Chris PeBenito ff7bc1
Chris PeBenito ff7bc1
	allow $1 security_t:dir { read search getattr };
Chris PeBenito ff7bc1
	allow $1 security_t:file { getattr read write };
Chris PeBenito ff7bc1
	allow $1 security_t:security check_context;
Chris PeBenito ff7bc1
')
Chris PeBenito ff7bc1
Chris PeBenito ff7bc1
define(`selinux_validate_context_depend',`
Chris PeBenito ff7bc1
	type security_t;
Chris PeBenito ff7bc1
Chris PeBenito ff7bc1
	class dir { read search getattr };
Chris PeBenito ff7bc1
	class file { getattr read write };
Chris PeBenito ff7bc1
	class security check_context;
Chris PeBenito ff7bc1
')
Chris PeBenito ff7bc1
Chris PeBenito ff7bc1
########################################
Chris PeBenito ff7bc1
## <interface name="selinux_compute_access_vector">
Chris PeBenito ff7bc1
##	<description>
Chris PeBenito ff7bc1
## 		Allows caller to compute an access vector.
Chris PeBenito ff7bc1
##	</description>
Chris PeBenito ff7bc1
##	<parameter name="domain">
Chris PeBenito ff7bc1
##		The process type allowed to compute an access vector.
Chris PeBenito ff7bc1
##	</parameter>
Chris PeBenito ff7bc1
## </interface>
Chris PeBenito ff7bc1
#
Chris PeBenito ff7bc1
define(`selinux_compute_access_vector',`
Chris PeBenito ff7bc1
	gen_require(`$0'_depend)
Chris PeBenito ff7bc1
Chris PeBenito ff7bc1
	allow $1 security_t:dir { read search getattr };
Chris PeBenito ff7bc1
	allow $1 security_t:file { getattr read write };
Chris PeBenito ff7bc1
	allow $1 security_t:security compute_av;
Chris PeBenito ff7bc1
')
Chris PeBenito ff7bc1
Chris PeBenito ff7bc1
define(`selinux_compute_access_vector_depend',`
Chris PeBenito ff7bc1
	type security_t;
Chris PeBenito ff7bc1
Chris PeBenito ff7bc1
	class dir { read search getattr };
Chris PeBenito ff7bc1
	class file { getattr read write };
Chris PeBenito ff7bc1
	class security compute_av;
Chris PeBenito ff7bc1
')
Chris PeBenito ff7bc1
Chris PeBenito ff7bc1
########################################
Chris PeBenito ff7bc1
## <interface name="selinux_compute_create_context">
Chris PeBenito ff7bc1
##	<description>
Chris PeBenito ff7bc1
## 		
Chris PeBenito ff7bc1
##	</description>
Chris PeBenito ff7bc1
##	<parameter name="domain">
Chris PeBenito ff7bc1
##		
Chris PeBenito ff7bc1
##	</parameter>
Chris PeBenito ff7bc1
## </interface>
Chris PeBenito ff7bc1
#
Chris PeBenito ff7bc1
define(`selinux_compute_create_context',`
Chris PeBenito ff7bc1
	gen_require(`$0'_depend)
Chris PeBenito ff7bc1
Chris PeBenito ff7bc1
	allow $1 security_t:dir { read search getattr };
Chris PeBenito ff7bc1
	allow $1 security_t:file { getattr read write };
Chris PeBenito ff7bc1
	allow $1 security_t:security compute_create;
Chris PeBenito ff7bc1
')
Chris PeBenito ff7bc1
Chris PeBenito ff7bc1
define(`selinux_compute_create_context_depend',`
Chris PeBenito ff7bc1
	type security_t;
Chris PeBenito ff7bc1
Chris PeBenito ff7bc1
	class dir { read search getattr };
Chris PeBenito ff7bc1
	class file { getattr read write };
Chris PeBenito ff7bc1
	class security compute_create;
Chris PeBenito ff7bc1
')
Chris PeBenito ff7bc1
Chris PeBenito ff7bc1
########################################
Chris PeBenito ff7bc1
## <interface name="selinux_compute_relabel_context">
Chris PeBenito ff7bc1
##	<description>
Chris PeBenito ff7bc1
## 		
Chris PeBenito ff7bc1
##	</description>
Chris PeBenito ff7bc1
##	<parameter name="domain">
Chris PeBenito ff7bc1
##		The process type to 
Chris PeBenito ff7bc1
##	</parameter>
Chris PeBenito ff7bc1
## </interface>
Chris PeBenito ff7bc1
#
Chris PeBenito ff7bc1
define(`selinux_compute_relabel_context',`
Chris PeBenito ff7bc1
	gen_require(`$0'_depend)
Chris PeBenito ff7bc1
Chris PeBenito ff7bc1
	allow $1 security_t:dir { read search getattr };
Chris PeBenito ff7bc1
	allow $1 security_t:file { getattr read write };
Chris PeBenito ff7bc1
	allow $1 security_t:security compute_relabel;
Chris PeBenito ff7bc1
')
Chris PeBenito ff7bc1
Chris PeBenito ff7bc1
define(`selinux_compute_relabel_context_depend',`
Chris PeBenito ff7bc1
	type security_t;
Chris PeBenito ff7bc1
Chris PeBenito ff7bc1
	class dir { read search getattr };
Chris PeBenito ff7bc1
	class file { getattr read write };
Chris PeBenito ff7bc1
	class security compute_relabel;
Chris PeBenito ff7bc1
')
Chris PeBenito ff7bc1
Chris PeBenito ff7bc1
########################################
Chris PeBenito ff7bc1
## <interface name="selinux_compute_user_contexts">
Chris PeBenito ff7bc1
##	<description>
Chris PeBenito ff7bc1
## 		Allows caller to compute possible contexts for a user.
Chris PeBenito ff7bc1
##	</description>
Chris PeBenito ff7bc1
##	<parameter name="domain">
Chris PeBenito ff7bc1
##		The process type allowed to compute user contexts.
Chris PeBenito ff7bc1
##	</parameter>
Chris PeBenito ff7bc1
## </interface>
Chris PeBenito ff7bc1
#
Chris PeBenito ff7bc1
define(`selinux_compute_user_contexts',`
Chris PeBenito ff7bc1
	gen_require(`$0'_depend)
Chris PeBenito ff7bc1
Chris PeBenito ff7bc1
	allow $1 security_t:dir { read search getattr };
Chris PeBenito ff7bc1
	allow $1 security_t:file { getattr read write };
Chris PeBenito ff7bc1
	allow $1 security_t:security compute_user;
Chris PeBenito ff7bc1
')
Chris PeBenito ff7bc1
Chris PeBenito ff7bc1
define(`selinux_compute_user_contexts_depend',`
Chris PeBenito ff7bc1
	type security_t;
Chris PeBenito ff7bc1
Chris PeBenito ff7bc1
	class dir { read search getattr };
Chris PeBenito ff7bc1
	class file { getattr read write };
Chris PeBenito ff7bc1
	class security compute_user;
Chris PeBenito ff7bc1
')
Chris PeBenito ff7bc1
Chris PeBenito ff7bc1
## </module>