|
Chris PeBenito |
77f6e2 |
#DESC pegasus - The Open Group Pegasus CIM/WBEM Server
|
|
Chris PeBenito |
77f6e2 |
#
|
|
Chris PeBenito |
77f6e2 |
# Author: Jason Vas Dias <jvdias@redhat.com>
|
|
Chris PeBenito |
77f6e2 |
# Package: tog-pegasus
|
|
Chris PeBenito |
77f6e2 |
#
|
|
Chris PeBenito |
77f6e2 |
#################################
|
|
Chris PeBenito |
77f6e2 |
#
|
|
Chris PeBenito |
77f6e2 |
# Rules for the pegasus domain
|
|
Chris PeBenito |
77f6e2 |
#
|
|
Chris PeBenito |
77f6e2 |
daemon_domain(pegasus, `, nscd_client_domain, auth')
|
|
Chris PeBenito |
77f6e2 |
type pegasus_data_t, file_type, sysadmfile;
|
|
Chris PeBenito |
77f6e2 |
type pegasus_conf_t, file_type, sysadmfile;
|
|
Chris PeBenito |
77f6e2 |
type pegasus_mof_t, file_type, sysadmfile;
|
|
Chris PeBenito |
77f6e2 |
type pegasus_conf_exec_t, file_type, exec_type, sysadmfile;
|
|
Chris PeBenito |
77f6e2 |
allow pegasus_t self:capability { dac_override net_bind_service audit_write };
|
|
Chris PeBenito |
77f6e2 |
can_network_tcp(pegasus_t);
|
|
Chris PeBenito |
77f6e2 |
nsswitch_domain(pegasus_t);
|
|
Chris PeBenito |
77f6e2 |
allow pegasus_t pegasus_var_run_t:sock_file { create setattr };
|
|
Chris PeBenito |
77f6e2 |
allow pegasus_t self:unix_dgram_socket create_socket_perms;
|
|
Chris PeBenito |
77f6e2 |
allow pegasus_t self:unix_stream_socket create_stream_socket_perms;
|
|
Chris PeBenito |
77f6e2 |
allow pegasus_t self:file { read getattr };
|
|
Chris PeBenito |
77f6e2 |
allow pegasus_t self:fifo_file rw_file_perms;
|
|
Chris PeBenito |
77f6e2 |
allow pegasus_t self:netlink_audit_socket { create_netlink_socket_perms nlmsg_relay };
|
|
Chris PeBenito |
77f6e2 |
allow pegasus_t { pegasus_http_port_t pegasus_https_port_t }:tcp_socket { name_bind name_connect };
|
|
Chris PeBenito |
77f6e2 |
allow pegasus_t proc_t:file { getattr read };
|
|
Chris PeBenito |
77f6e2 |
allow pegasus_t sysctl_vm_t:dir search;
|
|
Chris PeBenito |
77f6e2 |
allow pegasus_t initrc_var_run_t:file { read write lock };
|
|
Chris PeBenito |
77f6e2 |
allow pegasus_t urandom_device_t:chr_file { getattr read };
|
|
Chris PeBenito |
77f6e2 |
r_dir_file(pegasus_t, etc_t)
|
|
Chris PeBenito |
77f6e2 |
r_dir_file(pegasus_t, var_lib_t)
|
|
Chris PeBenito |
77f6e2 |
r_dir_file(pegasus_t, pegasus_mof_t)
|
|
Chris PeBenito |
77f6e2 |
rw_dir_create_file(pegasus_t, pegasus_conf_t)
|
|
Chris PeBenito |
77f6e2 |
rw_dir_create_file(pegasus_t, pegasus_data_t)
|
|
Chris PeBenito |
77f6e2 |
rw_dir_create_file(pegasus_conf_exec_t, pegasus_conf_t)
|
|
Chris PeBenito |
77f6e2 |
allow pegasus_t shadow_t:file { getattr read };
|
|
Chris PeBenito |
77f6e2 |
dontaudit pegasus_t selinux_config_t:dir search;
|
|
Chris PeBenito |
77f6e2 |
|