Chris PeBenito cff75c
#
Chris PeBenito cff75c
# Define sensitivities 
Chris PeBenito cff75c
#
Chris PeBenito cff75c
# Each sensitivity has a name and zero or more aliases.
Chris PeBenito cff75c
#
Chris PeBenito cff75c
# MCS is single-sensitivity.
Chris PeBenito cff75c
#
Chris PeBenito cff75c
sensitivity s0;
Chris PeBenito cff75c
Chris PeBenito cff75c
#
Chris PeBenito cff75c
# Define the ordering of the sensitivity levels (least to greatest)
Chris PeBenito cff75c
#
Chris PeBenito cff75c
dominance { s0 }
Chris PeBenito cff75c
Chris PeBenito cff75c
Chris PeBenito cff75c
#
Chris PeBenito cff75c
# Define the categories
Chris PeBenito cff75c
#
Chris PeBenito cff75c
# Each category has a name and zero or more aliases.
Chris PeBenito cff75c
#
Chris PeBenito cff75c
category c0;
Chris PeBenito cff75c
category c1;
Chris PeBenito cff75c
category c2;
Chris PeBenito cff75c
category c3;
Chris PeBenito cff75c
category c4;
Chris PeBenito cff75c
category c5;
Chris PeBenito cff75c
category c6;
Chris PeBenito cff75c
category c7;
Chris PeBenito cff75c
category c8;
Chris PeBenito cff75c
category c9;
Chris PeBenito cff75c
category c10;
Chris PeBenito cff75c
category c11;
Chris PeBenito cff75c
category c12;
Chris PeBenito cff75c
category c13;
Chris PeBenito cff75c
category c14;
Chris PeBenito cff75c
category c15;
Chris PeBenito cff75c
category c16;
Chris PeBenito cff75c
category c17;
Chris PeBenito cff75c
category c18;
Chris PeBenito cff75c
category c19;
Chris PeBenito cff75c
category c20;
Chris PeBenito cff75c
category c21;
Chris PeBenito cff75c
category c22;
Chris PeBenito cff75c
category c23;
Chris PeBenito cff75c
category c24;
Chris PeBenito cff75c
category c25;
Chris PeBenito cff75c
category c26;
Chris PeBenito cff75c
category c27;
Chris PeBenito cff75c
category c28;
Chris PeBenito cff75c
category c29;
Chris PeBenito cff75c
category c30;
Chris PeBenito cff75c
category c31;
Chris PeBenito cff75c
category c32;
Chris PeBenito cff75c
category c33;
Chris PeBenito cff75c
category c34;
Chris PeBenito cff75c
category c35;
Chris PeBenito cff75c
category c36;
Chris PeBenito cff75c
category c37;
Chris PeBenito cff75c
category c38;
Chris PeBenito cff75c
category c39;
Chris PeBenito cff75c
category c40;
Chris PeBenito cff75c
category c41;
Chris PeBenito cff75c
category c42;
Chris PeBenito cff75c
category c43;
Chris PeBenito cff75c
category c44;
Chris PeBenito cff75c
category c45;
Chris PeBenito cff75c
category c46;
Chris PeBenito cff75c
category c47;
Chris PeBenito cff75c
category c48;
Chris PeBenito cff75c
category c49;
Chris PeBenito cff75c
category c50;
Chris PeBenito cff75c
category c51;
Chris PeBenito cff75c
category c52;
Chris PeBenito cff75c
category c53;
Chris PeBenito cff75c
category c54;
Chris PeBenito cff75c
category c55;
Chris PeBenito cff75c
category c56;
Chris PeBenito cff75c
category c57;
Chris PeBenito cff75c
category c58;
Chris PeBenito cff75c
category c59;
Chris PeBenito cff75c
category c60;
Chris PeBenito cff75c
category c61;
Chris PeBenito cff75c
category c62;
Chris PeBenito cff75c
category c63;
Chris PeBenito cff75c
category c64;
Chris PeBenito cff75c
category c65;
Chris PeBenito cff75c
category c66;
Chris PeBenito cff75c
category c67;
Chris PeBenito cff75c
category c68;
Chris PeBenito cff75c
category c69;
Chris PeBenito cff75c
category c70;
Chris PeBenito cff75c
category c71;
Chris PeBenito cff75c
category c72;
Chris PeBenito cff75c
category c73;
Chris PeBenito cff75c
category c74;
Chris PeBenito cff75c
category c75;
Chris PeBenito cff75c
category c76;
Chris PeBenito cff75c
category c77;
Chris PeBenito cff75c
category c78;
Chris PeBenito cff75c
category c79;
Chris PeBenito cff75c
category c80;
Chris PeBenito cff75c
category c81;
Chris PeBenito cff75c
category c82;
Chris PeBenito cff75c
category c83;
Chris PeBenito cff75c
category c84;
Chris PeBenito cff75c
category c85;
Chris PeBenito cff75c
category c86;
Chris PeBenito cff75c
category c87;
Chris PeBenito cff75c
category c88;
Chris PeBenito cff75c
category c89;
Chris PeBenito cff75c
category c90;
Chris PeBenito cff75c
category c91;
Chris PeBenito cff75c
category c92;
Chris PeBenito cff75c
category c93;
Chris PeBenito cff75c
category c94;
Chris PeBenito cff75c
category c95;
Chris PeBenito cff75c
category c96;
Chris PeBenito cff75c
category c97;
Chris PeBenito cff75c
category c98;
Chris PeBenito cff75c
category c99;
Chris PeBenito cff75c
category c100;
Chris PeBenito cff75c
category c101;
Chris PeBenito cff75c
category c102;
Chris PeBenito cff75c
category c103;
Chris PeBenito cff75c
category c104;
Chris PeBenito cff75c
category c105;
Chris PeBenito cff75c
category c106;
Chris PeBenito cff75c
category c107;
Chris PeBenito cff75c
category c108;
Chris PeBenito cff75c
category c109;
Chris PeBenito cff75c
category c110;
Chris PeBenito cff75c
category c111;
Chris PeBenito cff75c
category c112;
Chris PeBenito cff75c
category c113;
Chris PeBenito cff75c
category c114;
Chris PeBenito cff75c
category c115;
Chris PeBenito cff75c
category c116;
Chris PeBenito cff75c
category c117;
Chris PeBenito cff75c
category c118;
Chris PeBenito cff75c
category c119;
Chris PeBenito cff75c
category c120;
Chris PeBenito cff75c
category c121;
Chris PeBenito cff75c
category c122;
Chris PeBenito cff75c
category c123;
Chris PeBenito cff75c
category c124;
Chris PeBenito cff75c
category c125;
Chris PeBenito cff75c
category c126;
Chris PeBenito cff75c
category c127;
Chris PeBenito cff75c
Chris PeBenito cff75c
Chris PeBenito cff75c
#
Chris PeBenito cff75c
# Each MCS level specifies a sensitivity and zero or more categories which may
Chris PeBenito cff75c
# be associated with that sensitivity.
Chris PeBenito cff75c
#
Chris PeBenito cff75c
level s0:c0.c127;
Chris PeBenito cff75c
Chris PeBenito cff75c
#
Chris PeBenito cff75c
# Define the MCS policy
Chris PeBenito cff75c
#
Chris PeBenito cff75c
# mlsconstrain class_set perm_set expression ;
Chris PeBenito cff75c
#
Chris PeBenito cff75c
# mlsvalidatetrans class_set expression ;
Chris PeBenito cff75c
#
Chris PeBenito cff75c
# expression : ( expression )
Chris PeBenito cff75c
#	     | not expression
Chris PeBenito cff75c
#	     | expression and expression
Chris PeBenito cff75c
#	     | expression or expression
Chris PeBenito cff75c
#	     | u1 op u2
Chris PeBenito cff75c
#	     | r1 role_mls_op r2
Chris PeBenito cff75c
#	     | t1 op t2
Chris PeBenito cff75c
#	     | l1 role_mls_op l2
Chris PeBenito cff75c
#	     | l1 role_mls_op h2
Chris PeBenito cff75c
#	     | h1 role_mls_op l2
Chris PeBenito cff75c
#	     | h1 role_mls_op h2
Chris PeBenito cff75c
#	     | l1 role_mls_op h1
Chris PeBenito cff75c
#	     | l2 role_mls_op h2
Chris PeBenito cff75c
#	     | u1 op names
Chris PeBenito cff75c
#	     | u2 op names
Chris PeBenito cff75c
#	     | r1 op names
Chris PeBenito cff75c
#	     | r2 op names
Chris PeBenito cff75c
#	     | t1 op names
Chris PeBenito cff75c
#	     | t2 op names
Chris PeBenito cff75c
#	     | u3 op names (NOTE: this is only available for mlsvalidatetrans)
Chris PeBenito cff75c
#	     | r3 op names (NOTE: this is only available for mlsvalidatetrans)
Chris PeBenito cff75c
#	     | t3 op names (NOTE: this is only available for mlsvalidatetrans)
Chris PeBenito cff75c
#
Chris PeBenito cff75c
# op : == | !=
Chris PeBenito cff75c
# role_mls_op : == | != | eq | dom | domby | incomp
Chris PeBenito cff75c
#
Chris PeBenito cff75c
# names : name | { name_list }
Chris PeBenito cff75c
# name_list : name | name_list name
Chris PeBenito cff75c
#
Chris PeBenito cff75c
Chris PeBenito cff75c
#
Chris PeBenito cff75c
# MCS policy for the file classes
Chris PeBenito cff75c
#
Chris PeBenito cff75c
# Constrain file access so that the high range of the process dominates
Chris PeBenito cff75c
# the high range of the file.  We use the high range of the process so
Chris PeBenito cff75c
# that processes can always simply run at s0.
Chris PeBenito cff75c
#
Chris PeBenito cff75c
# Only files are constrained by MCS at this stage.
Chris PeBenito cff75c
#
Chris PeBenito cff75c
mlsconstrain file { read write setattr append unlink link rename
Chris PeBenito cff75c
		    create ioctl lock execute } (h1 dom h2);
Chris PeBenito cff75c
Chris PeBenito cff75c
Chris PeBenito cff75c
# XXX
Chris PeBenito cff75c
#
Chris PeBenito cff75c
# For some reason, we need to reference the mlsfileread attribute
Chris PeBenito cff75c
# or we get a build error.  Below is a dummy entry to do this.
Chris PeBenito cff75c
mlsconstrain xextension query ( t1 == mlsfileread );
Chris PeBenito cff75c