Chris PeBenito cff75c
#
Chris PeBenito cff75c
# Define sensitivities 
Chris PeBenito cff75c
#
Chris PeBenito cff75c
# Each sensitivity has a name and zero or more aliases.
Chris PeBenito cff75c
#
Chris PeBenito cff75c
# MCS is single-sensitivity.
Chris PeBenito cff75c
#
Chris PeBenito cff75c
sensitivity s0;
Chris PeBenito cff75c
Chris PeBenito cff75c
#
Chris PeBenito cff75c
# Define the ordering of the sensitivity levels (least to greatest)
Chris PeBenito cff75c
#
Chris PeBenito cff75c
dominance { s0 }
Chris PeBenito cff75c
Chris PeBenito cff75c
Chris PeBenito cff75c
#
Chris PeBenito cff75c
# Define the categories
Chris PeBenito cff75c
#
Chris PeBenito cff75c
# Each category has a name and zero or more aliases.
Chris PeBenito cff75c
#
Chris PeBenito cff75c
category c0;
Chris PeBenito cff75c
category c1;
Chris PeBenito cff75c
category c2;
Chris PeBenito cff75c
category c3;
Chris PeBenito cff75c
category c4;
Chris PeBenito cff75c
category c5;
Chris PeBenito cff75c
category c6;
Chris PeBenito cff75c
category c7;
Chris PeBenito cff75c
category c8;
Chris PeBenito cff75c
category c9;
Chris PeBenito cff75c
category c10;
Chris PeBenito cff75c
category c11;
Chris PeBenito cff75c
category c12;
Chris PeBenito cff75c
category c13;
Chris PeBenito cff75c
category c14;
Chris PeBenito cff75c
category c15;
Chris PeBenito cff75c
category c16;
Chris PeBenito cff75c
category c17;
Chris PeBenito cff75c
category c18;
Chris PeBenito cff75c
category c19;
Chris PeBenito cff75c
category c20;
Chris PeBenito cff75c
category c21;
Chris PeBenito cff75c
category c22;
Chris PeBenito cff75c
category c23;
Chris PeBenito cff75c
category c24;
Chris PeBenito cff75c
category c25;
Chris PeBenito cff75c
category c26;
Chris PeBenito cff75c
category c27;
Chris PeBenito cff75c
category c28;
Chris PeBenito cff75c
category c29;
Chris PeBenito cff75c
category c30;
Chris PeBenito cff75c
category c31;
Chris PeBenito cff75c
category c32;
Chris PeBenito cff75c
category c33;
Chris PeBenito cff75c
category c34;
Chris PeBenito cff75c
category c35;
Chris PeBenito cff75c
category c36;
Chris PeBenito cff75c
category c37;
Chris PeBenito cff75c
category c38;
Chris PeBenito cff75c
category c39;
Chris PeBenito cff75c
category c40;
Chris PeBenito cff75c
category c41;
Chris PeBenito cff75c
category c42;
Chris PeBenito cff75c
category c43;
Chris PeBenito cff75c
category c44;
Chris PeBenito cff75c
category c45;
Chris PeBenito cff75c
category c46;
Chris PeBenito cff75c
category c47;
Chris PeBenito cff75c
category c48;
Chris PeBenito cff75c
category c49;
Chris PeBenito cff75c
category c50;
Chris PeBenito cff75c
category c51;
Chris PeBenito cff75c
category c52;
Chris PeBenito cff75c
category c53;
Chris PeBenito cff75c
category c54;
Chris PeBenito cff75c
category c55;
Chris PeBenito cff75c
category c56;
Chris PeBenito cff75c
category c57;
Chris PeBenito cff75c
category c58;
Chris PeBenito cff75c
category c59;
Chris PeBenito cff75c
category c60;
Chris PeBenito cff75c
category c61;
Chris PeBenito cff75c
category c62;
Chris PeBenito cff75c
category c63;
Chris PeBenito cff75c
category c64;
Chris PeBenito cff75c
category c65;
Chris PeBenito cff75c
category c66;
Chris PeBenito cff75c
category c67;
Chris PeBenito cff75c
category c68;
Chris PeBenito cff75c
category c69;
Chris PeBenito cff75c
category c70;
Chris PeBenito cff75c
category c71;
Chris PeBenito cff75c
category c72;
Chris PeBenito cff75c
category c73;
Chris PeBenito cff75c
category c74;
Chris PeBenito cff75c
category c75;
Chris PeBenito cff75c
category c76;
Chris PeBenito cff75c
category c77;
Chris PeBenito cff75c
category c78;
Chris PeBenito cff75c
category c79;
Chris PeBenito cff75c
category c80;
Chris PeBenito cff75c
category c81;
Chris PeBenito cff75c
category c82;
Chris PeBenito cff75c
category c83;
Chris PeBenito cff75c
category c84;
Chris PeBenito cff75c
category c85;
Chris PeBenito cff75c
category c86;
Chris PeBenito cff75c
category c87;
Chris PeBenito cff75c
category c88;
Chris PeBenito cff75c
category c89;
Chris PeBenito cff75c
category c90;
Chris PeBenito cff75c
category c91;
Chris PeBenito cff75c
category c92;
Chris PeBenito cff75c
category c93;
Chris PeBenito cff75c
category c94;
Chris PeBenito cff75c
category c95;
Chris PeBenito cff75c
category c96;
Chris PeBenito cff75c
category c97;
Chris PeBenito cff75c
category c98;
Chris PeBenito cff75c
category c99;
Chris PeBenito cff75c
category c100;
Chris PeBenito cff75c
category c101;
Chris PeBenito cff75c
category c102;
Chris PeBenito cff75c
category c103;
Chris PeBenito cff75c
category c104;
Chris PeBenito cff75c
category c105;
Chris PeBenito cff75c
category c106;
Chris PeBenito cff75c
category c107;
Chris PeBenito cff75c
category c108;
Chris PeBenito cff75c
category c109;
Chris PeBenito cff75c
category c110;
Chris PeBenito cff75c
category c111;
Chris PeBenito cff75c
category c112;
Chris PeBenito cff75c
category c113;
Chris PeBenito cff75c
category c114;
Chris PeBenito cff75c
category c115;
Chris PeBenito cff75c
category c116;
Chris PeBenito cff75c
category c117;
Chris PeBenito cff75c
category c118;
Chris PeBenito cff75c
category c119;
Chris PeBenito cff75c
category c120;
Chris PeBenito cff75c
category c121;
Chris PeBenito cff75c
category c122;
Chris PeBenito cff75c
category c123;
Chris PeBenito cff75c
category c124;
Chris PeBenito cff75c
category c125;
Chris PeBenito cff75c
category c126;
Chris PeBenito cff75c
category c127;
Chris PeBenito 77f6e2
category c128;
Chris PeBenito 77f6e2
category c129;
Chris PeBenito 77f6e2
category c130;
Chris PeBenito 77f6e2
category c131;
Chris PeBenito 77f6e2
category c132;
Chris PeBenito 77f6e2
category c133;
Chris PeBenito 77f6e2
category c134;
Chris PeBenito 77f6e2
category c135;
Chris PeBenito 77f6e2
category c136;
Chris PeBenito 77f6e2
category c137;
Chris PeBenito 77f6e2
category c138;
Chris PeBenito 77f6e2
category c139;
Chris PeBenito 77f6e2
category c140;
Chris PeBenito 77f6e2
category c141;
Chris PeBenito 77f6e2
category c142;
Chris PeBenito 77f6e2
category c143;
Chris PeBenito 77f6e2
category c144;
Chris PeBenito 77f6e2
category c145;
Chris PeBenito 77f6e2
category c146;
Chris PeBenito 77f6e2
category c147;
Chris PeBenito 77f6e2
category c148;
Chris PeBenito 77f6e2
category c149;
Chris PeBenito 77f6e2
category c150;
Chris PeBenito 77f6e2
category c151;
Chris PeBenito 77f6e2
category c152;
Chris PeBenito 77f6e2
category c153;
Chris PeBenito 77f6e2
category c154;
Chris PeBenito 77f6e2
category c155;
Chris PeBenito 77f6e2
category c156;
Chris PeBenito 77f6e2
category c157;
Chris PeBenito 77f6e2
category c158;
Chris PeBenito 77f6e2
category c159;
Chris PeBenito 77f6e2
category c160;
Chris PeBenito 77f6e2
category c161;
Chris PeBenito 77f6e2
category c162;
Chris PeBenito 77f6e2
category c163;
Chris PeBenito 77f6e2
category c164;
Chris PeBenito 77f6e2
category c165;
Chris PeBenito 77f6e2
category c166;
Chris PeBenito 77f6e2
category c167;
Chris PeBenito 77f6e2
category c168;
Chris PeBenito 77f6e2
category c169;
Chris PeBenito 77f6e2
category c170;
Chris PeBenito 77f6e2
category c171;
Chris PeBenito 77f6e2
category c172;
Chris PeBenito 77f6e2
category c173;
Chris PeBenito 77f6e2
category c174;
Chris PeBenito 77f6e2
category c175;
Chris PeBenito 77f6e2
category c176;
Chris PeBenito 77f6e2
category c177;
Chris PeBenito 77f6e2
category c178;
Chris PeBenito 77f6e2
category c179;
Chris PeBenito 77f6e2
category c180;
Chris PeBenito 77f6e2
category c181;
Chris PeBenito 77f6e2
category c182;
Chris PeBenito 77f6e2
category c183;
Chris PeBenito 77f6e2
category c184;
Chris PeBenito 77f6e2
category c185;
Chris PeBenito 77f6e2
category c186;
Chris PeBenito 77f6e2
category c187;
Chris PeBenito 77f6e2
category c188;
Chris PeBenito 77f6e2
category c189;
Chris PeBenito 77f6e2
category c190;
Chris PeBenito 77f6e2
category c191;
Chris PeBenito 77f6e2
category c192;
Chris PeBenito 77f6e2
category c193;
Chris PeBenito 77f6e2
category c194;
Chris PeBenito 77f6e2
category c195;
Chris PeBenito 77f6e2
category c196;
Chris PeBenito 77f6e2
category c197;
Chris PeBenito 77f6e2
category c198;
Chris PeBenito 77f6e2
category c199;
Chris PeBenito 77f6e2
category c200;
Chris PeBenito 77f6e2
category c201;
Chris PeBenito 77f6e2
category c202;
Chris PeBenito 77f6e2
category c203;
Chris PeBenito 77f6e2
category c204;
Chris PeBenito 77f6e2
category c205;
Chris PeBenito 77f6e2
category c206;
Chris PeBenito 77f6e2
category c207;
Chris PeBenito 77f6e2
category c208;
Chris PeBenito 77f6e2
category c209;
Chris PeBenito 77f6e2
category c210;
Chris PeBenito 77f6e2
category c211;
Chris PeBenito 77f6e2
category c212;
Chris PeBenito 77f6e2
category c213;
Chris PeBenito 77f6e2
category c214;
Chris PeBenito 77f6e2
category c215;
Chris PeBenito 77f6e2
category c216;
Chris PeBenito 77f6e2
category c217;
Chris PeBenito 77f6e2
category c218;
Chris PeBenito 77f6e2
category c219;
Chris PeBenito 77f6e2
category c220;
Chris PeBenito 77f6e2
category c221;
Chris PeBenito 77f6e2
category c222;
Chris PeBenito 77f6e2
category c223;
Chris PeBenito 77f6e2
category c224;
Chris PeBenito 77f6e2
category c225;
Chris PeBenito 77f6e2
category c226;
Chris PeBenito 77f6e2
category c227;
Chris PeBenito 77f6e2
category c228;
Chris PeBenito 77f6e2
category c229;
Chris PeBenito 77f6e2
category c230;
Chris PeBenito 77f6e2
category c231;
Chris PeBenito 77f6e2
category c232;
Chris PeBenito 77f6e2
category c233;
Chris PeBenito 77f6e2
category c234;
Chris PeBenito 77f6e2
category c235;
Chris PeBenito 77f6e2
category c236;
Chris PeBenito 77f6e2
category c237;
Chris PeBenito 77f6e2
category c238;
Chris PeBenito 77f6e2
category c239;
Chris PeBenito 77f6e2
category c240;
Chris PeBenito 77f6e2
category c241;
Chris PeBenito 77f6e2
category c242;
Chris PeBenito 77f6e2
category c243;
Chris PeBenito 77f6e2
category c244;
Chris PeBenito 77f6e2
category c245;
Chris PeBenito 77f6e2
category c246;
Chris PeBenito 77f6e2
category c247;
Chris PeBenito 77f6e2
category c248;
Chris PeBenito 77f6e2
category c249;
Chris PeBenito 77f6e2
category c250;
Chris PeBenito 77f6e2
category c251;
Chris PeBenito 77f6e2
category c252;
Chris PeBenito 77f6e2
category c253;
Chris PeBenito 77f6e2
category c254;
Chris PeBenito 77f6e2
category c255;
Chris PeBenito cff75c
Chris PeBenito cff75c
Chris PeBenito cff75c
#
Chris PeBenito cff75c
# Each MCS level specifies a sensitivity and zero or more categories which may
Chris PeBenito cff75c
# be associated with that sensitivity.
Chris PeBenito cff75c
#
Chris PeBenito 77f6e2
level s0:c0.c255;
Chris PeBenito cff75c
Chris PeBenito cff75c
#
Chris PeBenito cff75c
# Define the MCS policy
Chris PeBenito cff75c
#
Chris PeBenito cff75c
# mlsconstrain class_set perm_set expression ;
Chris PeBenito cff75c
#
Chris PeBenito cff75c
# mlsvalidatetrans class_set expression ;
Chris PeBenito cff75c
#
Chris PeBenito cff75c
# expression : ( expression )
Chris PeBenito cff75c
#	     | not expression
Chris PeBenito cff75c
#	     | expression and expression
Chris PeBenito cff75c
#	     | expression or expression
Chris PeBenito cff75c
#	     | u1 op u2
Chris PeBenito cff75c
#	     | r1 role_mls_op r2
Chris PeBenito cff75c
#	     | t1 op t2
Chris PeBenito cff75c
#	     | l1 role_mls_op l2
Chris PeBenito cff75c
#	     | l1 role_mls_op h2
Chris PeBenito cff75c
#	     | h1 role_mls_op l2
Chris PeBenito cff75c
#	     | h1 role_mls_op h2
Chris PeBenito cff75c
#	     | l1 role_mls_op h1
Chris PeBenito cff75c
#	     | l2 role_mls_op h2
Chris PeBenito cff75c
#	     | u1 op names
Chris PeBenito cff75c
#	     | u2 op names
Chris PeBenito cff75c
#	     | r1 op names
Chris PeBenito cff75c
#	     | r2 op names
Chris PeBenito cff75c
#	     | t1 op names
Chris PeBenito cff75c
#	     | t2 op names
Chris PeBenito cff75c
#	     | u3 op names (NOTE: this is only available for mlsvalidatetrans)
Chris PeBenito cff75c
#	     | r3 op names (NOTE: this is only available for mlsvalidatetrans)
Chris PeBenito cff75c
#	     | t3 op names (NOTE: this is only available for mlsvalidatetrans)
Chris PeBenito cff75c
#
Chris PeBenito cff75c
# op : == | !=
Chris PeBenito cff75c
# role_mls_op : == | != | eq | dom | domby | incomp
Chris PeBenito cff75c
#
Chris PeBenito cff75c
# names : name | { name_list }
Chris PeBenito cff75c
# name_list : name | name_list name
Chris PeBenito cff75c
#
Chris PeBenito cff75c
Chris PeBenito cff75c
#
Chris PeBenito cff75c
# MCS policy for the file classes
Chris PeBenito cff75c
#
Chris PeBenito cff75c
# Constrain file access so that the high range of the process dominates
Chris PeBenito cff75c
# the high range of the file.  We use the high range of the process so
Chris PeBenito cff75c
# that processes can always simply run at s0.
Chris PeBenito cff75c
#
Chris PeBenito cff75c
# Only files are constrained by MCS at this stage.
Chris PeBenito cff75c
#
Chris PeBenito 77f6e2
mlsconstrain file { write setattr append unlink link rename
Chris PeBenito cff75c
		    create ioctl lock execute } (h1 dom h2);
Chris PeBenito cff75c
Chris PeBenito 77f6e2
mlsconstrain file { read } ((h1 dom h2) or 
Chris PeBenito 77f6e2
			    ( t1 == mlsfileread ));
Chris PeBenito 77f6e2
Chris PeBenito 77f6e2
Chris PeBenito 77f6e2
# new file labels must be dominated by the relabeling subject's clearance
Chris PeBenito 77f6e2
mlsconstrain { dir file lnk_file chr_file blk_file sock_file fifo_file } { relabelfrom relabelto }
Chris PeBenito 77f6e2
	( h1 dom h2 );
Chris PeBenito 77f6e2
Chris PeBenito 77f6e2
define(`nogetattr_file_perms', `{ create ioctl read lock write setattr append 
Chris PeBenito 77f6e2
link unlink rename relabelfrom relabelto }')
Chris PeBenito 77f6e2
Chris PeBenito 77f6e2
define(`nogetattr_dir_perms', `{ create read lock setattr ioctl link unlink 
Chris PeBenito 77f6e2
rename search add_name remove_name reparent write rmdir relabelfrom 
Chris PeBenito 77f6e2
relabelto }')
Chris PeBenito cff75c
Chris PeBenito cff75c
# XXX
Chris PeBenito cff75c
#
Chris PeBenito cff75c
# For some reason, we need to reference the mlsfileread attribute
Chris PeBenito cff75c
# or we get a build error.  Below is a dummy entry to do this.
Chris PeBenito cff75c
mlsconstrain xextension query ( t1 == mlsfileread );
Chris PeBenito cff75c