Blob Blame History Raw
policy_module(cpufreqselector, 1.1.0)

########################################
#
# Declarations
#

type cpufreqselector_t;
type cpufreqselector_exec_t;
application_domain(cpufreqselector_t, cpufreqselector_exec_t)

########################################
#
# cpufreq-selector local policy
#

allow cpufreqselector_t self:capability { sys_nice sys_ptrace };
allow cpufreqselector_t self:fifo_file rw_fifo_file_perms;

files_read_etc_files(cpufreqselector_t)
files_read_usr_files(cpufreqselector_t)

corecmd_search_bin(cpufreqselector_t)

dev_rw_sysfs(cpufreqselector_t)

userdom_read_all_users_state(cpufreqselector_t)
userdom_dontaudit_search_user_home_dirs(cpufreqselector_t)

optional_policy(`
	dbus_system_domain(cpufreqselector_t, cpufreqselector_exec_t)

	optional_policy(`
		consolekit_dbus_chat(cpufreqselector_t)
	')

	optional_policy(`
		policykit_dbus_chat(cpufreqselector_t)
	')
')

optional_policy(`
	nscd_dontaudit_search_pid(cpufreqselector_t)
')

optional_policy(`
	policykit_domtrans_auth(cpufreqselector_t)
	policykit_read_lib(cpufreqselector_t)
	policykit_read_reload(cpufreqselector_t)
')