diff --git a/refpolicy/policy/modules/admin/dmesg.if b/refpolicy/policy/modules/admin/dmesg.if index bc718b2..81fae63 100644 --- a/refpolicy/policy/modules/admin/dmesg.if +++ b/refpolicy/policy/modules/admin/dmesg.if @@ -1,5 +1,4 @@ # Copyright (C) 2005 Tresys Technology, LLC - ## <module name="dmesg" layer="keyservices"> ## <summary>Policy for dmesg.</summary> diff --git a/refpolicy/policy/modules/kernel/filesystem.if b/refpolicy/policy/modules/kernel/filesystem.if index cd67131..e475529 100644 --- a/refpolicy/policy/modules/kernel/filesystem.if +++ b/refpolicy/policy/modules/kernel/filesystem.if @@ -1,4 +1,6 @@ # Copyright (C) 2005 Tresys Technology, LLC +## <module name="storage" layer="kernel"> +## <summary>Policy for filesystems.</summary> ######################################## # @@ -1196,3 +1198,5 @@ class lnk_file getattr; class fifo_file getattr; class sock_file getattr; ') + +## </module> diff --git a/refpolicy/policy/modules/kernel/kernel.if b/refpolicy/policy/modules/kernel/kernel.if index 2ce1ec2..b2f056b 100644 --- a/refpolicy/policy/modules/kernel/kernel.if +++ b/refpolicy/policy/modules/kernel/kernel.if @@ -1,4 +1,9 @@ # Copyright (C) 2005 Tresys Technology, LLC +## <module name="kernel" layer="kernel"> +## <summary> +## Policy for kernel threads, security interface (selinuxfs), +## proc filesystem, sysfs filesystem, and usb device filesystem. +## </summary> ######################################## # @@ -1319,3 +1324,5 @@ define(`kernel_read_directory_from_depend',` type kernel_t; class dir { getattr search read }; ') + +## </module> diff --git a/refpolicy/policy/modules/system/clock.if b/refpolicy/policy/modules/system/clock.if index 73e32dd..9a2644b 100644 --- a/refpolicy/policy/modules/system/clock.if +++ b/refpolicy/policy/modules/system/clock.if @@ -1,4 +1,6 @@ # Copyright (C) 2005 Tresys Technology, LLC +## <module name="clock" layer="keyservices"> +## <summary>Policy for reading and setting the hardware clock.</summary> ######################################## ## <interface name="clock_transition"> @@ -89,3 +91,5 @@ define(`clock_modify_drift_records_depend',` type adjtime_t; class file { getattr read write ioctl lock append }; ') + +## </module> diff --git a/refpolicy/policy/modules/system/init.if b/refpolicy/policy/modules/system/init.if index 61e2c01..8fc9830 100644 --- a/refpolicy/policy/modules/system/init.if +++ b/refpolicy/policy/modules/system/init.if @@ -1,4 +1,6 @@ # Copyright (C) 2005 Tresys Technology, LLC +## <module name="init" layer="system"> +## <summary>System initialization programs (init and init scripts).</summary> ######################################## # @@ -476,3 +478,5 @@ define(`init_script_ignore_modify_runtime_data_depend',` type initrc_var_run_t; class file { getattr read write append }; ') + +## </module> diff --git a/refpolicy/policy/modules/system/iptables.if b/refpolicy/policy/modules/system/iptables.if index c0d6335..4987c4c 100644 --- a/refpolicy/policy/modules/system/iptables.if +++ b/refpolicy/policy/modules/system/iptables.if @@ -1,4 +1,6 @@ # Copyright (C) 2005 Tresys Technology, LLC +## <module name="iptables" layer="system"> +## <summary>Policy for iptables.</summary> ######################################## ## <interface name="iptables_transition"> @@ -81,3 +83,5 @@ define(`iptables_execute_depend',` type iptables_t, iptables_exec_t; class file { getattr read execute execute_no_trans }; ') + +## </module> diff --git a/refpolicy/policy/modules/system/logging.if b/refpolicy/policy/modules/system/logging.if index 0b4c0a5..b878ef2 100644 --- a/refpolicy/policy/modules/system/logging.if +++ b/refpolicy/policy/modules/system/logging.if @@ -1,4 +1,6 @@ # Copyright (C) 2005 Tresys Technology, LLC +## <module name="logging" layer="system"> +## <summary>Policy for the kernel message logger and system logging daemon.</summary> ####################################### # @@ -181,3 +183,5 @@ type var_log_t; class dir { getattr search read }; class file { getattr read write append }; ') + +## </module> diff --git a/refpolicy/policy/modules/system/mount.if b/refpolicy/policy/modules/system/mount.if index 574bf39..ff64c26 100644 --- a/refpolicy/policy/modules/system/mount.if +++ b/refpolicy/policy/modules/system/mount.if @@ -1,4 +1,6 @@ # Copyright (C) 2005 Tresys Technology, LLC +## <module name="mount" layer="system"> +## <summary>Policy for mount.</summary> ######################################## ## <interface name="mount_transition"> @@ -89,3 +91,5 @@ define(`mount_send_nfs_client_request_depend',` type mount_t; class udp_socket { ioctl read getattr write setattr append bind connect getopt setopt shutdown }; ') + +## </module> diff --git a/refpolicy/policy/modules/system/sysnetwork.if b/refpolicy/policy/modules/system/sysnetwork.if index 0de49c3..cc64939 100644 --- a/refpolicy/policy/modules/system/sysnetwork.if +++ b/refpolicy/policy/modules/system/sysnetwork.if @@ -1,4 +1,6 @@ # Copyright (C) 2005 Tresys Technology, LLC +## <module name="sysnetwork" layer="system"> +## <summary>Policy for network configuration: ifconfig and dhcp client.</summary> ######################################## # @@ -100,3 +102,5 @@ define(`sysnetwork_read_network_config_depend',` type net_conf_t; class file { getattr read }; ') + +## </module>