]> git.ipfire.org Git - people/stevee/selinux-policy.git/blob - policy/modules/admin/anaconda.te
Makefile: Fix check for current git tag.
[people/stevee/selinux-policy.git] / policy / modules / admin / anaconda.te
1 policy_module(anaconda, 1.6.0)
2
3 ########################################
4 #
5 # Declarations
6 #
7
8 type anaconda_t;
9 type anaconda_exec_t;
10 domain_type(anaconda_t)
11 domain_obj_id_change_exemption(anaconda_t)
12 role system_r types anaconda_t;
13
14 ########################################
15 #
16 # Local policy
17 #
18
19 allow anaconda_t self:process execmem;
20
21 kernel_domtrans_to(anaconda_t, anaconda_exec_t)
22
23 init_domtrans_script(anaconda_t)
24
25 libs_domtrans_ldconfig(anaconda_t)
26
27 logging_send_syslog_msg(anaconda_t)
28
29 seutil_domtrans_semanage(anaconda_t)
30 seutil_domtrans_setsebool(anaconda_t)
31
32 userdom_user_home_dir_filetrans_user_home_content(anaconda_t, { dir file lnk_file fifo_file sock_file })
33
34 optional_policy(`
35 kudzu_domtrans(anaconda_t)
36 ')
37
38 optional_policy(`
39 modutils_domtrans_insmod(anaconda_t)
40 modutils_domtrans_depmod(anaconda_t)
41 ')
42 optional_policy(`
43 rpm_domtrans(anaconda_t)
44 rpm_domtrans_script(anaconda_t)
45 ')
46
47 optional_policy(`
48 ssh_domtrans_keygen(anaconda_t)
49 ')
50
51 optional_policy(`
52 udev_domtrans(anaconda_t)
53 ')
54
55 optional_policy(`
56 unconfined_domain_noaudit(anaconda_t)
57 ')
58
59 optional_policy(`
60 usermanage_domtrans_admin_passwd(anaconda_t)
61 ')