]> git.ipfire.org Git - people/stevee/selinux-policy.git/blame - policy/modules/services/comsat.te
Allow munin services plugins to use NSCD services
[people/stevee/selinux-policy.git] / policy / modules / services / comsat.te
CommitLineData
9570b288 1policy_module(comsat, 1.7.0)
6e61566d
CP
2
3########################################
4#
5# Declarations
6#
768283ac 7
6e61566d
CP
8type comsat_t;
9type comsat_exec_t;
0bfccda4 10inetd_udp_service_domain(comsat_t, comsat_exec_t)
6e61566d
CP
11role system_r types comsat_t;
12
13type comsat_tmp_t;
14files_tmp_file(comsat_tmp_t)
15
16type comsat_var_run_t;
17files_pid_file(comsat_var_run_t)
18
19########################################
20#
21# Local policy
22#
23
24allow comsat_t self:capability { setuid setgid };
25allow comsat_t self:process signal_perms;
c0868a7a 26allow comsat_t self:fifo_file rw_fifo_file_perms;
6e61566d 27allow comsat_t self:netlink_tcpdiag_socket r_netlink_socket_perms;
681c9a02 28allow comsat_t self:tcp_socket connected_stream_socket_perms;
1904b010 29allow comsat_t self:udp_socket create_socket_perms;
6e61566d 30
0bfccda4
CP
31manage_dirs_pattern(comsat_t, comsat_tmp_t, comsat_tmp_t)
32manage_files_pattern(comsat_t, comsat_tmp_t, comsat_tmp_t)
103fe280 33files_tmp_filetrans(comsat_t, comsat_tmp_t, { file dir })
6e61566d 34
0bfccda4
CP
35manage_files_pattern(comsat_t, comsat_var_run_t, comsat_var_run_t)
36files_pid_filetrans(comsat_t, comsat_var_run_t, file)
6e61566d 37
445522dc 38kernel_read_kernel_sysctls(comsat_t)
6e61566d
CP
39kernel_read_network_state(comsat_t)
40kernel_read_system_state(comsat_t)
41
19006686
CP
42corenet_all_recvfrom_unlabeled(comsat_t)
43corenet_all_recvfrom_netlabel(comsat_t)
668b3093
CP
44corenet_tcp_sendrecv_generic_if(comsat_t)
45corenet_udp_sendrecv_generic_if(comsat_t)
c1262146
CP
46corenet_tcp_sendrecv_generic_node(comsat_t)
47corenet_udp_sendrecv_generic_node(comsat_t)
2db2c7d0 48corenet_udp_sendrecv_all_ports(comsat_t)
6e61566d
CP
49
50dev_read_urand(comsat_t)
51
52fs_getattr_xattr_fs(comsat_t)
53
54files_read_etc_files(comsat_t)
681c9a02 55files_list_usr(comsat_t)
6e61566d
CP
56files_search_spool(comsat_t)
57files_search_home(comsat_t)
58
c0cf6e0a
CP
59auth_use_nsswitch(comsat_t)
60
68228b33
CP
61init_read_utmp(comsat_t)
62init_dontaudit_write_utmp(comsat_t)
6e61566d 63
6e61566d
CP
64logging_send_syslog_msg(comsat_t)
65
66miscfiles_read_localization(comsat_t)
67
296273a7 68userdom_dontaudit_getattr_user_ttys(comsat_t)
6e61566d 69
296273a7 70mta_getattr_spool(comsat_t)
e9c6cda7 71
bb7170f6 72optional_policy(`
6e61566d
CP
73 kerberos_use(comsat_t)
74')