]> git.ipfire.org Git - people/stevee/selinux-policy.git/blame - policy/modules/services/comsat.te
trunk: bump module versions for release.
[people/stevee/selinux-policy.git] / policy / modules / services / comsat.te
CommitLineData
6e61566d 1
17ec8c1f 2policy_module(comsat, 1.6.0)
6e61566d
CP
3
4########################################
5#
6# Declarations
7#
768283ac 8
6e61566d
CP
9type comsat_t;
10type comsat_exec_t;
0bfccda4 11inetd_udp_service_domain(comsat_t, comsat_exec_t)
6e61566d
CP
12role system_r types comsat_t;
13
14type comsat_tmp_t;
15files_tmp_file(comsat_tmp_t)
16
17type comsat_var_run_t;
18files_pid_file(comsat_var_run_t)
19
20########################################
21#
22# Local policy
23#
24
25allow comsat_t self:capability { setuid setgid };
26allow comsat_t self:process signal_perms;
c0868a7a 27allow comsat_t self:fifo_file rw_fifo_file_perms;
6e61566d 28allow comsat_t self:netlink_tcpdiag_socket r_netlink_socket_perms;
681c9a02 29allow comsat_t self:tcp_socket connected_stream_socket_perms;
1904b010 30allow comsat_t self:udp_socket create_socket_perms;
6e61566d 31
0bfccda4
CP
32manage_dirs_pattern(comsat_t, comsat_tmp_t, comsat_tmp_t)
33manage_files_pattern(comsat_t, comsat_tmp_t, comsat_tmp_t)
103fe280 34files_tmp_filetrans(comsat_t, comsat_tmp_t, { file dir })
6e61566d 35
0bfccda4
CP
36manage_files_pattern(comsat_t, comsat_var_run_t, comsat_var_run_t)
37files_pid_filetrans(comsat_t, comsat_var_run_t, file)
6e61566d 38
445522dc 39kernel_read_kernel_sysctls(comsat_t)
6e61566d
CP
40kernel_read_network_state(comsat_t)
41kernel_read_system_state(comsat_t)
42
19006686
CP
43corenet_all_recvfrom_unlabeled(comsat_t)
44corenet_all_recvfrom_netlabel(comsat_t)
6e61566d 45corenet_tcp_sendrecv_all_if(comsat_t)
681c9a02 46corenet_udp_sendrecv_all_if(comsat_t)
6e61566d 47corenet_tcp_sendrecv_all_nodes(comsat_t)
681c9a02 48corenet_udp_sendrecv_all_nodes(comsat_t)
2db2c7d0 49corenet_udp_sendrecv_all_ports(comsat_t)
6e61566d
CP
50
51dev_read_urand(comsat_t)
52
53fs_getattr_xattr_fs(comsat_t)
54
55files_read_etc_files(comsat_t)
681c9a02 56files_list_usr(comsat_t)
6e61566d
CP
57files_search_spool(comsat_t)
58files_search_home(comsat_t)
59
c0cf6e0a
CP
60auth_use_nsswitch(comsat_t)
61
68228b33
CP
62init_read_utmp(comsat_t)
63init_dontaudit_write_utmp(comsat_t)
6e61566d 64
6e61566d
CP
65logging_send_syslog_msg(comsat_t)
66
67miscfiles_read_localization(comsat_t)
68
296273a7 69userdom_dontaudit_getattr_user_ttys(comsat_t)
6e61566d 70
296273a7 71mta_getattr_spool(comsat_t)
e9c6cda7 72
bb7170f6 73optional_policy(`
6e61566d
CP
74 kerberos_use(comsat_t)
75')