]> git.ipfire.org Git - people/stevee/selinux-policy.git/blame - policy/modules/services/irqbalance.te
Bump module versions for release.
[people/stevee/selinux-policy.git] / policy / modules / services / irqbalance.te
CommitLineData
5d5ea8d0 1
29af4c13 2policy_module(irqbalance, 1.5.0)
5d5ea8d0
CP
3
4########################################
5#
6# Declarations
7#
8
9type irqbalance_t;
10type irqbalance_exec_t;
0bfccda4 11init_daemon_domain(irqbalance_t, irqbalance_exec_t)
5d5ea8d0
CP
12
13type irqbalance_var_run_t;
14files_pid_file(irqbalance_var_run_t)
15
16########################################
17#
18# Local policy
19#
20
7d05af77 21allow irqbalance_t self:capability { setpcap net_admin };
5d5ea8d0 22dontaudit irqbalance_t self:capability sys_tty_config;
7d05af77
CP
23allow irqbalance_t self:process { getcap setcap signal_perms };
24allow irqbalance_t self:udp_socket create_socket_perms;
5d5ea8d0 25
0bfccda4
CP
26manage_files_pattern(irqbalance_t, irqbalance_var_run_t, irqbalance_var_run_t)
27files_pid_filetrans(irqbalance_t, irqbalance_var_run_t, file)
5d5ea8d0 28
6b19be33 29kernel_read_network_state(irqbalance_t)
5d5ea8d0 30kernel_read_system_state(irqbalance_t)
445522dc
CP
31kernel_read_kernel_sysctls(irqbalance_t)
32kernel_rw_irq_sysctls(irqbalance_t)
5d5ea8d0
CP
33
34dev_read_sysfs(irqbalance_t)
35
95501942
CP
36files_read_etc_files(irqbalance_t)
37files_read_etc_runtime_files(irqbalance_t)
38
5d5ea8d0
CP
39fs_getattr_all_fs(irqbalance_t)
40fs_search_auto_mountpoints(irqbalance_t)
41
15722ec9 42domain_use_interactive_fds(irqbalance_t)
5d5ea8d0 43
5d5ea8d0
CP
44logging_send_syslog_msg(irqbalance_t)
45
46miscfiles_read_localization(irqbalance_t)
47
15722ec9 48userdom_dontaudit_use_unpriv_user_fds(irqbalance_t)
296273a7 49userdom_dontaudit_search_user_home_dirs(irqbalance_t)
5d5ea8d0 50
bb7170f6 51optional_policy(`
5d5ea8d0
CP
52 seutil_sigchld_newrole(irqbalance_t)
53')
54
bb7170f6 55optional_policy(`
5d5ea8d0
CP
56 udev_read_db(irqbalance_t)
57')