]> git.ipfire.org Git - people/stevee/selinux-policy.git/blame - policy/modules/services/sysstat.te
Bump module versions for release.
[people/stevee/selinux-policy.git] / policy / modules / services / sysstat.te
CommitLineData
0f73fdea 1
29af4c13 2policy_module(sysstat, 1.6.0)
0f73fdea
CP
3
4########################################
5#
6# Declarations
7#
8
9type sysstat_t;
10type sysstat_exec_t;
0bfccda4 11init_system_domain(sysstat_t, sysstat_exec_t)
0f73fdea
CP
12role system_r types sysstat_t;
13
14type sysstat_log_t;
15logging_log_file(sysstat_log_t)
16
17########################################
18#
19# Local policy
20#
21
08d7c733 22allow sysstat_t self:capability { dac_override sys_resource sys_tty_config };
0f73fdea 23dontaudit sysstat_t self:capability sys_admin;
c0868a7a 24allow sysstat_t self:fifo_file rw_fifo_file_perms;
0f73fdea
CP
25
26can_exec(sysstat_t, sysstat_exec_t)
27
08d7c733 28manage_dirs_pattern(sysstat_t,sysstat_log_t,sysstat_log_t)
0bfccda4 29manage_files_pattern(sysstat_t, sysstat_log_t, sysstat_log_t)
08d7c733 30manage_lnk_files_pattern(sysstat_t,sysstat_log_t,sysstat_log_t)
0bfccda4 31logging_log_filetrans(sysstat_t, sysstat_log_t, { file dir })
0f73fdea
CP
32
33# get info from /proc
34kernel_read_system_state(sysstat_t)
35kernel_read_network_state(sysstat_t)
445522dc
CP
36kernel_read_kernel_sysctls(sysstat_t)
37kernel_read_fs_sysctls(sysstat_t)
38kernel_read_rpc_sysctls(sysstat_t)
0f73fdea 39
0f73fdea
CP
40corecmd_exec_bin(sysstat_t)
41
42dev_read_urand(sysstat_t)
86b28c95 43dev_read_sysfs(sysstat_t)
0f73fdea
CP
44
45files_search_var(sysstat_t)
46# for mtab
47files_read_etc_runtime_files(sysstat_t)
48#for fstab
49files_read_etc_files(sysstat_t)
50
51fs_getattr_xattr_fs(sysstat_t)
657c226c 52fs_list_inotifyfs(sysstat_t)
0f73fdea 53
9667c156 54term_use_console(sysstat_t)
a5e2133b 55term_use_all_terms(sysstat_t)
0f73fdea 56
1c1ac67f 57init_use_fds(sysstat_t)
0f73fdea 58
a5e2133b
CP
59locallogin_use_fds(sysstat_t)
60
0f73fdea
CP
61miscfiles_read_localization(sysstat_t)
62
296273a7 63userdom_dontaudit_list_user_home_dirs(sysstat_t)
0f73fdea 64
bb7170f6 65optional_policy(`
0bfccda4 66 cron_system_entry(sysstat_t, sysstat_exec_t)
0f73fdea
CP
67')
68
bb7170f6 69optional_policy(`
0f73fdea
CP
70 logging_send_syslog_msg(sysstat_t)
71')