]> git.ipfire.org Git - people/stevee/selinux-policy.git/blame - policy/modules/services/transproxy.te
trunk: bump versions for release.
[people/stevee/selinux-policy.git] / policy / modules / services / transproxy.te
CommitLineData
fa895160 1
cfcf5004 2policy_module(transproxy, 1.5.0)
fa895160
CP
3
4########################################
5#
6# Declarations
7#
8
9type transproxy_t;
10type transproxy_exec_t;
11init_daemon_domain(transproxy_t,transproxy_exec_t)
12
13type transproxy_var_run_t;
14files_pid_file(transproxy_var_run_t)
15
16########################################
17#
18# Local policy
19#
20
21allow transproxy_t self:capability { setgid setuid };
22dontaudit transproxy_t self:capability sys_tty_config;
23allow transproxy_t self:process signal_perms;
24allow transproxy_t self:tcp_socket create_stream_socket_perms;
25
c0868a7a 26manage_files_pattern(transproxy_t,transproxy_var_run_t,transproxy_var_run_t)
fa895160
CP
27files_pid_filetrans(transproxy_t,transproxy_var_run_t,file)
28
29kernel_read_kernel_sysctls(transproxy_t)
30kernel_list_proc(transproxy_t)
31kernel_read_proc_symlinks(transproxy_t)
32
19006686
CP
33corenet_all_recvfrom_unlabeled(transproxy_t)
34corenet_all_recvfrom_netlabel(transproxy_t)
fa895160 35corenet_tcp_sendrecv_generic_if(transproxy_t)
fa895160 36corenet_tcp_sendrecv_all_nodes(transproxy_t)
fa895160
CP
37corenet_tcp_sendrecv_all_ports(transproxy_t)
38corenet_tcp_bind_all_nodes(transproxy_t)
39corenet_tcp_bind_transproxy_port(transproxy_t)
141cffdd 40corenet_sendrecv_transproxy_server_packets(transproxy_t)
fa895160
CP
41
42dev_read_sysfs(transproxy_t)
43
44domain_use_interactive_fds(transproxy_t)
45
46files_read_etc_files(transproxy_t)
47
48fs_getattr_all_fs(transproxy_t)
49fs_search_auto_mountpoints(transproxy_t)
50
fa895160
CP
51libs_use_ld_so(transproxy_t)
52libs_use_shared_libs(transproxy_t)
53
54logging_send_syslog_msg(transproxy_t)
55
56miscfiles_read_localization(transproxy_t)
57
58sysnet_read_config(transproxy_t)
59
60userdom_dontaudit_use_unpriv_user_fds(transproxy_t)
e9c6cda7
CP
61
62sysadm_dontaudit_search_home_dirs(transproxy_t)
fa895160 63
fa895160
CP
64optional_policy(`
65 seutil_sigchld_newrole(transproxy_t)
66')
67
68optional_policy(`
69 udev_read_db(transproxy_t)
70')