]> git.ipfire.org Git - people/stevee/selinux-policy.git/blob - policy/modules/services/aiccu.if
Merge upstream
[people/stevee/selinux-policy.git] / policy / modules / services / aiccu.if
1 ## <summary>Automatic IPv6 Connectivity Client Utility.</summary>
2
3 ########################################
4 ## <summary>
5 ## Execute a domain transition to run aiccu.
6 ## </summary>
7 ## <param name="domain">
8 ## <summary>
9 ## Domain allowed to transition.
10 ## </summary>
11 ## </param>
12 #
13 interface(`aiccu_domtrans',`
14 gen_require(`
15 type aiccu_t, aiccu_exec_t;
16 ')
17
18 domtrans_pattern($1, aiccu_exec_t, aiccu_t)
19 corecmd_search_bin($1)
20 ')
21
22
23 ########################################
24 ## <summary>
25 ## Execute aiccu server in the aiccu domain.
26 ## </summary>
27 ## <param name="domain">
28 ## <summary>
29 ## Domain allowed to transition.
30 ## </summary>
31 ## </param>
32 #
33 interface(`aiccu_initrc_domtrans',`
34 gen_require(`
35 type aiccu_initrc_exec_t;
36 ')
37
38 init_labeled_script_domtrans($1, aiccu_initrc_exec_t)
39 ')
40
41 ########################################
42 ## <summary>
43 ## Read aiccu PID files.
44 ## </summary>
45 ## <param name="domain">
46 ## <summary>
47 ## Domain allowed access.
48 ## </summary>
49 ## </param>
50 #
51 interface(`aiccu_read_pid_files',`
52 gen_require(`
53 type aiccu_var_run_t;
54 ')
55
56 allow $1 aiccu_var_run_t:file read_file_perms;
57 files_search_pids($1)
58 ')
59
60 ########################################
61 ## <summary>
62 ## Manage aiccu PID files.
63 ## </summary>
64 ## <param name="domain">
65 ## <summary>
66 ## Domain allowed access.
67 ## </summary>
68 ## </param>
69 #
70 interface(`aiccu_manage_var_run',`
71 gen_require(`
72 type aiccu_var_run_t;
73 ')
74
75 manage_dirs_pattern($1, aiccu_var_run_t, aiccu_var_run_t)
76 manage_files_pattern($1, aiccu_var_run_t, aiccu_var_run_t)
77 manage_lnk_files_pattern($1, aiccu_var_run_t, aiccu_var_run_t)
78 files_search_pids($1)
79 ')
80
81
82 ########################################
83 ## <summary>
84 ## All of the rules required to administrate
85 ## an aiccu environment
86 ## </summary>
87 ## <param name="domain">
88 ## <summary>
89 ## Domain allowed access.
90 ## </summary>
91 ## </param>
92 ## <param name="role">
93 ## <summary>
94 ## Role allowed access.
95 ## </summary>
96 ## </param>
97 ## <rolecap/>
98 #
99 interface(`aiccu_admin',`
100 gen_require(`
101 type aiccu_t, aiccu_initrc_exec_t, aiccu_etc_t;
102 type aiccu_var_run_t;
103 ')
104
105 allow $1 aiccu_t:process { ptrace signal_perms };
106 ps_process_pattern($1, aiccu_t)
107
108 aiccu_initrc_domtrans($1)
109 domain_system_change_exemption($1)
110 role_transition $2 aiccu_initrc_exec_t system_r;
111 allow $2 system_r;
112
113 admin_pattern($1, aiccu_etc_t)
114 files_search_etc($1)
115
116 admin_pattern($1, aiccu_var_run_t)
117 files_search_pids($1)
118 ')