#
# { tcp_socket unix_stream_socket } { connectto newconn acceptfrom }
#
+# tcp_socket name_connect
+#
# { netlink_route_socket netlink_firewall_socket netlink_tcpdiag_socket netlink_xfrm_socket netlink_audit_socket netlink_ip6fw_socket } nlmsg_write
#
+# netlink_audit_socket { nlmsg_relay nlmsg_readpriv }
+#
+# netlink_kobject_uevent_socket *
+#
(( l1 dom l2 ) and ( l1 domby h2 ));
# these access vectors have no MLS restrictions
-# { netif node } { enforce_dest }
+# node enforce_dest
( t1 == mlsprocwrite ));
# these access vectors have no MLS restrictions
-# process { fork sigchld signull noatsecure siginh setrlimit rlimitinh execmem }
+# process { fork sigchld signull noatsecure siginh setrlimit rlimitinh execmem execstack execheap }
#
# these access vectors have no MLS restrictions
-# association { sendto recvfrom }
+# association *
') dnl end enable_mls