]> git.ipfire.org Git - people/stevee/selinux-policy.git/blame - policy/modules/admin/backup.te
Remove module for amtu.
[people/stevee/selinux-policy.git] / policy / modules / admin / backup.te
CommitLineData
9570b288 1policy_module(backup, 1.5.0)
57f233b0
CP
2
3########################################
4#
5# Declarations
6#
7
8type backup_t;
9type backup_exec_t;
10domain_type(backup_t)
0bfccda4 11domain_entry_file(backup_t, backup_exec_t)
57f233b0
CP
12role system_r types backup_t;
13
14type backup_store_t;
15files_type(backup_store_t)
16
17########################################
18#
19# Local policy
20#
21
22allow backup_t self:capability dac_override;
23allow backup_t self:process signal;
c0868a7a 24allow backup_t self:fifo_file rw_fifo_file_perms;
57f233b0
CP
25allow backup_t self:tcp_socket create_socket_perms;
26allow backup_t self:udp_socket create_socket_perms;
27
c0868a7a 28allow backup_t backup_store_t:file setattr;
0bfccda4
CP
29manage_files_pattern(backup_t, backup_store_t, backup_store_t)
30rw_files_pattern(backup_t, backup_store_t, backup_store_t)
31read_lnk_files_pattern(backup_t, backup_store_t, backup_store_t)
57f233b0
CP
32
33kernel_read_system_state(backup_t)
34kernel_read_kernel_sysctls(backup_t)
35
36corecmd_exec_bin(backup_t)
45b56b01 37corecmd_exec_shell(backup_t)
57f233b0 38
19006686
CP
39corenet_all_recvfrom_unlabeled(backup_t)
40corenet_all_recvfrom_netlabel(backup_t)
57f233b0
CP
41corenet_tcp_sendrecv_generic_if(backup_t)
42corenet_udp_sendrecv_generic_if(backup_t)
43corenet_raw_sendrecv_generic_if(backup_t)
c1262146
CP
44corenet_tcp_sendrecv_generic_node(backup_t)
45corenet_udp_sendrecv_generic_node(backup_t)
46corenet_raw_sendrecv_generic_node(backup_t)
57f233b0
CP
47corenet_tcp_sendrecv_all_ports(backup_t)
48corenet_udp_sendrecv_all_ports(backup_t)
57f233b0 49corenet_tcp_connect_all_ports(backup_t)
9d0c9b3e 50corenet_sendrecv_all_client_packets(backup_t)
57f233b0
CP
51
52dev_getattr_all_blk_files(backup_t)
53dev_getattr_all_chr_files(backup_t)
54# for SSP
55dev_read_urand(backup_t)
56
57domain_use_interactive_fds(backup_t)
58
59files_read_all_files(backup_t)
60files_read_all_symlinks(backup_t)
61files_getattr_all_pipes(backup_t)
62files_getattr_all_sockets(backup_t)
63
64fs_getattr_xattr_fs(backup_t)
65fs_list_all(backup_t)
66
67auth_read_shadow(backup_t)
68
57f233b0
CP
69logging_send_syslog_msg(backup_t)
70
71sysnet_read_config(backup_t)
72
af2d8802 73userdom_use_inherited_user_terminals(backup_t)
296273a7 74
57f233b0 75optional_policy(`
0bfccda4 76 cron_system_entry(backup_t, backup_exec_t)
57f233b0
CP
77')
78
79optional_policy(`
80 hostname_exec(backup_t)
81')
82
83optional_policy(`
84 nis_use_ypbind(backup_t)
85')