08e9660ba32ab47fbb5351f1f174665e9172f71d
[selinux.git] / ut2004 / ut2004.te
1 policy_module(ut2004, 0.1.1)
2
3 require {
4     type interwise_port_t;
5 }
6
7 # File context for the executable process
8 type ut2004_t;
9 type ut2004_exec_t;
10
11 type ut2004_rw_t;
12 files_type(ut2004_rw_t)
13
14 type ut2004_ro_t;
15 files_type(ut2004_ro_t)
16
17 #type ut2004_tmp_t;
18 #files_tmp_file(ut2004_tmp_t)
19
20 init_daemon_domain(ut2004_t, ut2004_exec_t)
21
22 corenet_udp_sendrecv_generic_port(ut2004_t)
23 corenet_udp_bind_generic_port(ut2004_t)
24 corenet_udp_bind_generic_node(ut2004_t)
25
26 allow ut2004_t ut2004_ro_t:dir list_dir_perms;
27 allow ut2004_t ut2004_ro_t:file read_file_perms;
28 #allow ut2004_t ut2004_tmp_t:file manage_file_perms;
29 #allow ut2004_t ut2004_tmp_t:dir manage_dir_perms;
30
31 manage_files_pattern(ut2004_t, ut2004_rw_t, ut2004_rw_t)
32 manage_dirs_pattern(ut2004_t, ut2004_rw_t, ut2004_rw_t)
33 setattr_files_pattern(ut2004_t, ut2004_rw_t, ut2004_rw_t)
34
35 sysnet_dns_name_resolve(ut2004_t)
36 #files_tmp_filetrans(ut2004_t, ut2004_tmp_t, { file dir})
37
38 # The UT2004 default port is labelled interwise_port_t on some
39 # Fedora policies
40 allow ut2004_t interwise_port_t:udp_socket name_bind;