blob: ff5359577d058199d067cffc1e3af1bf05f67005 [file] [log] [blame]
Stephen Smalley2dd4e512012-01-04 12:33:27 -05001allow unconfineddomain self:capability_class_set *;
2allow unconfineddomain kernel:security *;
3allow unconfineddomain kernel:system *;
4allow unconfineddomain self:memprotect *;
5allow unconfineddomain domain:process *;
6allow unconfineddomain domain:fd *;
7allow unconfineddomain domain:dir r_dir_perms;
8allow unconfineddomain domain:lnk_file r_file_perms;
9allow unconfineddomain domain:{ fifo_file file } rw_file_perms;
10allow unconfineddomain domain:socket_class_set *;
11allow unconfineddomain domain:ipc_class_set *;
12allow unconfineddomain domain:key *;
13allow unconfineddomain fs_type:filesystem *;
14allow unconfineddomain fs_type:dir_file_class_set *;
15allow unconfineddomain dev_type:dir_file_class_set *;
16allow unconfineddomain file_type:dir_file_class_set *;
17allow unconfineddomain node_type:node *;
18allow unconfineddomain node_type:{ tcp_socket udp_socket } node_bind;
19allow unconfineddomain netif_type:netif *;
20allow unconfineddomain port_type:socket_class_set name_bind;
21allow unconfineddomain port_type:{ tcp_socket dccp_socket } name_connect;
22allow unconfineddomain domain:peer recv;
23allow unconfineddomain domain:binder { call transfer receive };
Stephen Smalley124720a2012-04-04 10:11:16 -040024allow unconfineddomain property_type:property_service set;