blob: ec2df7e044be169f7212ac9efcdffb866007f4c3 [file] [log] [blame]
Lorenzo Colittiab7dfab2013-08-05 15:32:56 +09001# 464xlat daemon
2type clatd, domain;
Stephen Smalleyf3214562014-02-11 09:45:28 -05003permissive_or_unconfined(clatd)
Lorenzo Colittiab7dfab2013-08-05 15:32:56 +09004type clatd_exec, exec_type, file_type;
5
Lorenzo Colittiab7dfab2013-08-05 15:32:56 +09006net_domain(clatd)
Stephen Smalleya770ee52014-02-21 11:08:15 -05007
8# Access objects inherited from netd.
9allow clatd netd:fd use;
10allow clatd netd:fifo_file { read write };
11allow clatd netd:netlink_kobject_uevent_socket { read write };
12allow clatd netd:netlink_nflog_socket { read write };
13allow clatd netd:netlink_route_socket { read write };
14allow clatd netd:udp_socket { read write };
15allow clatd netd:unix_stream_socket { read write };
16
17allow clatd self:capability { net_admin setuid setgid };
18
19# TODO: Run clatd in vpn group to avoid need for this on /dev/tun.
20allow clatd self:capability dac_override;
21
22allow clatd self:netlink_route_socket { create_socket_perms nlmsg_write };
23allow clatd self:tun_socket create_socket_perms;
24allow clatd tun_device:chr_file rw_file_perms;
25allow clatd proc_net:file rw_file_perms;;