blob: b10cecdaab3df2c0e5b3f6e9342e42af19967491 [file] [log] [blame]
Stephen Smalley2dd4e512012-01-04 12:33:27 -05001# Network types
2type node, node_type;
3type netif, netif_type;
4type port, port_type;
Stephen Smalleyca0759b2013-09-30 15:07:55 -04005
6# Use network sockets.
7allow netdomain self:{ tcp_socket udp_socket } *;
8# Connect to ports.
9allow netdomain port_type:tcp_socket name_connect;
10# Bind to ports.
11allow netdomain node_type:{ tcp_socket udp_socket } node_bind;
12allow netdomain port_type:udp_socket name_bind;
13allow netdomain port_type:tcp_socket name_bind;
14# Get route information.
15allow netdomain self:netlink_route_socket { create bind read nlmsg_read };
16
17# Talks to netd via dnsproxyd socket.
18unix_socket_connect(netdomain, dnsproxyd, netd)