blob: 31b7e4f6441fc06b450b3a6580eb1ff1eb6199c9 [file] [log] [blame]
William Robertsdc107232012-07-11 16:46:38 -07001# Label inodes with the fs label.
2genfscon rootfs / u:object_r:rootfs:s0
3# proc labeling can be further refined (longest matching prefix).
4genfscon proc / u:object_r:proc:s0
Robert Craig1bf61c42014-01-07 14:41:47 -05005genfscon proc /net u:object_r:proc_net:s0
hqjiang4c06d272012-07-19 11:07:04 -07006genfscon proc /net/xt_qtaguid/ctrl u:object_r:qtaguid_proc:s0
Nick Kralevichf2c01182014-09-26 10:51:12 -07007genfscon proc /cpuinfo u:object_r:proc_cpuinfo:s0
Stephen Smalley3dad7b62014-03-05 09:50:08 -05008genfscon proc /sysrq-trigger u:object_r:proc_sysrq:s0
Stephen Smalley7adb9992013-12-06 09:31:40 -05009genfscon proc /sys/fs/protected_hardlinks u:object_r:proc_security:s0
10genfscon proc /sys/fs/protected_symlinks u:object_r:proc_security:s0
11genfscon proc /sys/fs/suid_dumpable u:object_r:proc_security:s0
12genfscon proc /sys/kernel/core_pattern u:object_r:usermodehelper:s0
13genfscon proc /sys/kernel/dmesg_restrict u:object_r:proc_security:s0
14genfscon proc /sys/kernel/hotplug u:object_r:usermodehelper:s0
15genfscon proc /sys/kernel/kptr_restrict u:object_r:proc_security:s0
16genfscon proc /sys/kernel/modprobe u:object_r:usermodehelper:s0
17genfscon proc /sys/kernel/modules_disabled u:object_r:proc_security:s0
18genfscon proc /sys/kernel/poweroff_cmd u:object_r:usermodehelper:s0
19genfscon proc /sys/kernel/randomize_va_space u:object_r:proc_security:s0
20genfscon proc /sys/kernel/usermodehelper u:object_r:usermodehelper:s0
Robert Craig529fcbe2014-01-07 13:46:56 -050021genfscon proc /sys/net u:object_r:proc_net:s0
Stephen Smalleye6a7b372013-12-09 13:24:25 -050022genfscon proc /sys/vm/mmap_min_addr u:object_r:proc_security:s0
William Robertsdc107232012-07-11 16:46:38 -070023# selinuxfs booleans can be individually labeled.
24genfscon selinuxfs / u:object_r:selinuxfs:s0
25genfscon cgroup / u:object_r:cgroup:s0
26# sysfs labels can be set by userspace.
27genfscon sysfs / u:object_r:sysfs:s0
28genfscon inotifyfs / u:object_r:inotify:s0
Ed Heyle9c90bd2014-07-14 23:29:21 -070029genfscon vfat / u:object_r:vfat:s0
William Robertsdc107232012-07-11 16:46:38 -070030genfscon debugfs / u:object_r:debugfs:s0
Ed Heyle9c90bd2014-07-14 23:29:21 -070031genfscon fuse / u:object_r:fuse:s0
jaejyn.shin318e0c92014-04-10 13:32:54 +090032genfscon pstore / u:object_r:pstorefs:s0
Nick Kralevich77cc0552014-04-15 14:53:05 -070033genfscon functionfs / u:object_r:functionfs:s0
Nick Kralevich5a5fb852014-06-07 07:31:31 -070034genfscon usbfs / u:object_r:usbfs:s0