Changeset 215
- Timestamp:
- 07/21/08 14:09:54 (4 months ago)
- Files:
-
- branch/RHEL-5.2-20080702merge/src/selinux-policy-clip/policy/modules/admin/amanda.te (modified) (2 diffs)
- branch/RHEL-5.2-20080702merge/src/selinux-policy-clip/policy/modules/admin/apt.te (modified) (1 diff)
- branch/RHEL-5.2-20080702merge/src/selinux-policy-clip/policy/modules/admin/backup.te (modified) (1 diff)
- branch/RHEL-5.2-20080702merge/src/selinux-policy-clip/policy/modules/admin/dpkg.te (modified) (1 diff)
- branch/RHEL-5.2-20080702merge/src/selinux-policy-clip/policy/modules/admin/mrtg.te (modified) (1 diff)
- branch/RHEL-5.2-20080702merge/src/selinux-policy-clip/policy/modules/admin/netutils.te (modified) (2 diffs)
- branch/RHEL-5.2-20080702merge/src/selinux-policy-clip/policy/modules/admin/portage.if (modified) (2 diffs)
- branch/RHEL-5.2-20080702merge/src/selinux-policy-clip/policy/modules/admin/rpm.te (modified) (1 diff)
- branch/RHEL-5.2-20080702merge/src/selinux-policy-clip/policy/modules/admin/vpn.te (modified) (1 diff)
- branch/RHEL-5.2-20080702merge/src/selinux-policy-clip/policy/modules/apps/evolution.if (modified) (1 diff)
- branch/RHEL-5.2-20080702merge/src/selinux-policy-clip/policy/modules/apps/games.if (modified) (1 diff)
- branch/RHEL-5.2-20080702merge/src/selinux-policy-clip/policy/modules/apps/gift.if (modified) (1 diff)
- branch/RHEL-5.2-20080702merge/src/selinux-policy-clip/policy/modules/apps/gpg.if (modified) (2 diffs)
- branch/RHEL-5.2-20080702merge/src/selinux-policy-clip/policy/modules/apps/irc.if (modified) (1 diff)
- branch/RHEL-5.2-20080702merge/src/selinux-policy-clip/policy/modules/apps/java.if (modified) (1 diff)
- branch/RHEL-5.2-20080702merge/src/selinux-policy-clip/policy/modules/apps/qemu.if (modified) (1 diff)
- branch/RHEL-5.2-20080702merge/src/selinux-policy-clip/policy/modules/apps/qemu.te (modified) (1 diff)
- branch/RHEL-5.2-20080702merge/src/selinux-policy-clip/policy/modules/apps/screen.if (modified) (1 diff)
- branch/RHEL-5.2-20080702merge/src/selinux-policy-clip/policy/modules/apps/uml.if (modified) (1 diff)
- branch/RHEL-5.2-20080702merge/src/selinux-policy-clip/policy/modules/apps/vmware.te (modified) (1 diff)
- branch/RHEL-5.2-20080702merge/src/selinux-policy-clip/policy/modules/kernel/kernel.te (modified) (1 diff)
- branch/RHEL-5.2-20080702merge/src/selinux-policy-clip/policy/modules/services/afs.te (modified) (5 diffs)
- branch/RHEL-5.2-20080702merge/src/selinux-policy-clip/policy/modules/services/amavis.te (modified) (1 diff)
- branch/RHEL-5.2-20080702merge/src/selinux-policy-clip/policy/modules/services/apache.if (modified) (1 diff)
- branch/RHEL-5.2-20080702merge/src/selinux-policy-clip/policy/modules/services/apache.te (modified) (3 diffs)
- branch/RHEL-5.2-20080702merge/src/selinux-policy-clip/policy/modules/services/apcupsd.te (modified) (1 diff)
- branch/RHEL-5.2-20080702merge/src/selinux-policy-clip/policy/modules/services/asterisk.te (modified) (1 diff)
- branch/RHEL-5.2-20080702merge/src/selinux-policy-clip/policy/modules/services/automount.te (modified) (1 diff)
- branch/RHEL-5.2-20080702merge/src/selinux-policy-clip/policy/modules/services/avahi.te (modified) (1 diff)
- branch/RHEL-5.2-20080702merge/src/selinux-policy-clip/policy/modules/services/bind.te (modified) (1 diff)
- branch/RHEL-5.2-20080702merge/src/selinux-policy-clip/policy/modules/services/canna.te (modified) (1 diff)
- branch/RHEL-5.2-20080702merge/src/selinux-policy-clip/policy/modules/services/ccs.te (modified) (1 diff)
- branch/RHEL-5.2-20080702merge/src/selinux-policy-clip/policy/modules/services/cipe.te (modified) (1 diff)
- branch/RHEL-5.2-20080702merge/src/selinux-policy-clip/policy/modules/services/clamav.te (modified) (1 diff)
- branch/RHEL-5.2-20080702merge/src/selinux-policy-clip/policy/modules/services/clockspeed.te (modified) (1 diff)
- branch/RHEL-5.2-20080702merge/src/selinux-policy-clip/policy/modules/services/courier.te (modified) (1 diff)
- branch/RHEL-5.2-20080702merge/src/selinux-policy-clip/policy/modules/services/cron.if (modified) (1 diff)
- branch/RHEL-5.2-20080702merge/src/selinux-policy-clip/policy/modules/services/cups.te (modified) (5 diffs)
- branch/RHEL-5.2-20080702merge/src/selinux-policy-clip/policy/modules/services/cyrus.te (modified) (1 diff)
- branch/RHEL-5.2-20080702merge/src/selinux-policy-clip/policy/modules/services/dante.te (modified) (1 diff)
- branch/RHEL-5.2-20080702merge/src/selinux-policy-clip/policy/modules/services/dbus.if (modified) (1 diff)
- branch/RHEL-5.2-20080702merge/src/selinux-policy-clip/policy/modules/services/dcc.te (modified) (1 diff)
- branch/RHEL-5.2-20080702merge/src/selinux-policy-clip/policy/modules/services/ddclient.te (modified) (1 diff)
- branch/RHEL-5.2-20080702merge/src/selinux-policy-clip/policy/modules/services/dhcp.te (modified) (1 diff)
- branch/RHEL-5.2-20080702merge/src/selinux-policy-clip/policy/modules/services/dictd.te (modified) (1 diff)
- branch/RHEL-5.2-20080702merge/src/selinux-policy-clip/policy/modules/services/distcc.te (modified) (1 diff)
- branch/RHEL-5.2-20080702merge/src/selinux-policy-clip/policy/modules/services/djbdns.if (modified) (1 diff)
- branch/RHEL-5.2-20080702merge/src/selinux-policy-clip/policy/modules/services/dnsmasq.te (modified) (1 diff)
- branch/RHEL-5.2-20080702merge/src/selinux-policy-clip/policy/modules/services/dovecot.te (modified) (1 diff)
- branch/RHEL-5.2-20080702merge/src/selinux-policy-clip/policy/modules/services/exim.te (modified) (1 diff)
- branch/RHEL-5.2-20080702merge/src/selinux-policy-clip/policy/modules/services/fetchmail.te (modified) (1 diff)
- branch/RHEL-5.2-20080702merge/src/selinux-policy-clip/policy/modules/services/finger.te (modified) (1 diff)
- branch/RHEL-5.2-20080702merge/src/selinux-policy-clip/policy/modules/services/ftp.te (modified) (2 diffs)
- branch/RHEL-5.2-20080702merge/src/selinux-policy-clip/policy/modules/services/gatekeeper.te (modified) (1 diff)
- branch/RHEL-5.2-20080702merge/src/selinux-policy-clip/policy/modules/services/howl.te (modified) (1 diff)
- branch/RHEL-5.2-20080702merge/src/selinux-policy-clip/policy/modules/services/i18n_input.te (modified) (1 diff)
- branch/RHEL-5.2-20080702merge/src/selinux-policy-clip/policy/modules/services/imaze.te (modified) (1 diff)
- branch/RHEL-5.2-20080702merge/src/selinux-policy-clip/policy/modules/services/inetd.te (modified) (1 diff)
- branch/RHEL-5.2-20080702merge/src/selinux-policy-clip/policy/modules/services/inn.te (modified) (1 diff)
- branch/RHEL-5.2-20080702merge/src/selinux-policy-clip/policy/modules/services/ircd.te (modified) (1 diff)
- branch/RHEL-5.2-20080702merge/src/selinux-policy-clip/policy/modules/services/jabber.te (modified) (1 diff)
- branch/RHEL-5.2-20080702merge/src/selinux-policy-clip/policy/modules/services/kerberos.if (modified) (1 diff)
- branch/RHEL-5.2-20080702merge/src/selinux-policy-clip/policy/modules/services/kerberos.te (modified) (2 diffs)
- branch/RHEL-5.2-20080702merge/src/selinux-policy-clip/policy/modules/services/ldap.te (modified) (1 diff)
- branch/RHEL-5.2-20080702merge/src/selinux-policy-clip/policy/modules/services/lpd.if (modified) (1 diff)
- branch/RHEL-5.2-20080702merge/src/selinux-policy-clip/policy/modules/services/lpd.te (modified) (2 diffs)
- branch/RHEL-5.2-20080702merge/src/selinux-policy-clip/policy/modules/services/mailman.if (modified) (1 diff)
- branch/RHEL-5.2-20080702merge/src/selinux-policy-clip/policy/modules/services/monop.te (modified) (1 diff)
- branch/RHEL-5.2-20080702merge/src/selinux-policy-clip/policy/modules/services/mta.if (modified) (1 diff)
- branch/RHEL-5.2-20080702merge/src/selinux-policy-clip/policy/modules/services/mysql.te (modified) (1 diff)
- branch/RHEL-5.2-20080702merge/src/selinux-policy-clip/policy/modules/services/nagios.te (modified) (1 diff)
- branch/RHEL-5.2-20080702merge/src/selinux-policy-clip/policy/modules/services/nessus.te (modified) (1 diff)
- branch/RHEL-5.2-20080702merge/src/selinux-policy-clip/policy/modules/services/networkmanager.te (modified) (1 diff)
- branch/RHEL-5.2-20080702merge/src/selinux-policy-clip/policy/modules/services/nis.if (modified) (1 diff)
- branch/RHEL-5.2-20080702merge/src/selinux-policy-clip/policy/modules/services/nis.te (modified) (5 diffs)
- branch/RHEL-5.2-20080702merge/src/selinux-policy-clip/policy/modules/services/nscd.te (modified) (1 diff)
- branch/RHEL-5.2-20080702merge/src/selinux-policy-clip/policy/modules/services/nsd.te (modified) (2 diffs)
- branch/RHEL-5.2-20080702merge/src/selinux-policy-clip/policy/modules/services/ntp.te (modified) (1 diff)
- branch/RHEL-5.2-20080702merge/src/selinux-policy-clip/policy/modules/services/nx.te (modified) (1 diff)
- branch/RHEL-5.2-20080702merge/src/selinux-policy-clip/policy/modules/services/openvpn.te (modified) (1 diff)
- branch/RHEL-5.2-20080702merge/src/selinux-policy-clip/policy/modules/services/pegasus.te (modified) (1 diff)
- branch/RHEL-5.2-20080702merge/src/selinux-policy-clip/policy/modules/services/perdition.te (modified) (1 diff)
- branch/RHEL-5.2-20080702merge/src/selinux-policy-clip/policy/modules/services/portmap.te (modified) (2 diffs)
- branch/RHEL-5.2-20080702merge/src/selinux-policy-clip/policy/modules/services/postfix.if (modified) (1 diff)
- branch/RHEL-5.2-20080702merge/src/selinux-policy-clip/policy/modules/services/postfix.te (modified) (2 diffs)
- branch/RHEL-5.2-20080702merge/src/selinux-policy-clip/policy/modules/services/postfixpolicyd.te (modified) (1 diff)
- branch/RHEL-5.2-20080702merge/src/selinux-policy-clip/policy/modules/services/postgresql.te (modified) (1 diff)
- branch/RHEL-5.2-20080702merge/src/selinux-policy-clip/policy/modules/services/postgrey.te (modified) (1 diff)
- branch/RHEL-5.2-20080702merge/src/selinux-policy-clip/policy/modules/services/ppp.te (modified) (1 diff)
- branch/RHEL-5.2-20080702merge/src/selinux-policy-clip/policy/modules/services/prelude.te (modified) (2 diffs)
- branch/RHEL-5.2-20080702merge/src/selinux-policy-clip/policy/modules/services/privoxy.te (modified) (1 diff)
- branch/RHEL-5.2-20080702merge/src/selinux-policy-clip/policy/modules/services/procmail.te (modified) (1 diff)
- branch/RHEL-5.2-20080702merge/src/selinux-policy-clip/policy/modules/services/pyzor.te (modified) (1 diff)
- branch/RHEL-5.2-20080702merge/src/selinux-policy-clip/policy/modules/services/radius.te (modified) (1 diff)
- branch/RHEL-5.2-20080702merge/src/selinux-policy-clip/policy/modules/services/rhgb.te (modified) (1 diff)
- branch/RHEL-5.2-20080702merge/src/selinux-policy-clip/policy/modules/services/ricci.te (modified) (2 diffs)
- branch/RHEL-5.2-20080702merge/src/selinux-policy-clip/policy/modules/services/roundup.te (modified) (1 diff)
- branch/RHEL-5.2-20080702merge/src/selinux-policy-clip/policy/modules/services/rpc.if (modified) (1 diff)
- branch/RHEL-5.2-20080702merge/src/selinux-policy-clip/policy/modules/services/rpcbind.te (modified) (1 diff)
- branch/RHEL-5.2-20080702merge/src/selinux-policy-clip/policy/modules/services/rshd.te (modified) (1 diff)
- branch/RHEL-5.2-20080702merge/src/selinux-policy-clip/policy/modules/services/rsync.te (modified) (1 diff)
- branch/RHEL-5.2-20080702merge/src/selinux-policy-clip/policy/modules/services/rwho.te (modified) (1 diff)
- branch/RHEL-5.2-20080702merge/src/selinux-policy-clip/policy/modules/services/samba.te (modified) (5 diffs)
- branch/RHEL-5.2-20080702merge/src/selinux-policy-clip/policy/modules/services/sendmail.te (modified) (1 diff)
- branch/RHEL-5.2-20080702merge/src/selinux-policy-clip/policy/modules/services/setroubleshoot.te (modified) (1 diff)
- branch/RHEL-5.2-20080702merge/src/selinux-policy-clip/policy/modules/services/snmp.te (modified) (1 diff)
- branch/RHEL-5.2-20080702merge/src/selinux-policy-clip/policy/modules/services/soundserver.te (modified) (1 diff)
- branch/RHEL-5.2-20080702merge/src/selinux-policy-clip/policy/modules/services/spamassassin.if (modified) (2 diffs)
- branch/RHEL-5.2-20080702merge/src/selinux-policy-clip/policy/modules/services/spamassassin.te (modified) (2 diffs)
- branch/RHEL-5.2-20080702merge/src/selinux-policy-clip/policy/modules/services/squid.te (modified) (2 diffs)
- branch/RHEL-5.2-20080702merge/src/selinux-policy-clip/policy/modules/services/ssh.if (modified) (1 diff)
- branch/RHEL-5.2-20080702merge/src/selinux-policy-clip/policy/modules/services/stunnel.te (modified) (1 diff)
- branch/RHEL-5.2-20080702merge/src/selinux-policy-clip/policy/modules/services/tftp.te (modified) (1 diff)
- branch/RHEL-5.2-20080702merge/src/selinux-policy-clip/policy/modules/services/tor.te (modified) (1 diff)
- branch/RHEL-5.2-20080702merge/src/selinux-policy-clip/policy/modules/services/transproxy.te (modified) (1 diff)
- branch/RHEL-5.2-20080702merge/src/selinux-policy-clip/policy/modules/services/ucspitcp.te (modified) (2 diffs)
- branch/RHEL-5.2-20080702merge/src/selinux-policy-clip/policy/modules/services/uwimap.te (modified) (1 diff)
- branch/RHEL-5.2-20080702merge/src/selinux-policy-clip/policy/modules/services/virt.te (modified) (1 diff)
- branch/RHEL-5.2-20080702merge/src/selinux-policy-clip/policy/modules/services/watchdog.te (modified) (1 diff)
- branch/RHEL-5.2-20080702merge/src/selinux-policy-clip/policy/modules/services/xfs.te (modified) (1 diff)
- branch/RHEL-5.2-20080702merge/src/selinux-policy-clip/policy/modules/services/xserver.if (modified) (1 diff)
- branch/RHEL-5.2-20080702merge/src/selinux-policy-clip/policy/modules/services/xserver.te (modified) (1 diff)
- branch/RHEL-5.2-20080702merge/src/selinux-policy-clip/policy/modules/services/zebra.te (modified) (1 diff)
- branch/RHEL-5.2-20080702merge/src/selinux-policy-clip/policy/modules/system/init.te (modified) (1 diff)
- branch/RHEL-5.2-20080702merge/src/selinux-policy-clip/policy/modules/system/ipsec.te (modified) (2 diffs)
- branch/RHEL-5.2-20080702merge/src/selinux-policy-clip/policy/modules/system/logging.te (modified) (2 diffs)
- branch/RHEL-5.2-20080702merge/src/selinux-policy-clip/policy/modules/system/lvm.te (modified) (1 diff)
- branch/RHEL-5.2-20080702merge/src/selinux-policy-clip/policy/modules/system/mount.te (modified) (2 diffs)
- branch/RHEL-5.2-20080702merge/src/selinux-policy-clip/policy/modules/system/sysnetwork.te (modified) (1 diff)
- branch/RHEL-5.2-20080702merge/src/selinux-policy-clip/policy/modules/system/userdomain.if (modified) (3 diffs)
- branch/RHEL-5.2-20080702merge/src/selinux-policy-clip/policy/modules/system/xen.te (modified) (1 diff)
Legend:
- Unmodified
- Added
- Removed
- Modified
- Copied
- Moved
branch/RHEL-5.2-20080702merge/src/selinux-policy-clip/policy/modules/admin/amanda.te
r214 r215 126 126 corenet_tcp_sendrecv_generic_port(amanda_t) 127 127 corenet_udp_sendrecv_generic_port(amanda_t) 128 corenet_tcp_bind_ all_nodes(amanda_t)129 corenet_udp_bind_ all_nodes(amanda_t)128 corenet_tcp_bind_generic_node(amanda_t) 129 corenet_udp_bind_generic_node(amanda_t) 130 130 corenet_tcp_bind_all_rpc_ports(amanda_t) 131 131 … … 205 205 corenet_tcp_sendrecv_generic_port(amanda_recover_t) 206 206 corenet_udp_sendrecv_generic_port(amanda_recover_t) 207 corenet_tcp_bind_ all_nodes(amanda_recover_t)208 corenet_udp_bind_ all_nodes(amanda_recover_t)207 corenet_tcp_bind_generic_node(amanda_recover_t) 208 corenet_udp_bind_generic_node(amanda_recover_t) 209 209 corenet_tcp_bind_reserved_port(amanda_recover_t) 210 210 corenet_tcp_connect_amanda_port(amanda_recover_t) branch/RHEL-5.2-20080702merge/src/selinux-policy-clip/policy/modules/admin/apt.te
r214 r215 89 89 corenet_udp_sendrecv_generic_port(apt_t) 90 90 # TODO: reall allow all these? 91 corenet_tcp_bind_ all_nodes(apt_t)92 corenet_udp_bind_ all_nodes(apt_t)93 corenet_tcp_connect_ all_ports(apt_t)94 corenet_sendrecv_ all_client_packets(apt_t)91 corenet_tcp_bind_generic_node(apt_t) 92 corenet_udp_bind_generic_node(apt_t) 93 corenet_tcp_connect_generic_port(apt_t) 94 corenet_sendrecv_generic_client_packets(apt_t) 95 95 96 96 dev_read_urand(apt_t) branch/RHEL-5.2-20080702merge/src/selinux-policy-clip/policy/modules/admin/backup.te
r214 r215 48 48 corenet_tcp_sendrecv_generic_port(backup_t) 49 49 corenet_udp_sendrecv_generic_port(backup_t) 50 corenet_tcp_connect_ all_ports(backup_t)51 corenet_sendrecv_ all_client_packets(backup_t)50 corenet_tcp_connect_generic_port(backup_t) 51 corenet_sendrecv_generic_client_packets(backup_t) 52 52 53 53 dev_getattr_all_blk_files(backup_t) branch/RHEL-5.2-20080702merge/src/selinux-policy-clip/policy/modules/admin/dpkg.te
r214 r215 101 101 corenet_tcp_sendrecv_generic_port(dpkg_t) 102 102 corenet_udp_sendrecv_generic_port(dpkg_t) 103 corenet_tcp_connect_ all_ports(dpkg_t)104 corenet_sendrecv_ all_client_packets(dpkg_t)103 corenet_tcp_connect_generic_port(dpkg_t) 104 corenet_sendrecv_generic_client_packets(dpkg_t) 105 105 106 106 dev_list_sysfs(dpkg_t) branch/RHEL-5.2-20080702merge/src/selinux-policy-clip/policy/modules/admin/mrtg.te
r214 r215 72 72 corenet_tcp_sendrecv_generic_port(mrtg_t) 73 73 corenet_udp_sendrecv_generic_port(mrtg_t) 74 corenet_tcp_connect_ all_ports(mrtg_t)75 corenet_sendrecv_ all_client_packets(mrtg_t)74 corenet_tcp_connect_generic_port(mrtg_t) 75 corenet_sendrecv_generic_client_packets(mrtg_t) 76 76 77 77 dev_read_sysfs(mrtg_t) branch/RHEL-5.2-20080702merge/src/selinux-policy-clip/policy/modules/admin/netutils.te
r214 r215 62 62 corenet_tcp_sendrecv_generic_port(netutils_t) 63 63 corenet_udp_sendrecv_generic_port(netutils_t) 64 corenet_tcp_connect_ all_ports(netutils_t)65 corenet_sendrecv_ all_client_packets(netutils_t)64 corenet_tcp_connect_generic_port(netutils_t) 65 corenet_sendrecv_generic_client_packets(netutils_t) 66 66 corenet_udp_bind_generic_node(netutils_t) 67 67 … … 183 183 corenet_tcp_sendrecv_generic_port(traceroute_t) 184 184 corenet_udp_sendrecv_generic_port(traceroute_t) 185 corenet_udp_bind_ all_nodes(traceroute_t)186 corenet_tcp_bind_ all_nodes(traceroute_t)185 corenet_udp_bind_generic_node(traceroute_t) 186 corenet_tcp_bind_generic_node(traceroute_t) 187 187 # traceroute needs this but not tracepath 188 188 corenet_raw_bind_all_nodes(traceroute_t) 189 189 corenet_udp_bind_traceroute_port(traceroute_t) 190 corenet_tcp_connect_ all_ports(traceroute_t)191 corenet_sendrecv_ all_client_packets(traceroute_t)190 corenet_tcp_connect_generic_port(traceroute_t) 191 corenet_sendrecv_generic_client_packets(traceroute_t) 192 192 corenet_sendrecv_traceroute_server_packets(traceroute_t) 193 193 branch/RHEL-5.2-20080702merge/src/selinux-policy-clip/policy/modules/admin/portage.if
r214 r215 165 165 corenet_tcp_sendrecv_generic_port($1) 166 166 corenet_udp_sendrecv_generic_port($1) 167 corenet_tcp_connect_ all_reserved_ports($1)167 corenet_tcp_connect_reserved_port($1) 168 168 corenet_tcp_connect_distccd_port($1) 169 169 … … 257 257 # would rather not connect to unspecified ports, but 258 258 # it occasionally comes up 259 corenet_tcp_connect_ all_reserved_ports($1)259 corenet_tcp_connect_reserved_port($1) 260 260 corenet_tcp_connect_generic_port($1) 261 261 branch/RHEL-5.2-20080702merge/src/selinux-policy-clip/policy/modules/admin/rpm.te
r214 r215 105 105 corenet_tcp_sendrecv_generic_port(rpm_t) 106 106 corenet_udp_sendrecv_generic_port(rpm_t) 107 corenet_tcp_connect_ all_ports(rpm_t)108 corenet_sendrecv_ all_client_packets(rpm_t)107 corenet_tcp_connect_generic_port(rpm_t) 108 corenet_sendrecv_generic_client_packets(rpm_t) 109 109 110 110 dev_list_sysfs(rpm_t) branch/RHEL-5.2-20080702merge/src/selinux-policy-clip/policy/modules/admin/vpn.te
r214 r215 57 57 corenet_tcp_sendrecv_generic_port(vpnc_t) 58 58 corenet_udp_sendrecv_generic_port(vpnc_t) 59 corenet_udp_bind_ all_nodes(vpnc_t)59 corenet_udp_bind_generic_node(vpnc_t) 60 60 corenet_udp_bind_generic_port(vpnc_t) 61 61 corenet_udp_bind_isakmp_port(vpnc_t) 62 62 corenet_udp_bind_ipsecnat_port(vpnc_t) 63 corenet_tcp_connect_ all_ports(vpnc_t)64 corenet_sendrecv_ all_client_packets(vpnc_t)63 corenet_tcp_connect_generic_port(vpnc_t) 64 corenet_sendrecv_generic_client_packets(vpnc_t) 65 65 corenet_sendrecv_isakmp_server_packets(vpnc_t) 66 66 corenet_sendrecv_generic_server_packets(vpnc_t) branch/RHEL-5.2-20080702merge/src/selinux-policy-clip/policy/modules/apps/evolution.if
r214 r215 212 212 corenet_sendrecv_ipp_client_packets($1_evolution_t) 213 213 # not sure about this bind 214 corenet_udp_bind_ all_nodes($1_evolution_t)214 corenet_udp_bind_generic_node($1_evolution_t) 215 215 corenet_udp_bind_generic_port($1_evolution_t) 216 216 branch/RHEL-5.2-20080702merge/src/selinux-policy-clip/policy/modules/apps/games.if
r214 r215 100 100 corenet_tcp_sendrecv_generic_port($1_games_t) 101 101 corenet_udp_sendrecv_generic_port($1_games_t) 102 corenet_tcp_bind_ all_nodes($1_games_t)102 corenet_tcp_bind_generic_node($1_games_t) 103 103 corenet_tcp_bind_generic_port($1_games_t) 104 104 corenet_tcp_connect_generic_port($1_games_t) branch/RHEL-5.2-20080702merge/src/selinux-policy-clip/policy/modules/apps/gift.if
r214 r215 163 163 corenet_tcp_sendrecv_generic_port($1_giftd_t) 164 164 corenet_udp_sendrecv_generic_port($1_giftd_t) 165 corenet_tcp_bind_ all_nodes($1_giftd_t)166 corenet_udp_bind_ all_nodes($1_giftd_t)167 corenet_tcp_bind_ all_ports($1_giftd_t)168 corenet_udp_bind_ all_ports($1_giftd_t)169 corenet_tcp_connect_ all_ports($1_giftd_t)170 corenet_sendrecv_ all_client_packets($1_giftd_t)165 corenet_tcp_bind_generic_node($1_giftd_t) 166 corenet_udp_bind_generic_node($1_giftd_t) 167 corenet_tcp_bind_generic_port($1_giftd_t) 168 corenet_udp_bind_generic_port($1_giftd_t) 169 corenet_tcp_connect_generic_port($1_giftd_t) 170 corenet_sendrecv_generic_client_packets($1_giftd_t) 171 171 172 172 files_read_usr_files($1_giftd_t) branch/RHEL-5.2-20080702merge/src/selinux-policy-clip/policy/modules/apps/gpg.if
r214 r215 103 103 corenet_tcp_sendrecv_generic_port($1_gpg_t) 104 104 corenet_udp_sendrecv_generic_port($1_gpg_t) 105 corenet_tcp_connect_ all_ports($1_gpg_t)106 corenet_sendrecv_ all_client_packets($1_gpg_t)105 corenet_tcp_connect_generic_port($1_gpg_t) 106 corenet_sendrecv_generic_client_packets($1_gpg_t) 107 107 108 108 dev_read_rand($1_gpg_t) … … 169 169 corenet_tcp_sendrecv_generic_port($1_gpg_helper_t) 170 170 corenet_udp_sendrecv_generic_port($1_gpg_helper_t) 171 corenet_tcp_bind_ all_nodes($1_gpg_helper_t)172 corenet_udp_bind_ all_nodes($1_gpg_helper_t)173 corenet_tcp_connect_ all_ports($1_gpg_helper_t)171 corenet_tcp_bind_generic_node($1_gpg_helper_t) 172 corenet_udp_bind_generic_node($1_gpg_helper_t) 173 corenet_tcp_connect_generic_port($1_gpg_helper_t) 174 174 175 175 dev_read_urand($1_gpg_helper_t) branch/RHEL-5.2-20080702merge/src/selinux-policy-clip/policy/modules/apps/irc.if
r214 r215 100 100 corenet_sendrecv_ircd_client_packets($1_irc_t) 101 101 # cjp: this seems excessive: 102 corenet_tcp_connect_ all_ports($1_irc_t)103 corenet_sendrecv_ all_client_packets($1_irc_t)102 corenet_tcp_connect_generic_port($1_irc_t) 103 corenet_sendrecv_generic_client_packets($1_irc_t) 104 104 105 105 domain_use_interactive_fds($1_irc_t) branch/RHEL-5.2-20080702merge/src/selinux-policy-clip/policy/modules/apps/java.if
r214 r215 105 105 corenet_tcp_sendrecv_generic_port($1_javaplugin_t) 106 106 corenet_udp_sendrecv_generic_port($1_javaplugin_t) 107 corenet_tcp_connect_ all_ports($1_javaplugin_t)108 corenet_sendrecv_ all_client_packets($1_javaplugin_t)107 corenet_tcp_connect_generic_port($1_javaplugin_t) 108 corenet_sendrecv_generic_client_packets($1_javaplugin_t) 109 109 110 110 dev_read_sound($1_javaplugin_t) branch/RHEL-5.2-20080702merge/src/selinux-policy-clip/policy/modules/apps/qemu.if
r214 r215 168 168 corenet_tcp_sendrecv_generic_node($1_t) 169 169 corenet_tcp_sendrecv_generic_port($1_t) 170 corenet_tcp_bind_ all_nodes($1_t)170 corenet_tcp_bind_generic_node($1_t) 171 171 corenet_tcp_bind_vnc_port($1_t) 172 172 corenet_rw_tun_tap_dev($1_t) branch/RHEL-5.2-20080702merge/src/selinux-policy-clip/policy/modules/apps/qemu.te
r214 r215 30 30 corenet_udp_sendrecv_generic_node(qemu_t) 31 31 corenet_udp_sendrecv_generic_port(qemu_t) 32 corenet_udp_bind_ all_nodes(qemu_t)33 corenet_udp_bind_ all_ports(qemu_t)34 corenet_tcp_bind_ all_ports(qemu_t)35 corenet_tcp_connect_ all_ports(qemu_t)32 corenet_udp_bind_generic_node(qemu_t) 33 corenet_udp_bind_generic_port(qemu_t) 34 corenet_tcp_bind_generic_port(qemu_t) 35 corenet_tcp_connect_generic_port(qemu_t) 36 36 ') 37 37 branch/RHEL-5.2-20080702merge/src/selinux-policy-clip/policy/modules/apps/screen.if
r214 r215 119 119 corenet_tcp_sendrecv_generic_port($1_screen_t) 120 120 corenet_udp_sendrecv_generic_port($1_screen_t) 121 corenet_tcp_connect_ all_ports($1_screen_t)121 corenet_tcp_connect_generic_port($1_screen_t) 122 122 123 123 dev_dontaudit_getattr_all_chr_files($1_screen_t) branch/RHEL-5.2-20080702merge/src/selinux-policy-clip/policy/modules/apps/uml.if
r214 r215 159 159 corenet_tcp_sendrecv_generic_port($1_uml_t) 160 160 corenet_udp_sendrecv_generic_port($1_uml_t) 161 corenet_tcp_connect_ all_ports($1_uml_t)162 corenet_sendrecv_ all_client_packets($1_uml_t)161 corenet_tcp_connect_generic_port($1_uml_t) 162 corenet_sendrecv_generic_client_packets($1_uml_t) 163 163 corenet_rw_tun_tap_dev($1_uml_t) 164 164 branch/RHEL-5.2-20080702merge/src/selinux-policy-clip/policy/modules/apps/vmware.te
r214 r215 64 64 corenet_udp_sendrecv_generic_port(vmware_host_t) 65 65 corenet_raw_bind_all_nodes(vmware_host_t) 66 corenet_tcp_bind_ all_nodes(vmware_host_t)67 corenet_udp_bind_ all_nodes(vmware_host_t)68 corenet_tcp_connect_ all_ports(vmware_host_t)69 corenet_sendrecv_ all_client_packets(vmware_host_t)66 corenet_tcp_bind_generic_node(vmware_host_t) 67 corenet_udp_bind_generic_node(vmware_host_t) 68 corenet_tcp_connect_generic_port(vmware_host_t) 69 corenet_sendrecv_generic_client_packets(vmware_host_t) 70 70 corenet_sendrecv_all_server_packets(vmware_host_t) 71 71 branch/RHEL-5.2-20080702merge/src/selinux-policy-clip/policy/modules/kernel/kernel.te
r214 r215 313 313 corenet_udp_sendrecv_generic_node(kernel_t) 314 314 corenet_udp_sendrecv_generic_port(kernel_t) 315 corenet_udp_bind_ all_nodes(kernel_t)315 corenet_udp_bind_generic_node(kernel_t) 316 316 corenet_sendrecv_portmap_client_packets(kernel_t) 317 317 corenet_sendrecv_generic_server_packets(kernel_t) branch/RHEL-5.2-20080702merge/src/selinux-policy-clip/policy/modules/services/afs.te
r214 r215 98 98 corenet_tcp_sendrecv_generic_port(afs_bosserver_t) 99 99 corenet_udp_sendrecv_generic_port(afs_bosserver_t) 100 corenet_udp_bind_ all_nodes(afs_bosserver_t)100 corenet_udp_bind_generic_node(afs_bosserver_t) 101 101 corenet_udp_bind_afs_bos_port(afs_bosserver_t) 102 102 corenet_sendrecv_afs_bos_server_packets(afs_bosserver_t) … … 157 157 corenet_all_recvfrom_unlabeled(afs_fsserver_t) 158 158 corenet_all_recvfrom_netlabel(afs_fsserver_t) 159 corenet_tcp_bind_ all_nodes(afs_fsserver_t)160 corenet_udp_bind_ all_nodes(afs_fsserver_t)159 corenet_tcp_bind_generic_node(afs_fsserver_t) 160 corenet_udp_bind_generic_node(afs_fsserver_t) 161 161 corenet_tcp_bind_afs_fs_port(afs_fsserver_t) 162 162 corenet_udp_bind_afs_fs_port(afs_fsserver_t) … … 216 216 corenet_tcp_sendrecv_generic_port(afs_kaserver_t) 217 217 corenet_udp_sendrecv_generic_port(afs_kaserver_t) 218 corenet_udp_bind_ all_nodes(afs_kaserver_t)218 corenet_udp_bind_generic_node(afs_kaserver_t) 219 219 corenet_udp_bind_afs_ka_port(afs_kaserver_t) 220 220 corenet_udp_bind_kerberos_port(afs_kaserver_t) … … 263 263 corenet_tcp_sendrecv_generic_port(afs_ptserver_t) 264 264 corenet_udp_sendrecv_generic_port(afs_ptserver_t) 265 corenet_udp_bind_ all_nodes(afs_ptserver_t)265 corenet_udp_bind_generic_node(afs_ptserver_t) 266 266 corenet_udp_bind_afs_pt_port(afs_ptserver_t) 267 267 corenet_sendrecv_afs_pt_server_packets(afs_ptserver_t) … … 304 304 corenet_tcp_sendrecv_generic_port(afs_vlserver_t) 305 305 corenet_udp_sendrecv_generic_port(afs_vlserver_t) 306 corenet_udp_bind_ all_nodes(afs_vlserver_t)306 corenet_udp_bind_generic_node(afs_vlserver_t) 307 307 corenet_udp_bind_afs_vl_port(afs_vlserver_t) 308 308 corenet_sendrecv_afs_vl_server_packets(afs_vlserver_t) branch/RHEL-5.2-20080702merge/src/selinux-policy-clip/policy/modules/services/amavis.te
r214 r215 106 106 corenet_tcp_sendrecv_generic_if(amavis_t) 107 107 corenet_tcp_sendrecv_generic_node(amavis_t) 108 corenet_tcp_bind_ all_nodes(amavis_t)109 corenet_udp_bind_ all_nodes(amavis_t)108 corenet_tcp_bind_generic_node(amavis_t) 109 corenet_udp_bind_generic_node(amavis_t) 110 110 # amavis uses well-defined ports 111 111 corenet_tcp_sendrecv_amavisd_recv_port(amavis_t) branch/RHEL-5.2-20080702merge/src/selinux-policy-clip/policy/modules/services/apache.if
r214 r215 210 210 corenet_tcp_sendrecv_generic_port(httpd_$1_script_t) 211 211 corenet_udp_sendrecv_generic_port(httpd_$1_script_t) 212 corenet_tcp_connect_ all_ports(httpd_$1_script_t)213 corenet_sendrecv_ all_client_packets(httpd_$1_script_t)212 corenet_tcp_connect_generic_port(httpd_$1_script_t) 213 corenet_sendrecv_generic_client_packets(httpd_$1_script_t) 214 214 215 215 sysnet_read_config(httpd_$1_script_t) branch/RHEL-5.2-20080702merge/src/selinux-policy-clip/policy/modules/services/apache.te
r214 r215 299 299 corenet_tcp_sendrecv_generic_port(httpd_t) 300 300 corenet_udp_sendrecv_generic_port(httpd_t) 301 corenet_tcp_bind_ all_nodes(httpd_t)301 corenet_tcp_bind_generic_node(httpd_t) 302 302 corenet_tcp_bind_http_port(httpd_t) 303 303 corenet_tcp_bind_http_cache_port(httpd_t) … … 368 368 369 369 tunable_policy(`httpd_can_network_connect',` 370 corenet_tcp_connect_ all_ports(httpd_t)370 corenet_tcp_connect_generic_port(httpd_t) 371 371 ') 372 372 … … 631 631 corenet_tcp_sendrecv_generic_port(httpd_suexec_t) 632 632 corenet_udp_sendrecv_generic_port(httpd_suexec_t) 633 corenet_tcp_connect_ all_ports(httpd_suexec_t)634 corenet_sendrecv_ all_client_packets(httpd_suexec_t)633 corenet_tcp_connect_generic_port(httpd_suexec_t) 634 corenet_sendrecv_generic_client_packets(httpd_suexec_t) 635 635 ') 636 636 branch/RHEL-5.2-20080702merge/src/selinux-policy-clip/policy/modules/services/apcupsd.te
r214 r215 57 57 corenet_tcp_sendrecv_generic_node(apcupsd_t) 58 58 corenet_tcp_sendrecv_generic_port(apcupsd_t) 59 corenet_tcp_bind_ all_nodes(apcupsd_t)59 corenet_tcp_bind_generic_node(apcupsd_t) 60 60 corenet_tcp_bind_apcupsd_port(apcupsd_t) 61 61 corenet_sendrecv_apcupsd_server_packets(apcupsd_t) branch/RHEL-5.2-20080702merge/src/selinux-policy-clip/policy/modules/services/asterisk.te
r214 r215 91 91 corenet_tcp_sendrecv_generic_port(asterisk_t) 92 92 corenet_udp_sendrecv_generic_port(asterisk_t) 93 corenet_tcp_bind_ all_nodes(asterisk_t)94 corenet_udp_bind_ all_nodes(asterisk_t)93 corenet_tcp_bind_generic_node(asterisk_t) 94 corenet_udp_bind_generic_node(asterisk_t) 95 95 corenet_tcp_bind_asterisk_port(asterisk_t) 96 96 corenet_udp_bind_asterisk_port(asterisk_t) branch/RHEL-5.2-20080702merge/src/selinux-policy-clip/policy/modules/services/automount.te
r214 r215 85 85 corenet_tcp_sendrecv_generic_port(automount_t) 86 86 corenet_udp_sendrecv_generic_port(automount_t) 87
