Changeset 216
- Timestamp:
- 07/23/08 13:59:39
(4 months ago)
- Author:
- jmowery
- Message:
adding back several networking permissions that were covered by all (now with specific calls instead)
patch also contains a few (autocorrected) whitespace changes
-
Files:
-
Legend:
- Unmodified
- Added
- Removed
- Modified
- Copied
- Moved
| r215 |
r216 |
|
| 142 | 142 | corenet_raw_sendrecv_generic_node(cupsd_t) |
|---|
| 143 | 143 | corenet_tcp_sendrecv_generic_port(cupsd_t) |
|---|
| | 144 | corenet_tcp_sendrecv_ipp_port(cupsd_t) |
|---|
| | 145 | corenet_tcp_sendrecv_reserved_port(cupsd_t) |
|---|
| 144 | 146 | corenet_udp_sendrecv_generic_port(cupsd_t) |
|---|
| | 147 | corenet_udp_sendrecv_ipp_port(cupsd_t) |
|---|
| 145 | 148 | corenet_tcp_bind_generic_node(cupsd_t) |
|---|
| 146 | 149 | corenet_udp_bind_generic_node(cupsd_t) |
|---|
| … | … | |
| 150 | 153 | corenet_dontaudit_tcp_bind_all_reserved_ports(cupsd_t) |
|---|
| 151 | 154 | corenet_tcp_connect_generic_port(cupsd_t) |
|---|
| | 155 | corenet_tcp_connect_ipp_port(cupsd_t) |
|---|
| | 156 | corenet_tcp_connect_reserved_port(cupsd_t) |
|---|
| 152 | 157 | corenet_sendrecv_hplip_client_packets(cupsd_t) |
|---|
| 153 | 158 | corenet_sendrecv_ipp_client_packets(cupsd_t) |
|---|
| … | … | |
| 301 | 306 | files_var_filetrans(cupsd_config_t,cupsd_rw_etc_t,file) |
|---|
| 302 | 307 | |
|---|
| 303 | | can_exec(cupsd_config_t, cupsd_config_exec_t) |
|---|
| | 308 | can_exec(cupsd_config_t, cupsd_config_exec_t) |
|---|
| 304 | 309 | |
|---|
| 305 | 310 | allow cupsd_config_t cupsd_log_t:file rw_file_perms; |
|---|
| … | … | |
| 457 | 462 | corenet_udp_sendrecv_generic_node(cupsd_lpd_t) |
|---|
| 458 | 463 | corenet_tcp_sendrecv_generic_port(cupsd_lpd_t) |
|---|
| | 464 | corenet_tcp_sendrecv_ipp_port(cupsd_lpd_t) |
|---|
| 459 | 465 | corenet_udp_sendrecv_generic_port(cupsd_lpd_t) |
|---|
| 460 | 466 | corenet_tcp_bind_generic_node(cupsd_lpd_t) |
|---|
| … | … | |
| 525 | 531 | corenet_raw_sendrecv_generic_node(hplip_t) |
|---|
| 526 | 532 | corenet_tcp_sendrecv_generic_port(hplip_t) |
|---|
| | 533 | corenet_tcp_sendrecv_ipp_port(hplip_t) |
|---|
| 527 | 534 | corenet_udp_sendrecv_generic_port(hplip_t) |
|---|
| 528 | 535 | corenet_tcp_bind_generic_node(hplip_t) |
|---|
| … | … | |
| 530 | 537 | corenet_tcp_bind_hplip_port(hplip_t) |
|---|
| 531 | 538 | corenet_tcp_connect_hplip_port(hplip_t) |
|---|
| | 539 | corenet_tcp_sendrecv_hplip_port(hplip_t) |
|---|
| 532 | 540 | corenet_tcp_connect_ipp_port(hplip_t) |
|---|
| 533 | 541 | corenet_sendrecv_hplip_client_packets(hplip_t) |
|---|
| … | … | |
| 614 | 622 | corenet_tcp_sendrecv_generic_node(ptal_t) |
|---|
| 615 | 623 | corenet_tcp_sendrecv_generic_port(ptal_t) |
|---|
| | 624 | corenet_tcp_sendrecv_ptal_port(ptal_t) |
|---|
| 616 | 625 | corenet_tcp_bind_generic_node(ptal_t) |
|---|
| 617 | 626 | corenet_tcp_bind_ptal_port(ptal_t) |
|---|
| r215 |
r216 |
|
| 161 | 161 | corenet_udp_sendrecv_generic_node(lpd_t) |
|---|
| 162 | 162 | corenet_tcp_sendrecv_generic_port(lpd_t) |
|---|
| | 163 | corenet_tcp_sendrecv_printer_port(lpd_t) |
|---|
| 163 | 164 | corenet_udp_sendrecv_generic_port(lpd_t) |
|---|
| 164 | 165 | corenet_tcp_bind_generic_node(lpd_t) |
|---|
| r215 |
r216 |
|
| 77 | 77 | corenet_tcp_sendrecv_generic_node($1_mail_t) |
|---|
| 78 | 78 | corenet_tcp_sendrecv_generic_port($1_mail_t) |
|---|
| | 79 | corenet_tcp_sendrecv_smtp_port($1_mail_t) |
|---|
| 79 | 80 | corenet_tcp_connect_generic_port($1_mail_t) |
|---|
| 80 | 81 | corenet_tcp_connect_smtp_port($1_mail_t) |
|---|
| … | … | |
| 687 | 688 | ####################################### |
|---|
| 688 | 689 | ## <summary> |
|---|
| 689 | | ## Create private objects in the |
|---|
| | 690 | ## Create private objects in the |
|---|
| 690 | 691 | ## mail spool directory. |
|---|
| 691 | 692 | ## </summary> |
|---|
| r215 |
r216 |
|
| 70 | 70 | corenet_tcp_sendrecv_generic_port(ntpd_t) |
|---|
| 71 | 71 | corenet_udp_sendrecv_generic_port(ntpd_t) |
|---|
| | 72 | corenet_tcp_sendrecv_ntp_port(ntpd_t) |
|---|
| | 73 | corenet_udp_sendrecv_ntp_port(ntpd_t) |
|---|
| 72 | 74 | corenet_tcp_bind_generic_node(ntpd_t) |
|---|
| 73 | 75 | corenet_udp_bind_generic_node(ntpd_t) |
|---|
| r215 |
r216 |
|
| 126 | 126 | corenet_tcp_sendrecv_generic_node(ricci_t) |
|---|
| 127 | 127 | corenet_tcp_sendrecv_generic_port(ricci_t) |
|---|
| | 128 | corenet_tcp_sendrecv_ricci_port(ricci_t) |
|---|
| | 129 | corenet_tcp_sendrecv_http_port(ricci_t) |
|---|
| 128 | 130 | corenet_tcp_bind_generic_node(ricci_t) |
|---|
| 129 | 131 | corenet_udp_bind_generic_node(ricci_t) |
|---|
| … | … | |
| 290 | 292 | corenet_tcp_sendrecv_generic_if(ricci_modclusterd_t) |
|---|
| 291 | 293 | corenet_tcp_sendrecv_generic_port(ricci_modclusterd_t) |
|---|
| | 294 | corenet_tcp_sendrecv_ricci_modcluster_port(ricci_modclusterd_t) |
|---|
| 292 | 295 | corenet_tcp_bind_generic_node(ricci_modclusterd_t) |
|---|
| 293 | 296 | corenet_tcp_bind_ricci_modcluster_port(ricci_modclusterd_t) |
|---|
| r215 |
r216 |
|
| 43 | 43 | corenet_udp_sendrecv_generic_node(rwho_t) |
|---|
| 44 | 44 | corenet_udp_sendrecv_generic_port(rwho_t) |
|---|
| | 45 | corenet_udp_sendrecv_rwho_port(rwho_t) |
|---|
| 45 | 46 | corenet_udp_bind_generic_node(rwho_t) |
|---|
| 46 | 47 | corenet_udp_bind_rwho_port(rwho_t) |
|---|
| r215 |
r216 |
|
| 54 | 54 | corenet_tcp_sendrecv_generic_node(sendmail_t) |
|---|
| 55 | 55 | corenet_tcp_sendrecv_generic_port(sendmail_t) |
|---|
| | 56 | corenet_tcp_sendrecv_smtp_port(sendmail_t) |
|---|
| 56 | 57 | corenet_tcp_bind_generic_node(sendmail_t) |
|---|
| 57 | 58 | corenet_tcp_bind_smtp_port(sendmail_t) |
|---|
| 58 | 59 | corenet_tcp_connect_generic_port(sendmail_t) |
|---|
| | 60 | corenet_tcp_connect_snmp_port(sendmail_t) |
|---|
| | 61 | corenet_tcp_connect_smtp_port(sendmail_t) |
|---|
| | 62 | corenet_tcp_sendrecv_snmp_port(sendmail_t) |
|---|
| 59 | 63 | corenet_sendrecv_smtp_server_packets(sendmail_t) |
|---|
| 60 | 64 | corenet_sendrecv_smtp_client_packets(sendmail_t) |
|---|
| r215 |
r216 |
|
| 115 | 115 | corenet_tcp_sendrecv_generic_port($1_ssh_t) |
|---|
| 116 | 116 | corenet_tcp_connect_ssh_port($1_ssh_t) |
|---|
| | 117 | corenet_tcp_sendrecv_ssh_port($1_ssh_t) |
|---|
| 117 | 118 | corenet_sendrecv_ssh_client_packets($1_ssh_t) |
|---|
| 118 | 119 | |
|---|
| … | … | |
| 294 | 295 | # Should we have a boolean around this? |
|---|
| 295 | 296 | files_search_mnt($1_ssh_t) |
|---|
| 296 | | r_dir_file($1_ssh_t, removable_t) |
|---|
| | 297 | r_dir_file($1_ssh_t, removable_t) |
|---|
| 297 | 298 | |
|---|
| 298 | 299 | ') dnl endif TODO |
|---|
| … | … | |
| 475 | 476 | corenet_udp_sendrecv_generic_port($1_t) |
|---|
| 476 | 477 | corenet_tcp_sendrecv_generic_port($1_t) |
|---|
| | 478 | corenet_tcp_sendrecv_ssh_port($1_t) |
|---|
| 477 | 479 | corenet_tcp_bind_generic_node($1_t) |
|---|
| 478 | 480 | corenet_udp_bind_generic_node($1_t) |
|---|
| 479 | 481 | corenet_tcp_bind_ssh_port($1_t) |
|---|
| | 482 | corenet_tcp_connect_ssh_port($1_t) |
|---|
| 480 | 483 | corenet_tcp_connect_generic_port($1_t) |
|---|
| 481 | 484 | corenet_sendrecv_ssh_server_packets($1_t) |
|---|
| r203 |
r216 |
|
| 79 | 79 | # for X forwarding |
|---|
| 80 | 80 | corenet_tcp_bind_xserver_port(sshd_t) |
|---|
| | 81 | corenet_tcp_connect_xserver_port(sshd_t) |
|---|
| | 82 | corenet_tcp_sendrecv_xserver_port(sshd_t) |
|---|
| 81 | 83 | corenet_sendrecv_xserver_server_packets(sshd_t) |
|---|
| 82 | 84 | |
|---|
| r215 |
r216 |
|
| 44 | 44 | corenet_tcp_sendrecv_generic_node(xfs_t) |
|---|
| 45 | 45 | corenet_tcp_sendrecv_generic_port(xfs_t) |
|---|
| | 46 | corenet_tcp_sendrecv_xfs_port(xfs_t) |
|---|
| 46 | 47 | corenet_tcp_bind_generic_node(xfs_t) |
|---|
| 47 | 48 | corenet_tcp_bind_xfs_port(xfs_t) |
|---|
| r215 |
r216 |
|
| 115 | 115 | corenet_udp_sendrecv_generic_node($1_xserver_t) |
|---|
| 116 | 116 | corenet_tcp_sendrecv_generic_port($1_xserver_t) |
|---|
| | 117 | corenet_tcp_sendrecv_xserver_port($1_xserver_t) |
|---|
| 117 | 118 | corenet_udp_sendrecv_generic_port($1_xserver_t) |
|---|
| 118 | 119 | corenet_tcp_bind_generic_node($1_xserver_t) |
|---|
| 119 | 120 | corenet_tcp_bind_xserver_port($1_xserver_t) |
|---|
| 120 | 121 | corenet_tcp_connect_generic_port($1_xserver_t) |
|---|
| | 122 | corenet_tcp_connect_xserver_port($1_xserver_t) |
|---|
| 121 | 123 | corenet_sendrecv_xserver_server_packets($1_xserver_t) |
|---|
| 122 | 124 | corenet_sendrecv_generic_client_packets($1_xserver_t) |
|---|
| … | … | |
| 453 | 455 | |
|---|
| 454 | 456 | userdom_use_user_terminals($1,$1_iceauth_t) |
|---|
| 455 | | |
|---|
| | 457 | |
|---|
| 456 | 458 | files_search_tmp($1_iceauth_t) |
|---|
| 457 | | |
|---|
| | 459 | |
|---|
| 458 | 460 | userdom_read_user_home_content_files($1, $1_iceauth_t) |
|---|
| 459 | 461 | userdom_read_user_tmp_files($1, $1_iceauth_t) |
|---|
| … | … | |
| 461 | 463 | gen_require(` |
|---|
| 462 | 464 | type $1_t; |
|---|
| 463 | | ') |
|---|
| | 465 | ') |
|---|
| 464 | 466 | allow $1_iceauth_t $1_t:unix_stream_socket { read write }; |
|---|
| 465 | 467 | ') |
|---|
| … | … | |
| 707 | 709 | class x_property all_x_property_perms; |
|---|
| 708 | 710 | class x_selection all_x_selection_perms; |
|---|
| 709 | | class x_cursor all_x_cursor_perms; |
|---|
| | 711 | class x_cursor all_x_cursor_perms; |
|---|
| 710 | 712 | class x_client all_x_client_perms; |
|---|
| 711 | 713 | class x_device all_x_device_perms; |
|---|
| … | … | |
| 1150 | 1152 | ') |
|---|
| 1151 | 1153 | |
|---|
| 1152 | | allow $1 xdm_t:fd use; |
|---|
| | 1154 | allow $1 xdm_t:fd use; |
|---|
| 1153 | 1155 | ') |
|---|
| 1154 | 1156 | |
|---|
| … | … | |
| 1169 | 1171 | ') |
|---|
| 1170 | 1172 | |
|---|
| 1171 | | dontaudit $1 xdm_t:fd use; |
|---|
| | 1173 | dontaudit $1 xdm_t:fd use; |
|---|
| 1172 | 1174 | ') |
|---|
| 1173 | 1175 | |
|---|
| … | … | |
| 1187 | 1189 | ') |
|---|
| 1188 | 1190 | |
|---|
| 1189 | | allow $1 xdm_t:fifo_file { getattr read write }; |
|---|
| | 1191 | allow $1 xdm_t:fifo_file { getattr read write }; |
|---|
| 1190 | 1192 | ') |
|---|
| 1191 | 1193 | |
|---|
| … | … | |
| 1207 | 1209 | ') |
|---|
| 1208 | 1210 | |
|---|
| 1209 | | dontaudit $1 xdm_t:fifo_file rw_fifo_file_perms; |
|---|
| | 1211 | dontaudit $1 xdm_t:fifo_file rw_fifo_file_perms; |
|---|
| 1210 | 1212 | ') |
|---|
| 1211 | 1213 | |
|---|
| r215 |
r216 |
|
| 178 | 178 | fs_tmpfs_filetrans(xdm_t,xdm_tmpfs_t,{ dir file lnk_file sock_file fifo_file }) |
|---|
| 179 | 179 | |
|---|
| 180 | | manage_dirs_pattern(xdm_t,xdm_var_lib_t,xdm_var_lib_t) |
|---|
| | 180 | manage_dirs_pattern(xdm_t,xdm_var_lib_t,xdm_var_lib_t) |
|---|
| 181 | 181 | manage_files_pattern(xdm_t,xdm_var_lib_t,xdm_var_lib_t) |
|---|
| 182 | 182 | files_var_lib_filetrans(xdm_t,xdm_var_lib_t,file) |
|---|
| … | … | |
| 227 | 227 | corenet_udp_sendrecv_generic_node(xdm_t) |
|---|
| 228 | 228 | corenet_tcp_sendrecv_generic_port(xdm_t) |
|---|
| | 229 | corenet_tcp_sendrecv_xserver_port(xdm_t) |
|---|
| 229 | 230 | corenet_udp_sendrecv_generic_port(xdm_t) |
|---|
| 230 | 231 | corenet_tcp_bind_generic_node(xdm_t) |
|---|
| 231 | 232 | corenet_udp_bind_generic_node(xdm_t) |
|---|
| 232 | 233 | corenet_tcp_connect_generic_port(xdm_t) |
|---|
| | 234 | corenet_tcp_connect_xserver_port(xdm_t) |
|---|
| 233 | 235 | corenet_sendrecv_generic_client_packets(xdm_t) |
|---|
| | 236 | corenet_sendrecv_xserver_client_packets(xdm_t) |
|---|
| 234 | 237 | # xdm tries to bind to biff_port_t |
|---|
| 235 | 238 | corenet_dontaudit_tcp_bind_all_ports(xdm_t) |
|---|
| r214 |
r216 |
|
| 62 | 62 | corenet_tcp_sendrecv_generic_node(iscsid_t) |
|---|
| 63 | 63 | corenet_tcp_sendrecv_generic_port(iscsid_t) |
|---|
| | 64 | corenet_tcp_sendrecv_iscsi_port(iscsid_t) |
|---|
| | 65 | corenet_tcp_sendrecv_http_port(iscsid_t) |
|---|
| 64 | 66 | corenet_tcp_connect_http_port(iscsid_t) |
|---|
| 65 | 67 | corenet_tcp_connect_iscsi_port(iscsid_t) |
|---|
| r215 |
r216 |
|
| 95 | 95 | corenet_tcp_sendrecv_generic_port(dhcpc_t) |
|---|
| 96 | 96 | corenet_udp_sendrecv_generic_port(dhcpc_t) |
|---|
| | 97 | corenet_tcp_sendrecv_dhcpc_port(dhcpc_t) |
|---|
| | 98 | corenet_udp_sendrecv_dhcpc_port(dhcpc_t) |
|---|
| 97 | 99 | corenet_tcp_bind_generic_node(dhcpc_t) |
|---|
| 98 | 100 | corenet_udp_bind_generic_node(dhcpc_t) |
|---|
| 99 | 101 | corenet_udp_bind_dhcpc_port(dhcpc_t) |
|---|
| 100 | 102 | corenet_tcp_connect_generic_port(dhcpc_t) |
|---|
| | 103 | corenet_tcp_connect_dhcpc_port(dhcpc_t) |
|---|
| 101 | 104 | corenet_sendrecv_dhcpd_client_packets(dhcpc_t) |
|---|
| 102 | 105 | corenet_sendrecv_dhcpc_server_packets(dhcpc_t) |
|---|
| … | … | |
| 311 | 314 | ') |
|---|
| 312 | 315 | ') |
|---|
| 313 | | |
|---|
| | 316 | |
|---|
| 314 | 317 | ifdef(`hide_broken_symptoms',` |
|---|
| 315 | 318 | optional_policy(` |
|---|
Download in other formats:
* Generating other formats may take time.