2005-06-14 20:40:09 +00:00
|
|
|
|
2006-01-17 20:14:04 +00:00
|
|
|
policy_module(selinux,1.1.0)
|
2005-06-14 20:40:09 +00:00
|
|
|
|
|
|
|
########################################
|
|
|
|
#
|
|
|
|
# Declarations
|
|
|
|
#
|
|
|
|
|
2005-07-05 20:59:51 +00:00
|
|
|
attribute can_load_policy;
|
|
|
|
attribute can_setenforce;
|
|
|
|
attribute can_setsecparam;
|
|
|
|
|
2005-06-14 20:40:09 +00:00
|
|
|
#
|
|
|
|
# security_t is the target type when checking
|
|
|
|
# the permissions in the security class. It is also
|
|
|
|
# applied to selinuxfs inodes.
|
|
|
|
#
|
2005-09-26 20:26:32 +00:00
|
|
|
type security_t;
|
2005-06-28 17:48:59 +00:00
|
|
|
fs_type(security_t)
|
2005-09-26 20:26:32 +00:00
|
|
|
mls_trusted_object(security_t)
|
2006-01-06 22:51:40 +00:00
|
|
|
sid security gen_context(system_u:object_r:security_t,s15:c0.c255)
|
2005-10-06 19:33:06 +00:00
|
|
|
genfscon selinuxfs / gen_context(system_u:object_r:security_t,s0)
|
2005-07-05 20:59:51 +00:00
|
|
|
|
|
|
|
neverallow ~can_load_policy security_t:security load_policy;
|
|
|
|
neverallow ~can_setenforce security_t:security setenforce;
|
|
|
|
neverallow ~can_setsecparam security_t:security setsecparam;
|