interface renaming
This commit is contained in:
parent
1694dee685
commit
0c5a288e98
@ -2,7 +2,7 @@
|
|||||||
## <summary>Policy for the kernel modules, kernel image, and bootloader.</summary>
|
## <summary>Policy for the kernel modules, kernel image, and bootloader.</summary>
|
||||||
|
|
||||||
########################################
|
########################################
|
||||||
## <interface name="bootloader_transition">
|
## <interface name="bootloader_domtrans">
|
||||||
## <description>
|
## <description>
|
||||||
## Execute bootloader in the bootloader domain.
|
## Execute bootloader in the bootloader domain.
|
||||||
## </description>
|
## </description>
|
||||||
@ -12,7 +12,7 @@
|
|||||||
## <infoflow type="write" weight="10"/>
|
## <infoflow type="write" weight="10"/>
|
||||||
## </interface>
|
## </interface>
|
||||||
#
|
#
|
||||||
define(`bootloader_transition',`
|
define(`bootloader_domtrans',`
|
||||||
requires_block_template(`$0'_depend)
|
requires_block_template(`$0'_depend)
|
||||||
|
|
||||||
allow $1 bootloader_exec_t:file { getattr read execute };
|
allow $1 bootloader_exec_t:file { getattr read execute };
|
||||||
@ -26,7 +26,7 @@ define(`bootloader_transition',`
|
|||||||
allow bootloader_t $1:process sigchld;
|
allow bootloader_t $1:process sigchld;
|
||||||
')
|
')
|
||||||
|
|
||||||
define(`bootloader_transition_depend',`
|
define(`bootloader_domtrans_depend',`
|
||||||
type bootloader_t;
|
type bootloader_t;
|
||||||
|
|
||||||
class file { getattr read execute };
|
class file { getattr read execute };
|
||||||
@ -36,7 +36,7 @@ define(`bootloader_transition_depend',`
|
|||||||
')
|
')
|
||||||
|
|
||||||
########################################
|
########################################
|
||||||
## <interface name="bootloader_transition_add_role_use_terminal">
|
## <interface name="bootloader_run">
|
||||||
## <description>
|
## <description>
|
||||||
## Execute bootloader in the bootloader domain, and
|
## Execute bootloader in the bootloader domain, and
|
||||||
## allow the specified role the bootloader domain,
|
## allow the specified role the bootloader domain,
|
||||||
@ -54,7 +54,7 @@ define(`bootloader_transition_depend',`
|
|||||||
## <infoflow type="write" weight="10"/>
|
## <infoflow type="write" weight="10"/>
|
||||||
## </interface>
|
## </interface>
|
||||||
#
|
#
|
||||||
define(`bootloader_transition_add_role_use_terminal',`
|
define(`bootloader_run',`
|
||||||
requires_block_template(`$0'_depend)
|
requires_block_template(`$0'_depend)
|
||||||
|
|
||||||
bootloader_transition($1)
|
bootloader_transition($1)
|
||||||
@ -63,7 +63,7 @@ define(`bootloader_transition_add_role_use_terminal',`
|
|||||||
allow bootloader_t $3:chr_file { getattr read write ioctl };
|
allow bootloader_t $3:chr_file { getattr read write ioctl };
|
||||||
')
|
')
|
||||||
|
|
||||||
define(`bootloader_transition_add_role_use_terminal_depend',`
|
define(`bootloader_run_depend',`
|
||||||
type bootloader_t;
|
type bootloader_t;
|
||||||
class chr_file { getattr read write ioctl };
|
class chr_file { getattr read write ioctl };
|
||||||
')
|
')
|
||||||
@ -247,15 +247,15 @@ define(`bootloader_read_config_depend',`
|
|||||||
|
|
||||||
########################################
|
########################################
|
||||||
#
|
#
|
||||||
# bootloader_modify_config(domain)
|
# bootloader_rw_config(domain)
|
||||||
#
|
#
|
||||||
define(`bootloader_modify_bootloader_config',`
|
define(`bootloader_rw_bootloader_config',`
|
||||||
requires_block_template(`$0'_depend)
|
requires_block_template(`$0'_depend)
|
||||||
|
|
||||||
allow $1 bootloader_etc_t:file { getattr read write append };
|
allow $1 bootloader_etc_t:file { getattr read write append };
|
||||||
')
|
')
|
||||||
|
|
||||||
define(`bootloader_modify_bootloader_config_depend',`
|
define(`bootloader_rw_bootloader_config_depend',`
|
||||||
type bootloader_etc_t;
|
type bootloader_etc_t;
|
||||||
|
|
||||||
class file { getattr read write append };
|
class file { getattr read write append };
|
||||||
@ -263,16 +263,16 @@ define(`bootloader_modify_bootloader_config_depend',`
|
|||||||
|
|
||||||
########################################
|
########################################
|
||||||
#
|
#
|
||||||
# bootloader_modify_temporary_data(domain)
|
# bootloader_rw_temp_data(domain)
|
||||||
#
|
#
|
||||||
define(`bootloader_modify_temporary_data',`
|
define(`bootloader_rw_temp_data',`
|
||||||
requires_block_template(`$0'_depend)
|
requires_block_template(`$0'_depend)
|
||||||
|
|
||||||
# FIXME: read tmp_t
|
# FIXME: read tmp_t
|
||||||
allow $1 bootloader_tmp_t:file { getattr read write };
|
allow $1 bootloader_tmp_t:file { getattr read write };
|
||||||
')
|
')
|
||||||
|
|
||||||
define(`bootloader_modify_temporary_data_depend',`
|
define(`bootloader_rw_temp_data_depend',`
|
||||||
type bootloader_tmp_t;
|
type bootloader_tmp_t;
|
||||||
|
|
||||||
class file { getattr read write setattr };
|
class file { getattr read write setattr };
|
||||||
|
File diff suppressed because it is too large
Load Diff
Loading…
Reference in New Issue
Block a user