From a715dc09957215fb90121ec5441fa9591dbc84b3 Mon Sep 17 00:00:00 2001 From: Chris PeBenito Date: Mon, 26 Feb 2007 15:39:59 +0000 Subject: [PATCH] add dccp_socket object class --- Changelog | 1 + policy/flask/access_vectors | 11 +++++++++++ policy/flask/security_classes | 2 ++ 3 files changed, 14 insertions(+) diff --git a/Changelog b/Changelog index 6073634b..d2102a1a 100644 --- a/Changelog +++ b/Changelog @@ -1,3 +1,4 @@ +- Add dccp_socket object class which was added in kernel 2.6.20. - Patch for prelink relabefrom it's temp files from Dan Walsh. - Patch for capability fix for auditd and networking fix for syslogd from Dan Walsh. diff --git a/policy/flask/access_vectors b/policy/flask/access_vectors index 4848d259..d45ad96f 100644 --- a/policy/flask/access_vectors +++ b/policy/flask/access_vectors @@ -185,6 +185,8 @@ class node rawip_recv rawip_send enforce_dest + dccp_recv + dccp_send } class netif @@ -195,6 +197,8 @@ class netif udp_send rawip_recv rawip_send + dccp_recv + dccp_send } class netlink_socket @@ -637,3 +641,10 @@ class context translate contains } + +class dccp_socket +inherits socket +{ + node_bind + name_connect +} diff --git a/policy/flask/security_classes b/policy/flask/security_classes index 53c0cf15..788d8548 100644 --- a/policy/flask/security_classes +++ b/policy/flask/security_classes @@ -95,4 +95,6 @@ class key class context # userspace +class dccp_socket + # FLASK