## Policy for mount. ######################################## ## ## Execute mount in the mount domain. ## ## ## ## The type of the process performing this action. ## ## # interface(`mount_domtrans',` gen_require(` type mount_t, mount_exec_t; ') domain_auto_trans($1,mount_exec_t,mount_t) allow $1 mount_t:fd use; allow mount_t $1:fd use; allow mount_t $1:fifo_file rw_file_perms; allow mount_t $1:process sigchld; ') ######################################## ## ## Execute mount in the mount domain, and ## allow the specified role the mount domain, ## and use the caller's terminal. ## ## ## ## The type of the process performing this action. ## ## ## ## ## The role to be allowed the mount domain. ## ## ## ## ## The type of the terminal allow the mount domain to use. ## ## # interface(`mount_run',` gen_require(` type mount_t; ') mount_domtrans($1) role $2 types mount_t; allow mount_t $3:chr_file rw_file_perms; ') ######################################## ## ## Execute mount in the caller domain. ## ## ## ## The type of the process performing this action. ## ## # interface(`mount_exec',` gen_require(` type mount_exec_t; ') allow $1 mount_exec_t:dir r_dir_perms; allow $1 mount_exec_t:lnk_file r_file_perms; can_exec($1,mount_exec_t) ') ######################################## ## ## Use file descriptors for mount. ## ## ## ## The type of the process performing this action. ## ## # interface(`mount_use_fds',` gen_require(` type mount_t; ') allow $1 mount_t:fd use; ') ######################################## ## ## Allow the mount domain to send nfs requests for mounting ## network drives ## ## ## ## The type of the process performing this action. ## ## # interface(`mount_send_nfs_client_request',` gen_require(` type mount_t; ') allow $1 mount_t:udp_socket rw_socket_perms; ') ######################################## ## ## Execute mount in the unconfined mount domain. ## ## ## ## Domain allowed access. ## ## # interface(`mount_domtrans_unconfined',` ifdef(`targeted_policy',` gen_require(` type unconfined_mount_t, mount_exec_t; ') domain_auto_trans($1,mount_exec_t,unconfined_mount_t) allow $1 unconfined_mount_t:fd use; allow unconfined_mount_t $1:fd use; allow unconfined_mount_t $1:fifo_file rw_file_perms; allow unconfined_mount_t $1:process sigchld; ',` errprint(`Warning: $0($1) has no effect in strict policy.'__endline__) ') ')