## Manager for dynamically switching between networks. ######################################## ## ## Read and write NetworkManager UDP sockets. ## ## ## ## Domain allowed access. ## ## # # cjp: added for named. interface(`networkmanager_rw_udp_sockets',` gen_require(` type NetworkManager_t; ') allow $1 NetworkManager_t:udp_socket { read write }; ') ######################################## ## ## Read and write NetworkManager packet sockets. ## ## ## ## Domain allowed access. ## ## # # cjp: added for named. interface(`networkmanager_rw_packet_sockets',` gen_require(` type NetworkManager_t; ') allow $1 NetworkManager_t:packet_socket { read write }; ') ####################################### ## ## Allow caller to relabel tun_socket ## ## ## ## Domain allowed access. ## ## # interface(`networkmanager_attach_tun_iface',` gen_require(` type NetworkManager_t; ') allow $1 NetworkManager_t:tun_socket relabelfrom; allow $1 self:tun_socket relabelto; ') ######################################## ## ## Read and write NetworkManager netlink ## routing sockets. ## ## ## ## Domain allowed access. ## ## # # cjp: added for named. interface(`networkmanager_rw_routing_sockets',` gen_require(` type NetworkManager_t; ') allow $1 NetworkManager_t:netlink_route_socket { read write }; ') ######################################## ## ## Execute NetworkManager with a domain transition. ## ## ## ## Domain allowed access. ## ## # interface(`networkmanager_domtrans',` gen_require(` type NetworkManager_t, NetworkManager_exec_t; ') corecmd_search_bin($1) domtrans_pattern($1, NetworkManager_exec_t, NetworkManager_t) ') ######################################## ## ## Execute NetworkManager scripts with an automatic domain transition to initrc. ## ## ## ## Domain allowed access. ## ## # interface(`networkmanager_initrc_domtrans',` gen_require(` type NetworkManager_initrc_exec_t; ') init_labeled_script_domtrans($1, NetworkManager_initrc_exec_t) ') ######################################## ## ## Send and receive messages from ## NetworkManager over dbus. ## ## ## ## Domain allowed access. ## ## # interface(`networkmanager_dbus_chat',` gen_require(` type NetworkManager_t; class dbus send_msg; ') allow $1 NetworkManager_t:dbus send_msg; allow NetworkManager_t $1:dbus send_msg; ') ######################################## ## ## Send a generic signal to NetworkManager ## ## ## ## Domain allowed access. ## ## # interface(`networkmanager_signal',` gen_require(` type NetworkManager_t; ') allow $1 NetworkManager_t:process signal; ') ######################################## ## ## Read NetworkManager lib files. ## ## ## ## Domain allowed access. ## ## # interface(`networkmanager_read_lib_files',` gen_require(` type NetworkManager_var_lib_t; ') files_search_var_lib($1) list_dirs_pattern($1, NetworkManager_var_lib_t, NetworkManager_var_lib_t) read_files_pattern($1, NetworkManager_var_lib_t, NetworkManager_var_lib_t) ') ######################################## ## ## Read NetworkManager PID files. ## ## ## ## Domain allowed access. ## ## # interface(`networkmanager_read_pid_files',` gen_require(` type NetworkManager_var_run_t; ') files_search_pids($1) allow $1 NetworkManager_var_run_t:file read_file_perms; ')