34 lines
893 B
Text
34 lines
893 B
Text
|
policy_module(mip6d, 1.0.0)
|
||
|
|
||
|
########################################
|
||
|
#
|
||
|
# Declarations
|
||
|
#
|
||
|
|
||
|
type mip6d_t;
|
||
|
type mip6d_exec_t;
|
||
|
init_daemon_domain(mip6d_t, mip6d_exec_t)
|
||
|
|
||
|
type mip6d_unit_file_t;
|
||
|
systemd_unit_file(mip6d_unit_file_t)
|
||
|
|
||
|
########################################
|
||
|
#
|
||
|
# mip6d local policy
|
||
|
#
|
||
|
allow mip6d_t self:capability { net_admin net_raw };
|
||
|
allow mip6d_t self:process { setpgid fork signal };
|
||
|
allow mip6d_t self:netlink_route_socket create_netlink_socket_perms;
|
||
|
allow mip6d_t self:netlink_xfrm_socket create_netlink_socket_perms;
|
||
|
allow mip6d_t self:rawip_socket create_socket_perms;
|
||
|
allow mip6d_t self:udp_socket create_socket_perms;
|
||
|
allow mip6d_t self:fifo_file rw_fifo_file_perms;
|
||
|
allow mip6d_t self:unix_stream_socket create_stream_socket_perms;
|
||
|
|
||
|
kernel_rw_net_sysctls(mip6d_t)
|
||
|
kernel_read_network_state(mip6d_t)
|
||
|
kernel_request_load_module(mip6d_t)
|
||
|
|
||
|
logging_send_syslog_msg(mip6d_t)
|
||
|
|