policy_module(mip6d, 1.0.0) ######################################## # # Declarations # type mip6d_t; type mip6d_exec_t; init_daemon_domain(mip6d_t, mip6d_exec_t) type mip6d_unit_file_t; systemd_unit_file(mip6d_unit_file_t) ######################################## # # mip6d local policy # allow mip6d_t self:capability { net_admin net_raw }; allow mip6d_t self:process { setpgid fork signal }; allow mip6d_t self:netlink_route_socket create_netlink_socket_perms; allow mip6d_t self:netlink_xfrm_socket create_netlink_socket_perms; allow mip6d_t self:rawip_socket create_socket_perms; allow mip6d_t self:udp_socket create_socket_perms; allow mip6d_t self:fifo_file rw_fifo_file_perms; allow mip6d_t self:unix_stream_socket create_stream_socket_perms; kernel_rw_net_sysctls(mip6d_t) kernel_read_network_state(mip6d_t) kernel_request_load_module(mip6d_t) logging_send_syslog_msg(mip6d_t)