## policy for wireguard ######################################## ## ## Execute wireguard_exec_t in the wireguard domain. ## ## ## ## Domain allowed to transition. ## ## # interface(`wireguard_domtrans',` gen_require(` type wireguard_t, wireguard_exec_t; ') corecmd_search_bin($1) domtrans_pattern($1, wireguard_exec_t, wireguard_t) ') ###################################### ## ## Execute wireguard in the caller domain. ## ## ## ## Domain allowed access. ## ## # interface(`wireguard_exec',` gen_require(` type wireguard_exec_t; ') corecmd_search_bin($1) can_exec($1, wireguard_exec_t) ') ######################################## ## ## Read wireguard fifo files. ## ## ## ## Domain to not audit. ## ## # interface(`wireguard_read_fifo_files',` gen_require(` type wireguard_t; ') allow $1 wireguard_t:fifo_file read_fifo_file_perms; ')