diff options
author | Toni Uhlig <matzeton@googlemail.com> | 2019-04-09 16:11:38 +0200 |
---|---|---|
committer | Toni Uhlig <matzeton@googlemail.com> | 2019-04-09 16:11:38 +0200 |
commit | f62bbc82579868aa1c494b0082136ed7c3c583f7 (patch) | |
tree | fd749d5ae391efdc7d87b3d88db07b41f2116358 /selinux/ptunnel.te | |
parent | 1c04661dc9b11c6506e96a21e79b3587b4038a28 (diff) |
updated selinux policy file and added compile script
Signed-off-by: Toni Uhlig <matzeton@googlemail.com>
Diffstat (limited to 'selinux/ptunnel.te')
-rw-r--r-- | selinux/ptunnel.te | 22 |
1 files changed, 0 insertions, 22 deletions
diff --git a/selinux/ptunnel.te b/selinux/ptunnel.te deleted file mode 100644 index 995c765..0000000 --- a/selinux/ptunnel.te +++ /dev/null @@ -1,22 +0,0 @@ -policy_module(ptunnel, 1.7) - -require { - type initrc_t; - type unconfined_t; - type unlabeled_t; - class tcp_socket { read write create connect }; - class association recvfrom; - class rawip_socket { write read }; -} - -type ptunnel_t; -domain_dyntrans_type(initrc_t) - -allow ptunnel_t self:tcp_socket { read write create connect }; -allow ptunnel_t unconfined_t:rawip_socket { write read }; -allow ptunnel_t unlabeled_t:association recvfrom; -corenet_tcp_sendrecv_generic_if(ptunnel_t) -corenet_tcp_sendrecv_ssh_port(ptunnel_t) -corenet_raw_receive_generic_node(ptunnel_t) -corenet_tcp_connect_ssh_port(ptunnel_t) -corenet_tcp_sendrecv_lo_node(ptunnel_t) |