ttrss.te 1009 B

123456789101112131415161718192021222324252627282930313233343536373839404142434445
  1. policy_module(ttrss, 0.0.3)
  2. ########################################
  3. #
  4. # Declarations
  5. #
  6. attribute_role ttrss_roles;
  7. type ttrss_t;
  8. type ttrss_exec_t;
  9. init_system_domain(ttrss_t, ttrss_exec_t)
  10. ########################################
  11. #
  12. # Local policy
  13. #
  14. allow ttrss_t self:netlink_route_socket { bind create getattr nlmsg_read read write };
  15. allow ttrss_t self:tcp_socket { connect create getattr getopt read setopt write };
  16. allow ttrss_t self:udp_socket { connect create getattr read write };
  17. allow ttrss_t self:unix_stream_socket { connect create read write };
  18. corenet_tcp_connect_generic_port(ttrss_t)
  19. corenet_tcp_connect_http_port(ttrss_t)
  20. files_read_etc_files(ttrss_t)
  21. miscfiles_read_generic_certs(ttrss_t)
  22. apache_manage_sys_content(ttrss_t)
  23. corecmd_check_exec_shell(ttrss_t)
  24. corecmd_exec_bin(ttrss_t)
  25. sysnet_read_config(ttrss_t)
  26. miscfiles_read_localization(ttrss_t)
  27. mysql_tcp_connect(ttrss_t)
  28. mysql_stream_connect(ttrss_t)
  29. optional_policy(`
  30. cron_system_entry(ttrss_t, ttrss_exec_t)
  31. ')