]> git.proxmox.com Git - mirror_ovs.git/blame - selinux/openvswitch-custom.te
ovsdb-idl: Avoid mutable type specifier.
[mirror_ovs.git] / selinux / openvswitch-custom.te
CommitLineData
5e2e3ada 1module openvswitch-custom 1.0.1;
9b897c91
AA
2
3require {
4 type openvswitch_t;
5e2e3ada
JS
5 type openvswitch_tmp_t;
6 type ifconfig_exec_t;
7 type hostname_exec_t;
9b897c91 8 class netlink_socket { setopt getopt create connect getattr write read };
5e2e3ada 9 class file { write getattr read open execute execute_no_trans };
9b897c91
AA
10}
11
12#============= openvswitch_t ==============
13allow openvswitch_t self:netlink_socket { setopt getopt create connect getattr write read };
5e2e3ada
JS
14allow openvswitch_t hostname_exec_t:file { read getattr open execute execute_no_trans };
15allow openvswitch_t ifconfig_exec_t:file { read getattr open execute execute_no_trans };
16allow openvswitch_t openvswitch_tmp_t:file { execute execute_no_trans };