Skip to content
Snippets Groups Projects
security_classes 1.85 KiB
Newer Older
  • Learn to ignore specific revisions
  • Stephen Smalley's avatar
    Stephen Smalley committed
    # FLASK
    
    #
    # Define the security object classes
    #
    
    # Classes marked as userspace are classes
    # for userspace object managers
    
    class security
    class process
    class system
    class capability
    
    # file-related classes
    class filesystem
    class file
    class dir
    class fd
    class lnk_file
    class chr_file
    class blk_file
    class sock_file
    class fifo_file
    
    # network-related classes
    class socket
    class tcp_socket
    class udp_socket
    class rawip_socket
    class node
    class netif
    class netlink_socket
    class packet_socket
    class key_socket
    class unix_stream_socket
    class unix_dgram_socket
    
    # sysv-ipc-related classes
    class sem
    class msg
    class msgq
    class shm
    class ipc
    
    # extended netlink sockets
    class netlink_route_socket
    class netlink_firewall_socket
    class netlink_tcpdiag_socket
    class netlink_nflog_socket
    class netlink_xfrm_socket
    class netlink_selinux_socket
    class netlink_audit_socket
    class netlink_ip6fw_socket
    class netlink_dnrt_socket
    
    # IPSec association
    class association
    
    # Updated Netlink class for KOBJECT_UEVENT family.
    class netlink_kobject_uevent_socket
    
    class appletalk_socket
    
    class packet
    
    # Kernel access key retention
    class key
    
    class dccp_socket
    
    class memprotect
    
    # network peer labels
    class peer
    
    # Capabilities >= 32
    class capability2
    
    # kernel services that need to override task security, e.g. cachefiles
    class kernel_service
    
    class tun_socket
    
    class binder
    
    
    # Updated netlink classes for more recent netlink protocols.
    class netlink_iscsi_socket
    class netlink_fib_lookup_socket
    class netlink_connector_socket
    class netlink_netfilter_socket
    class netlink_generic_socket
    class netlink_scsitransport_socket
    class netlink_rdma_socket
    class netlink_crypto_socket
    
    
    # Property service
    class property_service          # userspace
    
    
    # Service manager
    class service_manager           # userspace
    
    
    # Keystore Key
    class keystore_key              # userspace
    
    
    class drmservice                # userspace
    
    Stephen Smalley's avatar
    Stephen Smalley committed
    # FLASK