Skip to content
Snippets Groups Projects
Commit cc65fe82 authored by Stephen Smalley's avatar Stephen Smalley
Browse files

Make ppp permissive or unconfined.


Also add rules from our policy.

Change-Id: I6f552538cc4f6b28b2883aa74832230944cbdb7a
Signed-off-by: default avatarStephen Smalley <sds@tycho.nsa.gov>
parent e21871c8
No related branches found
No related tags found
No related merge requests found
# Point to Point Protocol daemon # Point to Point Protocol daemon
type ppp, domain; type ppp, domain;
permissive_or_unconfined(ppp)
type ppp_device, dev_type; type ppp_device, dev_type;
type ppp_exec, exec_type, file_type; type ppp_exec, exec_type, file_type;
unconfined_domain(ppp)
domain_auto_trans(mtp, ppp_exec, ppp) domain_auto_trans(mtp, ppp_exec, ppp)
allow ppp mtp:socket rw_socket_perms;
allow ppp ppp_device:chr_file rw_file_perms;
allow ppp self:capability net_admin;
allow ppp self:udp_socket create_socket_perms;
allow ppp system_file:file rx_file_perms;
allow ppp vpn_data_file:dir w_dir_perms;
allow ppp vpn_data_file:file create_file_perms;
allow ppp mtp:fd use;
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment