blob: 2c87fde5ee87630ae561f12deb88dd3f61c8dbc0 [file] [log] [blame]
Stephen Smalley2dd4e512012-01-04 12:33:27 -05001#####################################
2# Common groupings of object classes.
3#
Benjamin Gordon9b2e0cb2017-11-09 15:51:26 -07004define(`capability_class_set', `{ capability capability2 cap_userns cap2_userns }')
5define(`global_capability_class_set', `{ capability cap_userns }')
6define(`global_capability2_class_set', `{ capability2 cap2_userns }')
Stephen Smalley2dd4e512012-01-04 12:33:27 -05007
Stephen Smalley2dd4e512012-01-04 12:33:27 -05008define(`devfile_class_set', `{ chr_file blk_file }')
William Roberts7104df52012-10-03 09:55:28 -07009define(`notdevfile_class_set', `{ file lnk_file sock_file fifo_file }')
10define(`file_class_set', `{ devfile_class_set notdevfile_class_set }')
11define(`dir_file_class_set', `{ dir file_class_set }')
Stephen Smalley2dd4e512012-01-04 12:33:27 -050012
Nick Kralevicha194d372018-11-16 02:48:03 -080013define(`socket_class_set', `{ socket tcp_socket udp_socket rawip_socket netlink_socket packet_socket key_socket unix_stream_socket unix_dgram_socket appletalk_socket netlink_route_socket netlink_tcpdiag_socket netlink_nflog_socket netlink_xfrm_socket netlink_selinux_socket netlink_audit_socket netlink_dnrt_socket netlink_kobject_uevent_socket tun_socket netlink_iscsi_socket netlink_fib_lookup_socket netlink_connector_socket netlink_netfilter_socket netlink_generic_socket netlink_scsitransport_socket netlink_rdma_socket netlink_crypto_socket sctp_socket icmp_socket ax25_socket ipx_socket netrom_socket atmpvc_socket x25_socket rose_socket decnet_socket atmsvc_socket rds_socket irda_socket pppox_socket llc_socket can_socket tipc_socket bluetooth_socket iucv_socket rxrpc_socket isdn_socket phonet_socket ieee802154_socket caif_socket alg_socket nfc_socket vsock_socket kcm_socket qipcrtr_socket smc_socket xdp_socket }')
Stephen Smalley2dd4e512012-01-04 12:33:27 -050014define(`dgram_socket_class_set', `{ udp_socket unix_dgram_socket }')
Nick Kralevichea1775d2018-11-01 19:39:44 -070015define(`stream_socket_class_set', `{ tcp_socket unix_stream_socket sctp_socket }')
16define(`unpriv_socket_class_set', `{ tcp_socket udp_socket unix_stream_socket unix_dgram_socket sctp_socket }')
Jeff Vander Stoep561aa012019-01-17 14:44:29 -080017define(`network_socket_class_set', `{ icmp_socket rawip_socket tcp_socket udp_socket }')
Stephen Smalley2dd4e512012-01-04 12:33:27 -050018
19define(`ipc_class_set', `{ sem msgq shm ipc }')
20
21#####################################
22# Common groupings of permissions.
23#
Stephen Smalley4397f082017-07-10 09:32:10 -040024define(`x_file_perms', `{ getattr execute execute_no_trans map }')
Nick Kralevichc4ab8ed2019-08-28 12:23:20 -070025define(`r_file_perms', `{ getattr open read ioctl lock map watch watch_reads }')
Stephen Smalley4397f082017-07-10 09:32:10 -040026define(`w_file_perms', `{ open append write lock map }')
Stephen Smalley2dd4e512012-01-04 12:33:27 -050027define(`rx_file_perms', `{ r_file_perms x_file_perms }')
28define(`ra_file_perms', `{ r_file_perms append }')
29define(`rw_file_perms', `{ r_file_perms w_file_perms }')
30define(`rwx_file_perms', `{ rw_file_perms x_file_perms }')
Nick Kralevich85ce2c72015-03-26 18:18:03 -070031define(`create_file_perms', `{ create rename setattr unlink rw_file_perms }')
Stephen Smalley2dd4e512012-01-04 12:33:27 -050032
Nick Kralevichc4ab8ed2019-08-28 12:23:20 -070033define(`r_dir_perms', `{ open getattr read search ioctl lock watch watch_reads }')
Nick Kralevich4ee494c2016-03-21 18:15:05 -070034define(`w_dir_perms', `{ open search write add_name remove_name lock }')
Stephen Smalley2dd4e512012-01-04 12:33:27 -050035define(`ra_dir_perms', `{ r_dir_perms add_name write }')
36define(`rw_dir_perms', `{ r_dir_perms w_dir_perms }')
Nick Kralevich85ce2c72015-03-26 18:18:03 -070037define(`create_dir_perms', `{ create reparent rename rmdir setattr rw_dir_perms }')
Stephen Smalley2dd4e512012-01-04 12:33:27 -050038
39define(`r_ipc_perms', `{ getattr read associate unix_read }')
40define(`w_ipc_perms', `{ write unix_write }')
41define(`rw_ipc_perms', `{ r_ipc_perms w_ipc_perms }')
42define(`create_ipc_perms', `{ create setattr destroy rw_ipc_perms }')
Robert Craig18b5f872013-01-07 09:21:18 -050043
44#####################################
45# Common socket permission sets.
Nick Kralevich9c228952018-10-15 21:24:57 -070046define(`rw_socket_perms', `{ ioctl read getattr write setattr lock append bind connect getopt setopt shutdown map }')
47define(`rw_socket_perms_no_ioctl', `{ read getattr write setattr lock append bind connect getopt setopt shutdown map }')
Robert Craig18b5f872013-01-07 09:21:18 -050048define(`create_socket_perms', `{ create rw_socket_perms }')
Jeff Vander Stoepeab8a8b2016-09-09 12:48:45 -070049define(`create_socket_perms_no_ioctl', `{ create rw_socket_perms_no_ioctl }')
Stephen Smalley85708ec2014-02-24 10:48:03 -050050define(`rw_stream_socket_perms', `{ rw_socket_perms listen accept }')
51define(`create_stream_socket_perms', `{ create rw_stream_socket_perms }')