2012-01-04 09:33:27 -08:00
|
|
|
# Life begins with the kernel.
|
|
|
|
type kernel, domain;
|
2014-01-24 20:43:07 -08:00
|
|
|
|
|
|
|
allow kernel init:process dyntransition;
|
|
|
|
|
2012-01-04 09:33:27 -08:00
|
|
|
# The kernel is unconfined.
|
|
|
|
unconfined_domain(kernel)
|
2013-07-10 14:46:05 -07:00
|
|
|
relabelto_domain(kernel)
|
|
|
|
|
|
|
|
allow kernel {fs_type dev_type file_type}:dir_file_class_set relabelto;
|
2013-09-05 15:36:30 -07:00
|
|
|
allow kernel unlabeled:filesystem mount;
|
2014-02-10 10:29:38 -08:00
|
|
|
allow kernel fs_type:filesystem *;
|
2013-12-06 05:05:53 -08:00
|
|
|
|
|
|
|
# Initial setenforce by init prior to switching to init domain.
|
|
|
|
allow kernel self:security setenforce;
|
2014-01-08 06:29:30 -08:00
|
|
|
|
|
|
|
# Set checkreqprot by init.rc prior to switching to init domain.
|
|
|
|
allow kernel self:security setcheckreqprot;
|
2014-02-10 13:31:04 -08:00
|
|
|
|
|
|
|
# For operations performed by kernel or init prior to switching to init domain.
|
|
|
|
## TODO: Investigate whether it is safe to remove these
|
|
|
|
allow kernel self:capability { sys_rawio mknod };
|
|
|
|
auditallow kernel self:capability { sys_rawio mknod };
|