The SELinux Notebook - Sample Policy Source
class node { tcp_recv tcp_send udp_recv udp_send rawip_recv rawip_send
enforce_dest dccp_recv dccp_send recvfrom sendto }
class netif { tcp_recv tcp_send udp_recv udp_send rawip_recv rawip_send
dccp_recv dccp_send ingress egress }
class netlink_socket inherits socket
class packet_socket inherits socket
class key_socket inherits socket
class unix_stream_socket inherits socket { connectto newconn acceptfrom }
class unix_dgram_socket inherits socket
class process { fork transition sigchld sigkill sigstop signull signal ptrace
getsched setsched getsession getpgid setpgid getcap setcap share getattr setexec
setfscreate noatsecure siginh setrlimit rlimitinh dyntransition setcurrent
execmem execstack execheap setkeycreate setsockcreate }
class ipc inherits ipc
class sem inherits ipc
class msgq inherits ipc { enqueue }
class msg { send receive }
class shm inherits ipc { lock }
class security { compute_av compute_create compute_member check_context
load_policy compute_relabel compute_user setenforce setbool setsecparam
setcheckreqprot }
class system { ipc_info syslog_read syslog_mod syslog_console module_request }
class capability { chown dac_override dac_read_search fowner fsetid kill setgid
setuid setpcap linux_immutable net_bind_service net_broadcast net_admin net_raw
ipc_lock ipc_owner sys_module sys_rawio sys_chroot sys_ptrace sys_pacct
sys_admin sys_boot sys_nice sys_resource sys_time sys_tty_config mknod lease
audit_write audit_control setfcap }
class capability2 { mac_override mac_admin }
class passwd { passwd chfn chsh rootok crontab }
class x_drawable { create destroy read write blend getattr setattr list_child
add_child remove_child list_property get_property set_property manage override
show hide send receive }
class x_screen { getattr setattr hide_cursor show_cursor saver_getattr
saver_setattr saver_hide saver_show }
class x_gc { create destroy getattr setattr use }
class x_font { create destroy getattr add_glyph remove_glyph use }
class x_colormap { create destroy read write getattr add_color remove_color
install uninstall use }
class x_property { create destroy read write append getattr setattr }
class x_selection { read write getattr setattr }
class x_cursor { create destroy read write getattr setattr use }
class x_client { destroy getattr setattr manage }
class x_device inherits x_device
class x_server { getattr setattr record debug grab manage }
class x_extension { query use }
class x_resource { read write }
class x_event { send receive }
class x_synthetic_event { send receive }
class netlink_route_socket inherits socket { nlmsg_read nlmsg_write }
class netlink_firewall_socket inherits socket { nlmsg_read nlmsg_write }
class netlink_tcpdiag_socket inherits socket { nlmsg_read nlmsg_write }
class netlink_nflog_socket inherits socket
class netlink_xfrm_socket inherits socket { nlmsg_read nlmsg_write }
class netlink_selinux_socket inherits socket
class netlink_audit_socket inherits socket { nlmsg_read nlmsg_write nlmsg_relay
nlmsg_readpriv nlmsg_tty_audit }
class netlink_ip6fw_socket inherits socket { nlmsg_read nlmsg_write }
class netlink_dnrt_socket inherits socket
class dbus { acquire_svc send_msg }
class nscd { getpwd getgrp gethost getstat admin shmempwd shmemgrp shmemhost
getserv shmemserv }
class association { sendto recvfrom setcontext polmatch }
class netlink_kobject_uevent_socket inherits socket
class appletalk_socket inherits socket
class packet { send recv relabelto flow_in flow_out forward_in forward_out }
class key { view read write search link setattr create }
class context { translate contains }
class dccp_socket inherits socket { node_bind name_connect }
class memprotect { mmap_zero }
class db_database inherits database { access install_module load_module
get_param set_param }
class db_table inherits database { use select update insert delete lock }
class db_procedure inherits database { execute entrypoint install }
class db_column inherits database { use select update insert }
class db_tuple { relabelfrom relabelto use select update insert delete }
Page 17