xref: /aosp_15_r20/external/selinux/libsepol/tests/policies/test-cond/refpolicy-base.conf (revision 2d543d20722ada2425b5bdab9d0d1d29470e7bba)
1*2d543d20SAndroid Build Coastguard Workerclass security
2*2d543d20SAndroid Build Coastguard Workerclass process
3*2d543d20SAndroid Build Coastguard Workerclass system
4*2d543d20SAndroid Build Coastguard Workerclass capability
5*2d543d20SAndroid Build Coastguard Workerclass filesystem
6*2d543d20SAndroid Build Coastguard Workerclass file
7*2d543d20SAndroid Build Coastguard Workerclass dir
8*2d543d20SAndroid Build Coastguard Workerclass fd
9*2d543d20SAndroid Build Coastguard Workerclass lnk_file
10*2d543d20SAndroid Build Coastguard Workerclass chr_file
11*2d543d20SAndroid Build Coastguard Workerclass blk_file
12*2d543d20SAndroid Build Coastguard Workerclass sock_file
13*2d543d20SAndroid Build Coastguard Workerclass fifo_file
14*2d543d20SAndroid Build Coastguard Workerclass socket
15*2d543d20SAndroid Build Coastguard Workerclass tcp_socket
16*2d543d20SAndroid Build Coastguard Workerclass udp_socket
17*2d543d20SAndroid Build Coastguard Workerclass rawip_socket
18*2d543d20SAndroid Build Coastguard Workerclass node
19*2d543d20SAndroid Build Coastguard Workerclass netif
20*2d543d20SAndroid Build Coastguard Workerclass netlink_socket
21*2d543d20SAndroid Build Coastguard Workerclass packet_socket
22*2d543d20SAndroid Build Coastguard Workerclass key_socket
23*2d543d20SAndroid Build Coastguard Workerclass unix_stream_socket
24*2d543d20SAndroid Build Coastguard Workerclass unix_dgram_socket
25*2d543d20SAndroid Build Coastguard Workerclass sem
26*2d543d20SAndroid Build Coastguard Workerclass msg
27*2d543d20SAndroid Build Coastguard Workerclass msgq
28*2d543d20SAndroid Build Coastguard Workerclass shm
29*2d543d20SAndroid Build Coastguard Workerclass ipc
30*2d543d20SAndroid Build Coastguard Workerclass passwd			# userspace
31*2d543d20SAndroid Build Coastguard Workerclass drawable			# userspace
32*2d543d20SAndroid Build Coastguard Workerclass window			# userspace
33*2d543d20SAndroid Build Coastguard Workerclass gc			# userspace
34*2d543d20SAndroid Build Coastguard Workerclass font			# userspace
35*2d543d20SAndroid Build Coastguard Workerclass colormap			# userspace
36*2d543d20SAndroid Build Coastguard Workerclass property			# userspace
37*2d543d20SAndroid Build Coastguard Workerclass cursor			# userspace
38*2d543d20SAndroid Build Coastguard Workerclass xclient			# userspace
39*2d543d20SAndroid Build Coastguard Workerclass xinput			# userspace
40*2d543d20SAndroid Build Coastguard Workerclass xserver			# userspace
41*2d543d20SAndroid Build Coastguard Workerclass xextension		# userspace
42*2d543d20SAndroid Build Coastguard Workerclass pax
43*2d543d20SAndroid Build Coastguard Workerclass netlink_route_socket
44*2d543d20SAndroid Build Coastguard Workerclass netlink_firewall_socket
45*2d543d20SAndroid Build Coastguard Workerclass netlink_tcpdiag_socket
46*2d543d20SAndroid Build Coastguard Workerclass netlink_nflog_socket
47*2d543d20SAndroid Build Coastguard Workerclass netlink_xfrm_socket
48*2d543d20SAndroid Build Coastguard Workerclass netlink_selinux_socket
49*2d543d20SAndroid Build Coastguard Workerclass netlink_audit_socket
50*2d543d20SAndroid Build Coastguard Workerclass netlink_ip6fw_socket
51*2d543d20SAndroid Build Coastguard Workerclass netlink_dnrt_socket
52*2d543d20SAndroid Build Coastguard Workerclass dbus			# userspace
53*2d543d20SAndroid Build Coastguard Workerclass nscd			# userspace
54*2d543d20SAndroid Build Coastguard Workerclass association
55*2d543d20SAndroid Build Coastguard Workerclass netlink_kobject_uevent_socket
56*2d543d20SAndroid Build Coastguard Workersid kernel
57*2d543d20SAndroid Build Coastguard Workersid security
58*2d543d20SAndroid Build Coastguard Workersid unlabeled
59*2d543d20SAndroid Build Coastguard Workersid fs
60*2d543d20SAndroid Build Coastguard Workersid file
61*2d543d20SAndroid Build Coastguard Workersid file_labels
62*2d543d20SAndroid Build Coastguard Workersid init
63*2d543d20SAndroid Build Coastguard Workersid any_socket
64*2d543d20SAndroid Build Coastguard Workersid port
65*2d543d20SAndroid Build Coastguard Workersid netif
66*2d543d20SAndroid Build Coastguard Workersid netmsg
67*2d543d20SAndroid Build Coastguard Workersid node
68*2d543d20SAndroid Build Coastguard Workersid igmp_packet
69*2d543d20SAndroid Build Coastguard Workersid icmp_socket
70*2d543d20SAndroid Build Coastguard Workersid tcp_socket
71*2d543d20SAndroid Build Coastguard Workersid sysctl_modprobe
72*2d543d20SAndroid Build Coastguard Workersid sysctl
73*2d543d20SAndroid Build Coastguard Workersid sysctl_fs
74*2d543d20SAndroid Build Coastguard Workersid sysctl_kernel
75*2d543d20SAndroid Build Coastguard Workersid sysctl_net
76*2d543d20SAndroid Build Coastguard Workersid sysctl_net_unix
77*2d543d20SAndroid Build Coastguard Workersid sysctl_vm
78*2d543d20SAndroid Build Coastguard Workersid sysctl_dev
79*2d543d20SAndroid Build Coastguard Workersid kmod
80*2d543d20SAndroid Build Coastguard Workersid policy
81*2d543d20SAndroid Build Coastguard Workersid scmp_packet
82*2d543d20SAndroid Build Coastguard Workersid devnull
83*2d543d20SAndroid Build Coastguard Workercommon file
84*2d543d20SAndroid Build Coastguard Worker{
85*2d543d20SAndroid Build Coastguard Worker	ioctl
86*2d543d20SAndroid Build Coastguard Worker	read
87*2d543d20SAndroid Build Coastguard Worker	write
88*2d543d20SAndroid Build Coastguard Worker	create
89*2d543d20SAndroid Build Coastguard Worker	getattr
90*2d543d20SAndroid Build Coastguard Worker	setattr
91*2d543d20SAndroid Build Coastguard Worker	lock
92*2d543d20SAndroid Build Coastguard Worker	relabelfrom
93*2d543d20SAndroid Build Coastguard Worker	relabelto
94*2d543d20SAndroid Build Coastguard Worker	append
95*2d543d20SAndroid Build Coastguard Worker	unlink
96*2d543d20SAndroid Build Coastguard Worker	link
97*2d543d20SAndroid Build Coastguard Worker	rename
98*2d543d20SAndroid Build Coastguard Worker	execute
99*2d543d20SAndroid Build Coastguard Worker	swapon
100*2d543d20SAndroid Build Coastguard Worker	quotaon
101*2d543d20SAndroid Build Coastguard Worker	mounton
102*2d543d20SAndroid Build Coastguard Worker}
103*2d543d20SAndroid Build Coastguard Workercommon socket
104*2d543d20SAndroid Build Coastguard Worker{
105*2d543d20SAndroid Build Coastguard Worker	ioctl
106*2d543d20SAndroid Build Coastguard Worker	read
107*2d543d20SAndroid Build Coastguard Worker	write
108*2d543d20SAndroid Build Coastguard Worker	create
109*2d543d20SAndroid Build Coastguard Worker	getattr
110*2d543d20SAndroid Build Coastguard Worker	setattr
111*2d543d20SAndroid Build Coastguard Worker	lock
112*2d543d20SAndroid Build Coastguard Worker	relabelfrom
113*2d543d20SAndroid Build Coastguard Worker	relabelto
114*2d543d20SAndroid Build Coastguard Worker	append
115*2d543d20SAndroid Build Coastguard Worker	bind
116*2d543d20SAndroid Build Coastguard Worker	connect
117*2d543d20SAndroid Build Coastguard Worker	listen
118*2d543d20SAndroid Build Coastguard Worker	accept
119*2d543d20SAndroid Build Coastguard Worker	getopt
120*2d543d20SAndroid Build Coastguard Worker	setopt
121*2d543d20SAndroid Build Coastguard Worker	shutdown
122*2d543d20SAndroid Build Coastguard Worker	recvfrom
123*2d543d20SAndroid Build Coastguard Worker	sendto
124*2d543d20SAndroid Build Coastguard Worker	recv_msg
125*2d543d20SAndroid Build Coastguard Worker	send_msg
126*2d543d20SAndroid Build Coastguard Worker	name_bind
127*2d543d20SAndroid Build Coastguard Worker}
128*2d543d20SAndroid Build Coastguard Workercommon ipc
129*2d543d20SAndroid Build Coastguard Worker{
130*2d543d20SAndroid Build Coastguard Worker	create
131*2d543d20SAndroid Build Coastguard Worker	destroy
132*2d543d20SAndroid Build Coastguard Worker	getattr
133*2d543d20SAndroid Build Coastguard Worker	setattr
134*2d543d20SAndroid Build Coastguard Worker	read
135*2d543d20SAndroid Build Coastguard Worker	write
136*2d543d20SAndroid Build Coastguard Worker	associate
137*2d543d20SAndroid Build Coastguard Worker	unix_read
138*2d543d20SAndroid Build Coastguard Worker	unix_write
139*2d543d20SAndroid Build Coastguard Worker}
140*2d543d20SAndroid Build Coastguard Workerclass filesystem
141*2d543d20SAndroid Build Coastguard Worker{
142*2d543d20SAndroid Build Coastguard Worker	mount
143*2d543d20SAndroid Build Coastguard Worker	remount
144*2d543d20SAndroid Build Coastguard Worker	unmount
145*2d543d20SAndroid Build Coastguard Worker	getattr
146*2d543d20SAndroid Build Coastguard Worker	relabelfrom
147*2d543d20SAndroid Build Coastguard Worker	relabelto
148*2d543d20SAndroid Build Coastguard Worker	transition
149*2d543d20SAndroid Build Coastguard Worker	associate
150*2d543d20SAndroid Build Coastguard Worker	quotamod
151*2d543d20SAndroid Build Coastguard Worker	quotaget
152*2d543d20SAndroid Build Coastguard Worker}
153*2d543d20SAndroid Build Coastguard Workerclass dir
154*2d543d20SAndroid Build Coastguard Workerinherits file
155*2d543d20SAndroid Build Coastguard Worker{
156*2d543d20SAndroid Build Coastguard Worker	add_name
157*2d543d20SAndroid Build Coastguard Worker	remove_name
158*2d543d20SAndroid Build Coastguard Worker	reparent
159*2d543d20SAndroid Build Coastguard Worker	search
160*2d543d20SAndroid Build Coastguard Worker	rmdir
161*2d543d20SAndroid Build Coastguard Worker}
162*2d543d20SAndroid Build Coastguard Workerclass file
163*2d543d20SAndroid Build Coastguard Workerinherits file
164*2d543d20SAndroid Build Coastguard Worker{
165*2d543d20SAndroid Build Coastguard Worker	execute_no_trans
166*2d543d20SAndroid Build Coastguard Worker	entrypoint
167*2d543d20SAndroid Build Coastguard Worker	execmod
168*2d543d20SAndroid Build Coastguard Worker}
169*2d543d20SAndroid Build Coastguard Workerclass lnk_file
170*2d543d20SAndroid Build Coastguard Workerinherits file
171*2d543d20SAndroid Build Coastguard Workerclass chr_file
172*2d543d20SAndroid Build Coastguard Workerinherits file
173*2d543d20SAndroid Build Coastguard Worker{
174*2d543d20SAndroid Build Coastguard Worker	execute_no_trans
175*2d543d20SAndroid Build Coastguard Worker	entrypoint
176*2d543d20SAndroid Build Coastguard Worker	execmod
177*2d543d20SAndroid Build Coastguard Worker}
178*2d543d20SAndroid Build Coastguard Workerclass blk_file
179*2d543d20SAndroid Build Coastguard Workerinherits file
180*2d543d20SAndroid Build Coastguard Workerclass sock_file
181*2d543d20SAndroid Build Coastguard Workerinherits file
182*2d543d20SAndroid Build Coastguard Workerclass fifo_file
183*2d543d20SAndroid Build Coastguard Workerinherits file
184*2d543d20SAndroid Build Coastguard Workerclass fd
185*2d543d20SAndroid Build Coastguard Worker{
186*2d543d20SAndroid Build Coastguard Worker	use
187*2d543d20SAndroid Build Coastguard Worker}
188*2d543d20SAndroid Build Coastguard Workerclass socket
189*2d543d20SAndroid Build Coastguard Workerinherits socket
190*2d543d20SAndroid Build Coastguard Workerclass tcp_socket
191*2d543d20SAndroid Build Coastguard Workerinherits socket
192*2d543d20SAndroid Build Coastguard Worker{
193*2d543d20SAndroid Build Coastguard Worker	connectto
194*2d543d20SAndroid Build Coastguard Worker	newconn
195*2d543d20SAndroid Build Coastguard Worker	acceptfrom
196*2d543d20SAndroid Build Coastguard Worker	node_bind
197*2d543d20SAndroid Build Coastguard Worker	name_connect
198*2d543d20SAndroid Build Coastguard Worker}
199*2d543d20SAndroid Build Coastguard Workerclass udp_socket
200*2d543d20SAndroid Build Coastguard Workerinherits socket
201*2d543d20SAndroid Build Coastguard Worker{
202*2d543d20SAndroid Build Coastguard Worker	node_bind
203*2d543d20SAndroid Build Coastguard Worker}
204*2d543d20SAndroid Build Coastguard Workerclass rawip_socket
205*2d543d20SAndroid Build Coastguard Workerinherits socket
206*2d543d20SAndroid Build Coastguard Worker{
207*2d543d20SAndroid Build Coastguard Worker	node_bind
208*2d543d20SAndroid Build Coastguard Worker}
209*2d543d20SAndroid Build Coastguard Workerclass node
210*2d543d20SAndroid Build Coastguard Worker{
211*2d543d20SAndroid Build Coastguard Worker	tcp_recv
212*2d543d20SAndroid Build Coastguard Worker	tcp_send
213*2d543d20SAndroid Build Coastguard Worker	udp_recv
214*2d543d20SAndroid Build Coastguard Worker	udp_send
215*2d543d20SAndroid Build Coastguard Worker	rawip_recv
216*2d543d20SAndroid Build Coastguard Worker	rawip_send
217*2d543d20SAndroid Build Coastguard Worker	enforce_dest
218*2d543d20SAndroid Build Coastguard Worker}
219*2d543d20SAndroid Build Coastguard Workerclass netif
220*2d543d20SAndroid Build Coastguard Worker{
221*2d543d20SAndroid Build Coastguard Worker	tcp_recv
222*2d543d20SAndroid Build Coastguard Worker	tcp_send
223*2d543d20SAndroid Build Coastguard Worker	udp_recv
224*2d543d20SAndroid Build Coastguard Worker	udp_send
225*2d543d20SAndroid Build Coastguard Worker	rawip_recv
226*2d543d20SAndroid Build Coastguard Worker	rawip_send
227*2d543d20SAndroid Build Coastguard Worker}
228*2d543d20SAndroid Build Coastguard Workerclass netlink_socket
229*2d543d20SAndroid Build Coastguard Workerinherits socket
230*2d543d20SAndroid Build Coastguard Workerclass packet_socket
231*2d543d20SAndroid Build Coastguard Workerinherits socket
232*2d543d20SAndroid Build Coastguard Workerclass key_socket
233*2d543d20SAndroid Build Coastguard Workerinherits socket
234*2d543d20SAndroid Build Coastguard Workerclass unix_stream_socket
235*2d543d20SAndroid Build Coastguard Workerinherits socket
236*2d543d20SAndroid Build Coastguard Worker{
237*2d543d20SAndroid Build Coastguard Worker	connectto
238*2d543d20SAndroid Build Coastguard Worker	newconn
239*2d543d20SAndroid Build Coastguard Worker	acceptfrom
240*2d543d20SAndroid Build Coastguard Worker}
241*2d543d20SAndroid Build Coastguard Workerclass unix_dgram_socket
242*2d543d20SAndroid Build Coastguard Workerinherits socket
243*2d543d20SAndroid Build Coastguard Workerclass process
244*2d543d20SAndroid Build Coastguard Worker{
245*2d543d20SAndroid Build Coastguard Worker	fork
246*2d543d20SAndroid Build Coastguard Worker	transition
247*2d543d20SAndroid Build Coastguard Worker	sigchld # commonly granted from child to parent
248*2d543d20SAndroid Build Coastguard Worker	sigkill # cannot be caught or ignored
249*2d543d20SAndroid Build Coastguard Worker	sigstop # cannot be caught or ignored
250*2d543d20SAndroid Build Coastguard Worker	signull # for kill(pid, 0)
251*2d543d20SAndroid Build Coastguard Worker	signal  # all other signals
252*2d543d20SAndroid Build Coastguard Worker	ptrace
253*2d543d20SAndroid Build Coastguard Worker	getsched
254*2d543d20SAndroid Build Coastguard Worker	setsched
255*2d543d20SAndroid Build Coastguard Worker	getsession
256*2d543d20SAndroid Build Coastguard Worker	getpgid
257*2d543d20SAndroid Build Coastguard Worker	setpgid
258*2d543d20SAndroid Build Coastguard Worker	getcap
259*2d543d20SAndroid Build Coastguard Worker	setcap
260*2d543d20SAndroid Build Coastguard Worker	share
261*2d543d20SAndroid Build Coastguard Worker	getattr
262*2d543d20SAndroid Build Coastguard Worker	setexec
263*2d543d20SAndroid Build Coastguard Worker	setfscreate
264*2d543d20SAndroid Build Coastguard Worker	noatsecure
265*2d543d20SAndroid Build Coastguard Worker	siginh
266*2d543d20SAndroid Build Coastguard Worker	setrlimit
267*2d543d20SAndroid Build Coastguard Worker	rlimitinh
268*2d543d20SAndroid Build Coastguard Worker	dyntransition
269*2d543d20SAndroid Build Coastguard Worker	setcurrent
270*2d543d20SAndroid Build Coastguard Worker	execmem
271*2d543d20SAndroid Build Coastguard Worker	execstack
272*2d543d20SAndroid Build Coastguard Worker	execheap
273*2d543d20SAndroid Build Coastguard Worker}
274*2d543d20SAndroid Build Coastguard Workerclass ipc
275*2d543d20SAndroid Build Coastguard Workerinherits ipc
276*2d543d20SAndroid Build Coastguard Workerclass sem
277*2d543d20SAndroid Build Coastguard Workerinherits ipc
278*2d543d20SAndroid Build Coastguard Workerclass msgq
279*2d543d20SAndroid Build Coastguard Workerinherits ipc
280*2d543d20SAndroid Build Coastguard Worker{
281*2d543d20SAndroid Build Coastguard Worker	enqueue
282*2d543d20SAndroid Build Coastguard Worker}
283*2d543d20SAndroid Build Coastguard Workerclass msg
284*2d543d20SAndroid Build Coastguard Worker{
285*2d543d20SAndroid Build Coastguard Worker	send
286*2d543d20SAndroid Build Coastguard Worker	receive
287*2d543d20SAndroid Build Coastguard Worker}
288*2d543d20SAndroid Build Coastguard Workerclass shm
289*2d543d20SAndroid Build Coastguard Workerinherits ipc
290*2d543d20SAndroid Build Coastguard Worker{
291*2d543d20SAndroid Build Coastguard Worker	lock
292*2d543d20SAndroid Build Coastguard Worker}
293*2d543d20SAndroid Build Coastguard Workerclass security
294*2d543d20SAndroid Build Coastguard Worker{
295*2d543d20SAndroid Build Coastguard Worker	compute_av
296*2d543d20SAndroid Build Coastguard Worker	compute_create
297*2d543d20SAndroid Build Coastguard Worker	compute_member
298*2d543d20SAndroid Build Coastguard Worker	check_context
299*2d543d20SAndroid Build Coastguard Worker	load_policy
300*2d543d20SAndroid Build Coastguard Worker	compute_relabel
301*2d543d20SAndroid Build Coastguard Worker	compute_user
302*2d543d20SAndroid Build Coastguard Worker	setenforce     # was avc_toggle in system class
303*2d543d20SAndroid Build Coastguard Worker	setbool
304*2d543d20SAndroid Build Coastguard Worker	setsecparam
305*2d543d20SAndroid Build Coastguard Worker	setcheckreqprot
306*2d543d20SAndroid Build Coastguard Worker}
307*2d543d20SAndroid Build Coastguard Workerclass system
308*2d543d20SAndroid Build Coastguard Worker{
309*2d543d20SAndroid Build Coastguard Worker	ipc_info
310*2d543d20SAndroid Build Coastguard Worker	syslog_read
311*2d543d20SAndroid Build Coastguard Worker	syslog_mod
312*2d543d20SAndroid Build Coastguard Worker	syslog_console
313*2d543d20SAndroid Build Coastguard Worker}
314*2d543d20SAndroid Build Coastguard Workerclass capability
315*2d543d20SAndroid Build Coastguard Worker{
316*2d543d20SAndroid Build Coastguard Worker	chown
317*2d543d20SAndroid Build Coastguard Worker	dac_override
318*2d543d20SAndroid Build Coastguard Worker	dac_read_search
319*2d543d20SAndroid Build Coastguard Worker	fowner
320*2d543d20SAndroid Build Coastguard Worker	fsetid
321*2d543d20SAndroid Build Coastguard Worker	kill
322*2d543d20SAndroid Build Coastguard Worker	setgid
323*2d543d20SAndroid Build Coastguard Worker	setuid
324*2d543d20SAndroid Build Coastguard Worker	setpcap
325*2d543d20SAndroid Build Coastguard Worker	linux_immutable
326*2d543d20SAndroid Build Coastguard Worker	net_bind_service
327*2d543d20SAndroid Build Coastguard Worker	net_broadcast
328*2d543d20SAndroid Build Coastguard Worker	net_admin
329*2d543d20SAndroid Build Coastguard Worker	net_raw
330*2d543d20SAndroid Build Coastguard Worker	ipc_lock
331*2d543d20SAndroid Build Coastguard Worker	ipc_owner
332*2d543d20SAndroid Build Coastguard Worker	sys_module
333*2d543d20SAndroid Build Coastguard Worker	sys_rawio
334*2d543d20SAndroid Build Coastguard Worker	sys_chroot
335*2d543d20SAndroid Build Coastguard Worker	sys_ptrace
336*2d543d20SAndroid Build Coastguard Worker	sys_pacct
337*2d543d20SAndroid Build Coastguard Worker	sys_admin
338*2d543d20SAndroid Build Coastguard Worker	sys_boot
339*2d543d20SAndroid Build Coastguard Worker	sys_nice
340*2d543d20SAndroid Build Coastguard Worker	sys_resource
341*2d543d20SAndroid Build Coastguard Worker	sys_time
342*2d543d20SAndroid Build Coastguard Worker	sys_tty_config
343*2d543d20SAndroid Build Coastguard Worker	mknod
344*2d543d20SAndroid Build Coastguard Worker	lease
345*2d543d20SAndroid Build Coastguard Worker	audit_write
346*2d543d20SAndroid Build Coastguard Worker	audit_control
347*2d543d20SAndroid Build Coastguard Worker}
348*2d543d20SAndroid Build Coastguard Workerclass passwd
349*2d543d20SAndroid Build Coastguard Worker{
350*2d543d20SAndroid Build Coastguard Worker	passwd	# change another user passwd
351*2d543d20SAndroid Build Coastguard Worker	chfn	# change another user finger info
352*2d543d20SAndroid Build Coastguard Worker	chsh	# change another user shell
353*2d543d20SAndroid Build Coastguard Worker	rootok  # pam_rootok check (skip auth)
354*2d543d20SAndroid Build Coastguard Worker	crontab # crontab on another user
355*2d543d20SAndroid Build Coastguard Worker}
356*2d543d20SAndroid Build Coastguard Workerclass drawable
357*2d543d20SAndroid Build Coastguard Worker{
358*2d543d20SAndroid Build Coastguard Worker	create
359*2d543d20SAndroid Build Coastguard Worker	destroy
360*2d543d20SAndroid Build Coastguard Worker	draw
361*2d543d20SAndroid Build Coastguard Worker	copy
362*2d543d20SAndroid Build Coastguard Worker	getattr
363*2d543d20SAndroid Build Coastguard Worker}
364*2d543d20SAndroid Build Coastguard Workerclass gc
365*2d543d20SAndroid Build Coastguard Worker{
366*2d543d20SAndroid Build Coastguard Worker	create
367*2d543d20SAndroid Build Coastguard Worker	free
368*2d543d20SAndroid Build Coastguard Worker	getattr
369*2d543d20SAndroid Build Coastguard Worker	setattr
370*2d543d20SAndroid Build Coastguard Worker}
371*2d543d20SAndroid Build Coastguard Workerclass window
372*2d543d20SAndroid Build Coastguard Worker{
373*2d543d20SAndroid Build Coastguard Worker	addchild
374*2d543d20SAndroid Build Coastguard Worker	create
375*2d543d20SAndroid Build Coastguard Worker	destroy
376*2d543d20SAndroid Build Coastguard Worker	map
377*2d543d20SAndroid Build Coastguard Worker	unmap
378*2d543d20SAndroid Build Coastguard Worker	chstack
379*2d543d20SAndroid Build Coastguard Worker	chproplist
380*2d543d20SAndroid Build Coastguard Worker	chprop
381*2d543d20SAndroid Build Coastguard Worker	listprop
382*2d543d20SAndroid Build Coastguard Worker	getattr
383*2d543d20SAndroid Build Coastguard Worker	setattr
384*2d543d20SAndroid Build Coastguard Worker	setfocus
385*2d543d20SAndroid Build Coastguard Worker	move
386*2d543d20SAndroid Build Coastguard Worker	chselection
387*2d543d20SAndroid Build Coastguard Worker	chparent
388*2d543d20SAndroid Build Coastguard Worker	ctrllife
389*2d543d20SAndroid Build Coastguard Worker	enumerate
390*2d543d20SAndroid Build Coastguard Worker	transparent
391*2d543d20SAndroid Build Coastguard Worker	mousemotion
392*2d543d20SAndroid Build Coastguard Worker	clientcomevent
393*2d543d20SAndroid Build Coastguard Worker	inputevent
394*2d543d20SAndroid Build Coastguard Worker	drawevent
395*2d543d20SAndroid Build Coastguard Worker	windowchangeevent
396*2d543d20SAndroid Build Coastguard Worker	windowchangerequest
397*2d543d20SAndroid Build Coastguard Worker	serverchangeevent
398*2d543d20SAndroid Build Coastguard Worker	extensionevent
399*2d543d20SAndroid Build Coastguard Worker}
400*2d543d20SAndroid Build Coastguard Workerclass font
401*2d543d20SAndroid Build Coastguard Worker{
402*2d543d20SAndroid Build Coastguard Worker	load
403*2d543d20SAndroid Build Coastguard Worker	free
404*2d543d20SAndroid Build Coastguard Worker	getattr
405*2d543d20SAndroid Build Coastguard Worker	use
406*2d543d20SAndroid Build Coastguard Worker}
407*2d543d20SAndroid Build Coastguard Workerclass colormap
408*2d543d20SAndroid Build Coastguard Worker{
409*2d543d20SAndroid Build Coastguard Worker	create
410*2d543d20SAndroid Build Coastguard Worker	free
411*2d543d20SAndroid Build Coastguard Worker	install
412*2d543d20SAndroid Build Coastguard Worker	uninstall
413*2d543d20SAndroid Build Coastguard Worker	list
414*2d543d20SAndroid Build Coastguard Worker	read
415*2d543d20SAndroid Build Coastguard Worker	store
416*2d543d20SAndroid Build Coastguard Worker	getattr
417*2d543d20SAndroid Build Coastguard Worker	setattr
418*2d543d20SAndroid Build Coastguard Worker}
419*2d543d20SAndroid Build Coastguard Workerclass property
420*2d543d20SAndroid Build Coastguard Worker{
421*2d543d20SAndroid Build Coastguard Worker	create
422*2d543d20SAndroid Build Coastguard Worker	free
423*2d543d20SAndroid Build Coastguard Worker	read
424*2d543d20SAndroid Build Coastguard Worker	write
425*2d543d20SAndroid Build Coastguard Worker}
426*2d543d20SAndroid Build Coastguard Workerclass cursor
427*2d543d20SAndroid Build Coastguard Worker{
428*2d543d20SAndroid Build Coastguard Worker	create
429*2d543d20SAndroid Build Coastguard Worker	createglyph
430*2d543d20SAndroid Build Coastguard Worker	free
431*2d543d20SAndroid Build Coastguard Worker	assign
432*2d543d20SAndroid Build Coastguard Worker	setattr
433*2d543d20SAndroid Build Coastguard Worker}
434*2d543d20SAndroid Build Coastguard Workerclass xclient
435*2d543d20SAndroid Build Coastguard Worker{
436*2d543d20SAndroid Build Coastguard Worker	kill
437*2d543d20SAndroid Build Coastguard Worker}
438*2d543d20SAndroid Build Coastguard Workerclass xinput
439*2d543d20SAndroid Build Coastguard Worker{
440*2d543d20SAndroid Build Coastguard Worker	lookup
441*2d543d20SAndroid Build Coastguard Worker	getattr
442*2d543d20SAndroid Build Coastguard Worker	setattr
443*2d543d20SAndroid Build Coastguard Worker	setfocus
444*2d543d20SAndroid Build Coastguard Worker	warppointer
445*2d543d20SAndroid Build Coastguard Worker	activegrab
446*2d543d20SAndroid Build Coastguard Worker	passivegrab
447*2d543d20SAndroid Build Coastguard Worker	ungrab
448*2d543d20SAndroid Build Coastguard Worker	bell
449*2d543d20SAndroid Build Coastguard Worker	mousemotion
450*2d543d20SAndroid Build Coastguard Worker	relabelinput
451*2d543d20SAndroid Build Coastguard Worker}
452*2d543d20SAndroid Build Coastguard Workerclass xserver
453*2d543d20SAndroid Build Coastguard Worker{
454*2d543d20SAndroid Build Coastguard Worker	screensaver
455*2d543d20SAndroid Build Coastguard Worker	gethostlist
456*2d543d20SAndroid Build Coastguard Worker	sethostlist
457*2d543d20SAndroid Build Coastguard Worker	getfontpath
458*2d543d20SAndroid Build Coastguard Worker	setfontpath
459*2d543d20SAndroid Build Coastguard Worker	getattr
460*2d543d20SAndroid Build Coastguard Worker	grab
461*2d543d20SAndroid Build Coastguard Worker	ungrab
462*2d543d20SAndroid Build Coastguard Worker}
463*2d543d20SAndroid Build Coastguard Workerclass xextension
464*2d543d20SAndroid Build Coastguard Worker{
465*2d543d20SAndroid Build Coastguard Worker	query
466*2d543d20SAndroid Build Coastguard Worker	use
467*2d543d20SAndroid Build Coastguard Worker}
468*2d543d20SAndroid Build Coastguard Workerclass pax
469*2d543d20SAndroid Build Coastguard Worker{
470*2d543d20SAndroid Build Coastguard Worker	pageexec	# Paging based non-executable pages
471*2d543d20SAndroid Build Coastguard Worker	emutramp	# Emulate trampolines
472*2d543d20SAndroid Build Coastguard Worker	mprotect	# Restrict mprotect()
473*2d543d20SAndroid Build Coastguard Worker	randmmap	# Randomize mmap() base
474*2d543d20SAndroid Build Coastguard Worker	randexec	# Randomize ET_EXEC base
475*2d543d20SAndroid Build Coastguard Worker	segmexec	# Segmentation based non-executable pages
476*2d543d20SAndroid Build Coastguard Worker}
477*2d543d20SAndroid Build Coastguard Workerclass netlink_route_socket
478*2d543d20SAndroid Build Coastguard Workerinherits socket
479*2d543d20SAndroid Build Coastguard Worker{
480*2d543d20SAndroid Build Coastguard Worker	nlmsg_read
481*2d543d20SAndroid Build Coastguard Worker	nlmsg_write
482*2d543d20SAndroid Build Coastguard Worker}
483*2d543d20SAndroid Build Coastguard Workerclass netlink_firewall_socket
484*2d543d20SAndroid Build Coastguard Workerinherits socket
485*2d543d20SAndroid Build Coastguard Worker{
486*2d543d20SAndroid Build Coastguard Worker	nlmsg_read
487*2d543d20SAndroid Build Coastguard Worker	nlmsg_write
488*2d543d20SAndroid Build Coastguard Worker}
489*2d543d20SAndroid Build Coastguard Workerclass netlink_tcpdiag_socket
490*2d543d20SAndroid Build Coastguard Workerinherits socket
491*2d543d20SAndroid Build Coastguard Worker{
492*2d543d20SAndroid Build Coastguard Worker	nlmsg_read
493*2d543d20SAndroid Build Coastguard Worker	nlmsg_write
494*2d543d20SAndroid Build Coastguard Worker}
495*2d543d20SAndroid Build Coastguard Workerclass netlink_nflog_socket
496*2d543d20SAndroid Build Coastguard Workerinherits socket
497*2d543d20SAndroid Build Coastguard Workerclass netlink_xfrm_socket
498*2d543d20SAndroid Build Coastguard Workerinherits socket
499*2d543d20SAndroid Build Coastguard Worker{
500*2d543d20SAndroid Build Coastguard Worker	nlmsg_read
501*2d543d20SAndroid Build Coastguard Worker	nlmsg_write
502*2d543d20SAndroid Build Coastguard Worker}
503*2d543d20SAndroid Build Coastguard Workerclass netlink_selinux_socket
504*2d543d20SAndroid Build Coastguard Workerinherits socket
505*2d543d20SAndroid Build Coastguard Workerclass netlink_audit_socket
506*2d543d20SAndroid Build Coastguard Workerinherits socket
507*2d543d20SAndroid Build Coastguard Worker{
508*2d543d20SAndroid Build Coastguard Worker	nlmsg_read
509*2d543d20SAndroid Build Coastguard Worker	nlmsg_write
510*2d543d20SAndroid Build Coastguard Worker	nlmsg_relay
511*2d543d20SAndroid Build Coastguard Worker	nlmsg_readpriv
512*2d543d20SAndroid Build Coastguard Worker}
513*2d543d20SAndroid Build Coastguard Workerclass netlink_ip6fw_socket
514*2d543d20SAndroid Build Coastguard Workerinherits socket
515*2d543d20SAndroid Build Coastguard Worker{
516*2d543d20SAndroid Build Coastguard Worker	nlmsg_read
517*2d543d20SAndroid Build Coastguard Worker	nlmsg_write
518*2d543d20SAndroid Build Coastguard Worker}
519*2d543d20SAndroid Build Coastguard Workerclass netlink_dnrt_socket
520*2d543d20SAndroid Build Coastguard Workerinherits socket
521*2d543d20SAndroid Build Coastguard Workerclass dbus
522*2d543d20SAndroid Build Coastguard Worker{
523*2d543d20SAndroid Build Coastguard Worker	acquire_svc
524*2d543d20SAndroid Build Coastguard Worker	send_msg
525*2d543d20SAndroid Build Coastguard Worker}
526*2d543d20SAndroid Build Coastguard Workerclass nscd
527*2d543d20SAndroid Build Coastguard Worker{
528*2d543d20SAndroid Build Coastguard Worker	getpwd
529*2d543d20SAndroid Build Coastguard Worker	getgrp
530*2d543d20SAndroid Build Coastguard Worker	gethost
531*2d543d20SAndroid Build Coastguard Worker	getstat
532*2d543d20SAndroid Build Coastguard Worker	admin
533*2d543d20SAndroid Build Coastguard Worker	shmempwd
534*2d543d20SAndroid Build Coastguard Worker	shmemgrp
535*2d543d20SAndroid Build Coastguard Worker	shmemhost
536*2d543d20SAndroid Build Coastguard Worker}
537*2d543d20SAndroid Build Coastguard Workerclass association
538*2d543d20SAndroid Build Coastguard Worker{
539*2d543d20SAndroid Build Coastguard Worker	sendto
540*2d543d20SAndroid Build Coastguard Worker	recvfrom
541*2d543d20SAndroid Build Coastguard Worker	setcontext
542*2d543d20SAndroid Build Coastguard Worker}
543*2d543d20SAndroid Build Coastguard Workerclass netlink_kobject_uevent_socket
544*2d543d20SAndroid Build Coastguard Workerinherits socket
545*2d543d20SAndroid Build Coastguard Workersensitivity s0;
546*2d543d20SAndroid Build Coastguard Workerdominance { s0 }
547*2d543d20SAndroid Build Coastguard Workercategory c0; category c1; category c2; category c3;
548*2d543d20SAndroid Build Coastguard Workercategory c4; category c5; category c6; category c7;
549*2d543d20SAndroid Build Coastguard Workercategory c8; category c9; category c10; category c11;
550*2d543d20SAndroid Build Coastguard Workercategory c12; category c13; category c14; category c15;
551*2d543d20SAndroid Build Coastguard Workercategory c16; category c17; category c18; category c19;
552*2d543d20SAndroid Build Coastguard Workercategory c20; category c21; category c22; category c23;
553*2d543d20SAndroid Build Coastguard Workercategory c24; category c25; category c26; category c27;
554*2d543d20SAndroid Build Coastguard Workercategory c28; category c29; category c30; category c31;
555*2d543d20SAndroid Build Coastguard Workercategory c32; category c33; category c34; category c35;
556*2d543d20SAndroid Build Coastguard Workercategory c36; category c37; category c38; category c39;
557*2d543d20SAndroid Build Coastguard Workercategory c40; category c41; category c42; category c43;
558*2d543d20SAndroid Build Coastguard Workercategory c44; category c45; category c46; category c47;
559*2d543d20SAndroid Build Coastguard Workercategory c48; category c49; category c50; category c51;
560*2d543d20SAndroid Build Coastguard Workercategory c52; category c53; category c54; category c55;
561*2d543d20SAndroid Build Coastguard Workercategory c56; category c57; category c58; category c59;
562*2d543d20SAndroid Build Coastguard Workercategory c60; category c61; category c62; category c63;
563*2d543d20SAndroid Build Coastguard Workercategory c64; category c65; category c66; category c67;
564*2d543d20SAndroid Build Coastguard Workercategory c68; category c69; category c70; category c71;
565*2d543d20SAndroid Build Coastguard Workercategory c72; category c73; category c74; category c75;
566*2d543d20SAndroid Build Coastguard Workercategory c76; category c77; category c78; category c79;
567*2d543d20SAndroid Build Coastguard Workercategory c80; category c81; category c82; category c83;
568*2d543d20SAndroid Build Coastguard Workercategory c84; category c85; category c86; category c87;
569*2d543d20SAndroid Build Coastguard Workercategory c88; category c89; category c90; category c91;
570*2d543d20SAndroid Build Coastguard Workercategory c92; category c93; category c94; category c95;
571*2d543d20SAndroid Build Coastguard Workercategory c96; category c97; category c98; category c99;
572*2d543d20SAndroid Build Coastguard Workercategory c100; category c101; category c102; category c103;
573*2d543d20SAndroid Build Coastguard Workercategory c104; category c105; category c106; category c107;
574*2d543d20SAndroid Build Coastguard Workercategory c108; category c109; category c110; category c111;
575*2d543d20SAndroid Build Coastguard Workercategory c112; category c113; category c114; category c115;
576*2d543d20SAndroid Build Coastguard Workercategory c116; category c117; category c118; category c119;
577*2d543d20SAndroid Build Coastguard Workercategory c120; category c121; category c122; category c123;
578*2d543d20SAndroid Build Coastguard Workercategory c124; category c125; category c126; category c127;
579*2d543d20SAndroid Build Coastguard Workercategory c128; category c129; category c130; category c131;
580*2d543d20SAndroid Build Coastguard Workercategory c132; category c133; category c134; category c135;
581*2d543d20SAndroid Build Coastguard Workercategory c136; category c137; category c138; category c139;
582*2d543d20SAndroid Build Coastguard Workercategory c140; category c141; category c142; category c143;
583*2d543d20SAndroid Build Coastguard Workercategory c144; category c145; category c146; category c147;
584*2d543d20SAndroid Build Coastguard Workercategory c148; category c149; category c150; category c151;
585*2d543d20SAndroid Build Coastguard Workercategory c152; category c153; category c154; category c155;
586*2d543d20SAndroid Build Coastguard Workercategory c156; category c157; category c158; category c159;
587*2d543d20SAndroid Build Coastguard Workercategory c160; category c161; category c162; category c163;
588*2d543d20SAndroid Build Coastguard Workercategory c164; category c165; category c166; category c167;
589*2d543d20SAndroid Build Coastguard Workercategory c168; category c169; category c170; category c171;
590*2d543d20SAndroid Build Coastguard Workercategory c172; category c173; category c174; category c175;
591*2d543d20SAndroid Build Coastguard Workercategory c176; category c177; category c178; category c179;
592*2d543d20SAndroid Build Coastguard Workercategory c180; category c181; category c182; category c183;
593*2d543d20SAndroid Build Coastguard Workercategory c184; category c185; category c186; category c187;
594*2d543d20SAndroid Build Coastguard Workercategory c188; category c189; category c190; category c191;
595*2d543d20SAndroid Build Coastguard Workercategory c192; category c193; category c194; category c195;
596*2d543d20SAndroid Build Coastguard Workercategory c196; category c197; category c198; category c199;
597*2d543d20SAndroid Build Coastguard Workercategory c200; category c201; category c202; category c203;
598*2d543d20SAndroid Build Coastguard Workercategory c204; category c205; category c206; category c207;
599*2d543d20SAndroid Build Coastguard Workercategory c208; category c209; category c210; category c211;
600*2d543d20SAndroid Build Coastguard Workercategory c212; category c213; category c214; category c215;
601*2d543d20SAndroid Build Coastguard Workercategory c216; category c217; category c218; category c219;
602*2d543d20SAndroid Build Coastguard Workercategory c220; category c221; category c222; category c223;
603*2d543d20SAndroid Build Coastguard Workercategory c224; category c225; category c226; category c227;
604*2d543d20SAndroid Build Coastguard Workercategory c228; category c229; category c230; category c231;
605*2d543d20SAndroid Build Coastguard Workercategory c232; category c233; category c234; category c235;
606*2d543d20SAndroid Build Coastguard Workercategory c236; category c237; category c238; category c239;
607*2d543d20SAndroid Build Coastguard Workercategory c240; category c241; category c242; category c243;
608*2d543d20SAndroid Build Coastguard Workercategory c244; category c245; category c246; category c247;
609*2d543d20SAndroid Build Coastguard Workercategory c248; category c249; category c250; category c251;
610*2d543d20SAndroid Build Coastguard Workercategory c252; category c253; category c254; category c255;
611*2d543d20SAndroid Build Coastguard Workerlevel s0:c0.c255;
612*2d543d20SAndroid Build Coastguard Workermlsconstrain file { write setattr append unlink link rename
613*2d543d20SAndroid Build Coastguard Worker		    ioctl lock execute relabelfrom } (h1 dom h2);
614*2d543d20SAndroid Build Coastguard Workermlsconstrain file { create relabelto } ((h1 dom h2) and (l2 eq h2));
615*2d543d20SAndroid Build Coastguard Workermlsconstrain file { read } ((h1 dom h2) or ( t2 == domain ) or ( t1 == mlsfileread ));
616*2d543d20SAndroid Build Coastguard Workermlsconstrain { dir lnk_file chr_file blk_file sock_file fifo_file } { relabelfrom }
617*2d543d20SAndroid Build Coastguard Worker	( h1 dom h2 );
618*2d543d20SAndroid Build Coastguard Workermlsconstrain { dir lnk_file chr_file blk_file sock_file fifo_file } { create relabelto }
619*2d543d20SAndroid Build Coastguard Worker	(( h1 dom h2 ) and ( l2 eq h2 ));
620*2d543d20SAndroid Build Coastguard Workermlsconstrain process { ptrace } ( h1 dom h2 );
621*2d543d20SAndroid Build Coastguard Workermlsconstrain process { sigkill sigstop } ( h1 dom h2 ) or
622*2d543d20SAndroid Build Coastguard Worker		( t1 == mcskillall );
623*2d543d20SAndroid Build Coastguard Workermlsconstrain xextension query ( t1 == mlsfileread );
624*2d543d20SAndroid Build Coastguard Workerattribute netif_type;
625*2d543d20SAndroid Build Coastguard Workerattribute node_type;
626*2d543d20SAndroid Build Coastguard Workerattribute port_type;
627*2d543d20SAndroid Build Coastguard Workerattribute reserved_port_type;
628*2d543d20SAndroid Build Coastguard Workerattribute device_node;
629*2d543d20SAndroid Build Coastguard Workerattribute memory_raw_read;
630*2d543d20SAndroid Build Coastguard Workerattribute memory_raw_write;
631*2d543d20SAndroid Build Coastguard Workerattribute domain;
632*2d543d20SAndroid Build Coastguard Workerattribute unconfined_domain_type;
633*2d543d20SAndroid Build Coastguard Workerattribute set_curr_context;
634*2d543d20SAndroid Build Coastguard Workerattribute entry_type;
635*2d543d20SAndroid Build Coastguard Workerattribute privfd;
636*2d543d20SAndroid Build Coastguard Workerattribute can_change_process_identity;
637*2d543d20SAndroid Build Coastguard Workerattribute can_change_process_role;
638*2d543d20SAndroid Build Coastguard Workerattribute can_change_object_identity;
639*2d543d20SAndroid Build Coastguard Workerattribute can_system_change;
640*2d543d20SAndroid Build Coastguard Workerattribute process_user_target;
641*2d543d20SAndroid Build Coastguard Workerattribute cron_source_domain;
642*2d543d20SAndroid Build Coastguard Workerattribute cron_job_domain;
643*2d543d20SAndroid Build Coastguard Workerattribute process_uncond_exempt;	# add userhelperdomain to this one
644*2d543d20SAndroid Build Coastguard Workerattribute file_type;
645*2d543d20SAndroid Build Coastguard Workerattribute lockfile;
646*2d543d20SAndroid Build Coastguard Workerattribute mountpoint;
647*2d543d20SAndroid Build Coastguard Workerattribute pidfile;
648*2d543d20SAndroid Build Coastguard Workerattribute polydir;
649*2d543d20SAndroid Build Coastguard Workerattribute usercanread;
650*2d543d20SAndroid Build Coastguard Workerattribute polyparent;
651*2d543d20SAndroid Build Coastguard Workerattribute polymember;
652*2d543d20SAndroid Build Coastguard Workerattribute security_file_type;
653*2d543d20SAndroid Build Coastguard Workerattribute tmpfile;
654*2d543d20SAndroid Build Coastguard Workerattribute tmpfsfile;
655*2d543d20SAndroid Build Coastguard Workerattribute filesystem_type;
656*2d543d20SAndroid Build Coastguard Workerattribute noxattrfs;
657*2d543d20SAndroid Build Coastguard Workerattribute can_load_kernmodule;
658*2d543d20SAndroid Build Coastguard Workerattribute can_receive_kernel_messages;
659*2d543d20SAndroid Build Coastguard Workerattribute kern_unconfined;
660*2d543d20SAndroid Build Coastguard Workerattribute proc_type;
661*2d543d20SAndroid Build Coastguard Workerattribute sysctl_type;
662*2d543d20SAndroid Build Coastguard Workerattribute mcskillall;
663*2d543d20SAndroid Build Coastguard Workerattribute mlsfileread;
664*2d543d20SAndroid Build Coastguard Workerattribute mlsfilereadtoclr;
665*2d543d20SAndroid Build Coastguard Workerattribute mlsfilewrite;
666*2d543d20SAndroid Build Coastguard Workerattribute mlsfilewritetoclr;
667*2d543d20SAndroid Build Coastguard Workerattribute mlsfileupgrade;
668*2d543d20SAndroid Build Coastguard Workerattribute mlsfiledowngrade;
669*2d543d20SAndroid Build Coastguard Workerattribute mlsnetread;
670*2d543d20SAndroid Build Coastguard Workerattribute mlsnetreadtoclr;
671*2d543d20SAndroid Build Coastguard Workerattribute mlsnetwrite;
672*2d543d20SAndroid Build Coastguard Workerattribute mlsnetwritetoclr;
673*2d543d20SAndroid Build Coastguard Workerattribute mlsnetupgrade;
674*2d543d20SAndroid Build Coastguard Workerattribute mlsnetdowngrade;
675*2d543d20SAndroid Build Coastguard Workerattribute mlsnetrecvall;
676*2d543d20SAndroid Build Coastguard Workerattribute mlsipcread;
677*2d543d20SAndroid Build Coastguard Workerattribute mlsipcreadtoclr;
678*2d543d20SAndroid Build Coastguard Workerattribute mlsipcwrite;
679*2d543d20SAndroid Build Coastguard Workerattribute mlsipcwritetoclr;
680*2d543d20SAndroid Build Coastguard Workerattribute mlsprocread;
681*2d543d20SAndroid Build Coastguard Workerattribute mlsprocreadtoclr;
682*2d543d20SAndroid Build Coastguard Workerattribute mlsprocwrite;
683*2d543d20SAndroid Build Coastguard Workerattribute mlsprocwritetoclr;
684*2d543d20SAndroid Build Coastguard Workerattribute mlsprocsetsl;
685*2d543d20SAndroid Build Coastguard Workerattribute mlsxwinread;
686*2d543d20SAndroid Build Coastguard Workerattribute mlsxwinreadtoclr;
687*2d543d20SAndroid Build Coastguard Workerattribute mlsxwinwrite;
688*2d543d20SAndroid Build Coastguard Workerattribute mlsxwinwritetoclr;
689*2d543d20SAndroid Build Coastguard Workerattribute mlsxwinreadproperty;
690*2d543d20SAndroid Build Coastguard Workerattribute mlsxwinwriteproperty;
691*2d543d20SAndroid Build Coastguard Workerattribute mlsxwinreadcolormap;
692*2d543d20SAndroid Build Coastguard Workerattribute mlsxwinwritecolormap;
693*2d543d20SAndroid Build Coastguard Workerattribute mlsxwinwritexinput;
694*2d543d20SAndroid Build Coastguard Workerattribute mlstrustedobject;
695*2d543d20SAndroid Build Coastguard Workerattribute privrangetrans;
696*2d543d20SAndroid Build Coastguard Workerattribute mlsrangetrans;
697*2d543d20SAndroid Build Coastguard Workerattribute can_load_policy;
698*2d543d20SAndroid Build Coastguard Workerattribute can_setenforce;
699*2d543d20SAndroid Build Coastguard Workerattribute can_setsecparam;
700*2d543d20SAndroid Build Coastguard Workerattribute ttynode;
701*2d543d20SAndroid Build Coastguard Workerattribute ptynode;
702*2d543d20SAndroid Build Coastguard Workerattribute server_ptynode;
703*2d543d20SAndroid Build Coastguard Workerattribute serial_device;
704*2d543d20SAndroid Build Coastguard Workertype bin_t;
705*2d543d20SAndroid Build Coastguard Workertype sbin_t;
706*2d543d20SAndroid Build Coastguard Workertype ls_exec_t;
707*2d543d20SAndroid Build Coastguard Workertype shell_exec_t;
708*2d543d20SAndroid Build Coastguard Workertype chroot_exec_t;
709*2d543d20SAndroid Build Coastguard Workertype ppp_device_t;
710*2d543d20SAndroid Build Coastguard Workertype tun_tap_device_t;
711*2d543d20SAndroid Build Coastguard Workertype port_t, port_type;
712*2d543d20SAndroid Build Coastguard Workertype reserved_port_t, port_type, reserved_port_type;
713*2d543d20SAndroid Build Coastguard Workertype afs_bos_port_t, port_type;
714*2d543d20SAndroid Build Coastguard Workertype afs_fs_port_t, port_type;
715*2d543d20SAndroid Build Coastguard Workertype afs_ka_port_t, port_type;
716*2d543d20SAndroid Build Coastguard Workertype afs_pt_port_t, port_type;
717*2d543d20SAndroid Build Coastguard Workertype afs_vl_port_t, port_type;
718*2d543d20SAndroid Build Coastguard Workertype amanda_port_t, port_type;
719*2d543d20SAndroid Build Coastguard Workertype amavisd_recv_port_t, port_type;
720*2d543d20SAndroid Build Coastguard Workertype amavisd_send_port_t, port_type;
721*2d543d20SAndroid Build Coastguard Workertype asterisk_port_t, port_type;
722*2d543d20SAndroid Build Coastguard Workertype auth_port_t, port_type;
723*2d543d20SAndroid Build Coastguard Workertype bgp_port_t, port_type;
724*2d543d20SAndroid Build Coastguard Workertype biff_port_t, port_type, reserved_port_type;
725*2d543d20SAndroid Build Coastguard Workertype clamd_port_t, port_type;
726*2d543d20SAndroid Build Coastguard Workertype clockspeed_port_t, port_type;
727*2d543d20SAndroid Build Coastguard Workertype comsat_port_t, port_type;
728*2d543d20SAndroid Build Coastguard Workertype cvs_port_t, port_type;
729*2d543d20SAndroid Build Coastguard Workertype dcc_port_t, port_type;
730*2d543d20SAndroid Build Coastguard Workertype dbskkd_port_t, port_type;
731*2d543d20SAndroid Build Coastguard Workertype dhcpc_port_t, port_type;
732*2d543d20SAndroid Build Coastguard Workertype dhcpd_port_t, port_type;
733*2d543d20SAndroid Build Coastguard Workertype dict_port_t, port_type;
734*2d543d20SAndroid Build Coastguard Workertype distccd_port_t, port_type;
735*2d543d20SAndroid Build Coastguard Workertype dns_port_t, port_type;
736*2d543d20SAndroid Build Coastguard Workertype fingerd_port_t, port_type;
737*2d543d20SAndroid Build Coastguard Workertype ftp_data_port_t, port_type;
738*2d543d20SAndroid Build Coastguard Workertype ftp_port_t, port_type;
739*2d543d20SAndroid Build Coastguard Workertype gatekeeper_port_t, port_type;
740*2d543d20SAndroid Build Coastguard Workertype giftd_port_t, port_type;
741*2d543d20SAndroid Build Coastguard Workertype gopher_port_t, port_type;
742*2d543d20SAndroid Build Coastguard Workertype http_cache_port_t, port_type;
743*2d543d20SAndroid Build Coastguard Workertype http_port_t, port_type;
744*2d543d20SAndroid Build Coastguard Workertype howl_port_t, port_type;
745*2d543d20SAndroid Build Coastguard Workertype hplip_port_t, port_type;
746*2d543d20SAndroid Build Coastguard Workertype i18n_input_port_t, port_type;
747*2d543d20SAndroid Build Coastguard Workertype imaze_port_t, port_type;
748*2d543d20SAndroid Build Coastguard Workertype inetd_child_port_t, port_type;
749*2d543d20SAndroid Build Coastguard Workertype innd_port_t, port_type;
750*2d543d20SAndroid Build Coastguard Workertype ipp_port_t, port_type;
751*2d543d20SAndroid Build Coastguard Workertype ircd_port_t, port_type;
752*2d543d20SAndroid Build Coastguard Workertype isakmp_port_t, port_type;
753*2d543d20SAndroid Build Coastguard Workertype jabber_client_port_t, port_type;
754*2d543d20SAndroid Build Coastguard Workertype jabber_interserver_port_t, port_type;
755*2d543d20SAndroid Build Coastguard Workertype kerberos_admin_port_t, port_type;
756*2d543d20SAndroid Build Coastguard Workertype kerberos_master_port_t, port_type;
757*2d543d20SAndroid Build Coastguard Workertype kerberos_port_t, port_type;
758*2d543d20SAndroid Build Coastguard Workertype ktalkd_port_t, port_type;
759*2d543d20SAndroid Build Coastguard Workertype ldap_port_t, port_type;
760*2d543d20SAndroid Build Coastguard Workertype lrrd_port_t, port_type;
761*2d543d20SAndroid Build Coastguard Workertype mail_port_t, port_type;
762*2d543d20SAndroid Build Coastguard Workertype monopd_port_t, port_type;
763*2d543d20SAndroid Build Coastguard Workertype mysqld_port_t, port_type;
764*2d543d20SAndroid Build Coastguard Workertype nessus_port_t, port_type;
765*2d543d20SAndroid Build Coastguard Workertype nmbd_port_t, port_type;
766*2d543d20SAndroid Build Coastguard Workertype ntp_port_t, port_type;
767*2d543d20SAndroid Build Coastguard Workertype openvpn_port_t, port_type;
768*2d543d20SAndroid Build Coastguard Workertype pegasus_http_port_t, port_type;
769*2d543d20SAndroid Build Coastguard Workertype pegasus_https_port_t, port_type;
770*2d543d20SAndroid Build Coastguard Workertype pop_port_t, port_type;
771*2d543d20SAndroid Build Coastguard Workertype portmap_port_t, port_type;
772*2d543d20SAndroid Build Coastguard Workertype postgresql_port_t, port_type;
773*2d543d20SAndroid Build Coastguard Workertype postgrey_port_t, port_type;
774*2d543d20SAndroid Build Coastguard Workertype printer_port_t, port_type;
775*2d543d20SAndroid Build Coastguard Workertype ptal_port_t, port_type;
776*2d543d20SAndroid Build Coastguard Workertype pxe_port_t, port_type;
777*2d543d20SAndroid Build Coastguard Workertype pyzor_port_t, port_type;
778*2d543d20SAndroid Build Coastguard Workertype radacct_port_t, port_type;
779*2d543d20SAndroid Build Coastguard Workertype radius_port_t, port_type;
780*2d543d20SAndroid Build Coastguard Workertype razor_port_t, port_type;
781*2d543d20SAndroid Build Coastguard Workertype rlogind_port_t, port_type;
782*2d543d20SAndroid Build Coastguard Workertype rndc_port_t, port_type;
783*2d543d20SAndroid Build Coastguard Workertype router_port_t, port_type;
784*2d543d20SAndroid Build Coastguard Workertype rsh_port_t, port_type;
785*2d543d20SAndroid Build Coastguard Workertype rsync_port_t, port_type;
786*2d543d20SAndroid Build Coastguard Workertype smbd_port_t, port_type;
787*2d543d20SAndroid Build Coastguard Workertype smtp_port_t, port_type;
788*2d543d20SAndroid Build Coastguard Workertype snmp_port_t, port_type;
789*2d543d20SAndroid Build Coastguard Workertype spamd_port_t, port_type;
790*2d543d20SAndroid Build Coastguard Workertype ssh_port_t, port_type;
791*2d543d20SAndroid Build Coastguard Workertype soundd_port_t, port_type;
792*2d543d20SAndroid Build Coastguard Workertype socks_port_t, port_type; type stunnel_port_t, port_type;
793*2d543d20SAndroid Build Coastguard Workertype swat_port_t, port_type;
794*2d543d20SAndroid Build Coastguard Workertype syslogd_port_t, port_type;
795*2d543d20SAndroid Build Coastguard Workertype telnetd_port_t, port_type;
796*2d543d20SAndroid Build Coastguard Workertype tftp_port_t, port_type;
797*2d543d20SAndroid Build Coastguard Workertype transproxy_port_t, port_type;
798*2d543d20SAndroid Build Coastguard Workertype utcpserver_port_t, port_type;
799*2d543d20SAndroid Build Coastguard Workertype uucpd_port_t, port_type;
800*2d543d20SAndroid Build Coastguard Workertype vnc_port_t, port_type;
801*2d543d20SAndroid Build Coastguard Workertype xserver_port_t, port_type;
802*2d543d20SAndroid Build Coastguard Workertype xen_port_t, port_type;
803*2d543d20SAndroid Build Coastguard Workertype zebra_port_t, port_type;
804*2d543d20SAndroid Build Coastguard Workertype zope_port_t, port_type;
805*2d543d20SAndroid Build Coastguard Workertype node_t, node_type;
806*2d543d20SAndroid Build Coastguard Workertype compat_ipv4_node_t alias node_compat_ipv4_t, node_type;
807*2d543d20SAndroid Build Coastguard Workertype inaddr_any_node_t alias node_inaddr_any_t, node_type;
808*2d543d20SAndroid Build Coastguard Workertype node_internal_t, node_type;
809*2d543d20SAndroid Build Coastguard Workertype link_local_node_t alias node_link_local_t, node_type;
810*2d543d20SAndroid Build Coastguard Workertype lo_node_t alias node_lo_t, node_type;
811*2d543d20SAndroid Build Coastguard Workertype mapped_ipv4_node_t alias node_mapped_ipv4_t, node_type;
812*2d543d20SAndroid Build Coastguard Workertype multicast_node_t alias node_multicast_t, node_type;
813*2d543d20SAndroid Build Coastguard Workertype site_local_node_t alias node_site_local_t, node_type;
814*2d543d20SAndroid Build Coastguard Workertype unspec_node_t alias node_unspec_t, node_type;
815*2d543d20SAndroid Build Coastguard Workertype netif_t, netif_type;
816*2d543d20SAndroid Build Coastguard Workertype device_t;
817*2d543d20SAndroid Build Coastguard Workertype agp_device_t;
818*2d543d20SAndroid Build Coastguard Workertype apm_bios_t;
819*2d543d20SAndroid Build Coastguard Workertype cardmgr_dev_t;
820*2d543d20SAndroid Build Coastguard Workertype clock_device_t;
821*2d543d20SAndroid Build Coastguard Workertype cpu_device_t;
822*2d543d20SAndroid Build Coastguard Workertype crypt_device_t;
823*2d543d20SAndroid Build Coastguard Workertype dri_device_t;
824*2d543d20SAndroid Build Coastguard Workertype event_device_t;
825*2d543d20SAndroid Build Coastguard Workertype framebuf_device_t;
826*2d543d20SAndroid Build Coastguard Workertype lvm_control_t;
827*2d543d20SAndroid Build Coastguard Workertype memory_device_t;
828*2d543d20SAndroid Build Coastguard Workertype misc_device_t;
829*2d543d20SAndroid Build Coastguard Workertype mouse_device_t;
830*2d543d20SAndroid Build Coastguard Workertype mtrr_device_t;
831*2d543d20SAndroid Build Coastguard Workertype null_device_t;
832*2d543d20SAndroid Build Coastguard Workertype power_device_t;
833*2d543d20SAndroid Build Coastguard Workertype printer_device_t;
834*2d543d20SAndroid Build Coastguard Workertype random_device_t;
835*2d543d20SAndroid Build Coastguard Workertype scanner_device_t;
836*2d543d20SAndroid Build Coastguard Workertype sound_device_t;
837*2d543d20SAndroid Build Coastguard Workertype sysfs_t;
838*2d543d20SAndroid Build Coastguard Workertype urandom_device_t;
839*2d543d20SAndroid Build Coastguard Workertype usbfs_t alias usbdevfs_t;
840*2d543d20SAndroid Build Coastguard Workertype usb_device_t;
841*2d543d20SAndroid Build Coastguard Workertype v4l_device_t;
842*2d543d20SAndroid Build Coastguard Workertype xserver_misc_device_t;
843*2d543d20SAndroid Build Coastguard Workertype zero_device_t;
844*2d543d20SAndroid Build Coastguard Workertype xconsole_device_t;
845*2d543d20SAndroid Build Coastguard Workertype devfs_control_t;
846*2d543d20SAndroid Build Coastguard Workertype boot_t;
847*2d543d20SAndroid Build Coastguard Workertype default_t, file_type, mountpoint;
848*2d543d20SAndroid Build Coastguard Workertype etc_t, file_type;
849*2d543d20SAndroid Build Coastguard Workertype etc_runtime_t, file_type;
850*2d543d20SAndroid Build Coastguard Workertype file_t, file_type, mountpoint;
851*2d543d20SAndroid Build Coastguard Workertype home_root_t, file_type, mountpoint;
852*2d543d20SAndroid Build Coastguard Workertype lost_found_t, file_type;
853*2d543d20SAndroid Build Coastguard Workertype mnt_t, file_type, mountpoint;
854*2d543d20SAndroid Build Coastguard Workertype modules_object_t;
855*2d543d20SAndroid Build Coastguard Workertype no_access_t, file_type;
856*2d543d20SAndroid Build Coastguard Workertype poly_t, file_type;
857*2d543d20SAndroid Build Coastguard Workertype readable_t, file_type;
858*2d543d20SAndroid Build Coastguard Workertype root_t, file_type, mountpoint;
859*2d543d20SAndroid Build Coastguard Workertype src_t, file_type, mountpoint;
860*2d543d20SAndroid Build Coastguard Workertype system_map_t;
861*2d543d20SAndroid Build Coastguard Workertype tmp_t, mountpoint; #, polydir
862*2d543d20SAndroid Build Coastguard Workertype usr_t, file_type, mountpoint;
863*2d543d20SAndroid Build Coastguard Workertype var_t, file_type, mountpoint;
864*2d543d20SAndroid Build Coastguard Workertype var_lib_t, file_type, mountpoint;
865*2d543d20SAndroid Build Coastguard Workertype var_lock_t, file_type, lockfile;
866*2d543d20SAndroid Build Coastguard Workertype var_run_t, file_type, pidfile;
867*2d543d20SAndroid Build Coastguard Workertype var_spool_t;
868*2d543d20SAndroid Build Coastguard Workertype fs_t;
869*2d543d20SAndroid Build Coastguard Workertype bdev_t;
870*2d543d20SAndroid Build Coastguard Workertype binfmt_misc_fs_t;
871*2d543d20SAndroid Build Coastguard Workertype capifs_t;
872*2d543d20SAndroid Build Coastguard Workertype configfs_t;
873*2d543d20SAndroid Build Coastguard Workertype eventpollfs_t;
874*2d543d20SAndroid Build Coastguard Workertype futexfs_t;
875*2d543d20SAndroid Build Coastguard Workertype hugetlbfs_t;
876*2d543d20SAndroid Build Coastguard Workertype inotifyfs_t;
877*2d543d20SAndroid Build Coastguard Workertype nfsd_fs_t;
878*2d543d20SAndroid Build Coastguard Workertype ramfs_t;
879*2d543d20SAndroid Build Coastguard Workertype romfs_t;
880*2d543d20SAndroid Build Coastguard Workertype rpc_pipefs_t;
881*2d543d20SAndroid Build Coastguard Workertype tmpfs_t;
882*2d543d20SAndroid Build Coastguard Workertype autofs_t, noxattrfs;
883*2d543d20SAndroid Build Coastguard Workertype cifs_t alias sambafs_t, noxattrfs;
884*2d543d20SAndroid Build Coastguard Workertype dosfs_t, noxattrfs;
885*2d543d20SAndroid Build Coastguard Workertype iso9660_t, filesystem_type, noxattrfs;
886*2d543d20SAndroid Build Coastguard Workertype removable_t, noxattrfs;
887*2d543d20SAndroid Build Coastguard Workertype nfs_t, filesystem_type, noxattrfs;
888*2d543d20SAndroid Build Coastguard Workertype kernel_t, can_load_kernmodule;
889*2d543d20SAndroid Build Coastguard Workertype debugfs_t;
890*2d543d20SAndroid Build Coastguard Workertype proc_t, proc_type;
891*2d543d20SAndroid Build Coastguard Workertype proc_kmsg_t, proc_type;
892*2d543d20SAndroid Build Coastguard Workertype proc_kcore_t, proc_type;
893*2d543d20SAndroid Build Coastguard Workertype proc_mdstat_t, proc_type;
894*2d543d20SAndroid Build Coastguard Workertype proc_net_t, proc_type;
895*2d543d20SAndroid Build Coastguard Workertype proc_xen_t, proc_type;
896*2d543d20SAndroid Build Coastguard Workertype sysctl_t, sysctl_type;
897*2d543d20SAndroid Build Coastguard Workertype sysctl_irq_t, sysctl_type;
898*2d543d20SAndroid Build Coastguard Workertype sysctl_rpc_t, sysctl_type;
899*2d543d20SAndroid Build Coastguard Workertype sysctl_fs_t, sysctl_type;
900*2d543d20SAndroid Build Coastguard Workertype sysctl_kernel_t, sysctl_type;
901*2d543d20SAndroid Build Coastguard Workertype sysctl_modprobe_t, sysctl_type;
902*2d543d20SAndroid Build Coastguard Workertype sysctl_hotplug_t, sysctl_type;
903*2d543d20SAndroid Build Coastguard Workertype sysctl_net_t, sysctl_type;
904*2d543d20SAndroid Build Coastguard Workertype sysctl_net_unix_t, sysctl_type;
905*2d543d20SAndroid Build Coastguard Workertype sysctl_vm_t, sysctl_type;
906*2d543d20SAndroid Build Coastguard Workertype sysctl_dev_t, sysctl_type;
907*2d543d20SAndroid Build Coastguard Workertype unlabeled_t;
908*2d543d20SAndroid Build Coastguard Workertype auditd_exec_t;
909*2d543d20SAndroid Build Coastguard Workertype crond_exec_t;
910*2d543d20SAndroid Build Coastguard Workertype cupsd_exec_t;
911*2d543d20SAndroid Build Coastguard Workertype getty_t;
912*2d543d20SAndroid Build Coastguard Workertype init_t;
913*2d543d20SAndroid Build Coastguard Workertype init_exec_t;
914*2d543d20SAndroid Build Coastguard Workertype initrc_t;
915*2d543d20SAndroid Build Coastguard Workertype initrc_exec_t;
916*2d543d20SAndroid Build Coastguard Workertype login_exec_t;
917*2d543d20SAndroid Build Coastguard Workertype sshd_exec_t;
918*2d543d20SAndroid Build Coastguard Workertype su_exec_t;
919*2d543d20SAndroid Build Coastguard Workertype udev_exec_t;
920*2d543d20SAndroid Build Coastguard Workertype unconfined_t;
921*2d543d20SAndroid Build Coastguard Workertype xdm_exec_t;
922*2d543d20SAndroid Build Coastguard Workertype lvm_exec_t;
923*2d543d20SAndroid Build Coastguard Workertype security_t;
924*2d543d20SAndroid Build Coastguard Workertype bsdpty_device_t;
925*2d543d20SAndroid Build Coastguard Workertype console_device_t;
926*2d543d20SAndroid Build Coastguard Workertype devpts_t;
927*2d543d20SAndroid Build Coastguard Workertype devtty_t;
928*2d543d20SAndroid Build Coastguard Workertype ptmx_t;
929*2d543d20SAndroid Build Coastguard Workertype tty_device_t, serial_device;
930*2d543d20SAndroid Build Coastguard Workertype usbtty_device_t, serial_device;
931*2d543d20SAndroid Build Coastguard Worker	bool secure_mode false;
932*2d543d20SAndroid Build Coastguard Worker	bool secure_mode_insmod false;
933*2d543d20SAndroid Build Coastguard Worker	bool secure_mode_policyload false;
934*2d543d20SAndroid Build Coastguard Worker		bool allow_cvs_read_shadow false;
935*2d543d20SAndroid Build Coastguard Worker		bool allow_execheap false;
936*2d543d20SAndroid Build Coastguard Worker		bool allow_execmem true;
937*2d543d20SAndroid Build Coastguard Worker		bool allow_execmod false;
938*2d543d20SAndroid Build Coastguard Worker		bool allow_execstack true;
939*2d543d20SAndroid Build Coastguard Worker		bool allow_ftpd_anon_write false;
940*2d543d20SAndroid Build Coastguard Worker		bool allow_gssd_read_tmp true;
941*2d543d20SAndroid Build Coastguard Worker		bool allow_httpd_anon_write false;
942*2d543d20SAndroid Build Coastguard Worker		bool allow_java_execstack false;
943*2d543d20SAndroid Build Coastguard Worker		bool allow_kerberos true;
944*2d543d20SAndroid Build Coastguard Worker		bool allow_rsync_anon_write false;
945*2d543d20SAndroid Build Coastguard Worker		bool allow_saslauthd_read_shadow false;
946*2d543d20SAndroid Build Coastguard Worker		bool allow_smbd_anon_write false;
947*2d543d20SAndroid Build Coastguard Worker		bool allow_ptrace false;
948*2d543d20SAndroid Build Coastguard Worker		bool allow_ypbind false;
949*2d543d20SAndroid Build Coastguard Worker		bool fcron_crond false;
950*2d543d20SAndroid Build Coastguard Worker		bool ftp_home_dir false;
951*2d543d20SAndroid Build Coastguard Worker		bool ftpd_is_daemon true;
952*2d543d20SAndroid Build Coastguard Worker		bool httpd_builtin_scripting true;
953*2d543d20SAndroid Build Coastguard Worker		bool httpd_can_network_connect false;
954*2d543d20SAndroid Build Coastguard Worker		bool httpd_can_network_connect_db false;
955*2d543d20SAndroid Build Coastguard Worker		bool httpd_can_network_relay false;
956*2d543d20SAndroid Build Coastguard Worker		bool httpd_enable_cgi true;
957*2d543d20SAndroid Build Coastguard Worker		bool httpd_enable_ftp_server false;
958*2d543d20SAndroid Build Coastguard Worker		bool httpd_enable_homedirs true;
959*2d543d20SAndroid Build Coastguard Worker		bool httpd_ssi_exec true;
960*2d543d20SAndroid Build Coastguard Worker		bool httpd_tty_comm false;
961*2d543d20SAndroid Build Coastguard Worker		bool httpd_unified true;
962*2d543d20SAndroid Build Coastguard Worker		bool named_write_master_zones false;
963*2d543d20SAndroid Build Coastguard Worker		bool nfs_export_all_rw true;
964*2d543d20SAndroid Build Coastguard Worker		bool nfs_export_all_ro true;
965*2d543d20SAndroid Build Coastguard Worker		bool pppd_can_insmod false;
966*2d543d20SAndroid Build Coastguard Worker		bool read_default_t true;
967*2d543d20SAndroid Build Coastguard Worker		bool run_ssh_inetd false;
968*2d543d20SAndroid Build Coastguard Worker		bool samba_enable_home_dirs false;
969*2d543d20SAndroid Build Coastguard Worker		bool spamassasin_can_network false;
970*2d543d20SAndroid Build Coastguard Worker		bool squid_connect_any false;
971*2d543d20SAndroid Build Coastguard Worker		bool ssh_sysadm_login false;
972*2d543d20SAndroid Build Coastguard Worker		bool stunnel_is_daemon false;
973*2d543d20SAndroid Build Coastguard Worker		bool use_nfs_home_dirs false;
974*2d543d20SAndroid Build Coastguard Worker		bool use_samba_home_dirs false;
975*2d543d20SAndroid Build Coastguard Worker		bool user_ping true;
976*2d543d20SAndroid Build Coastguard Worker		bool spamd_enable_home_dirs true;
977*2d543d20SAndroid Build Coastguard Worker	allow bin_t fs_t:filesystem associate;
978*2d543d20SAndroid Build Coastguard Worker	allow bin_t noxattrfs:filesystem associate;
979*2d543d20SAndroid Build Coastguard Worker	typeattribute bin_t file_type;
980*2d543d20SAndroid Build Coastguard Worker	allow sbin_t fs_t:filesystem associate;
981*2d543d20SAndroid Build Coastguard Worker	allow sbin_t noxattrfs:filesystem associate;
982*2d543d20SAndroid Build Coastguard Worker	typeattribute sbin_t file_type;
983*2d543d20SAndroid Build Coastguard Worker	allow ls_exec_t fs_t:filesystem associate;
984*2d543d20SAndroid Build Coastguard Worker	allow ls_exec_t noxattrfs:filesystem associate;
985*2d543d20SAndroid Build Coastguard Worker	typeattribute ls_exec_t file_type;
986*2d543d20SAndroid Build Coastguard Workertypeattribute ls_exec_t entry_type;
987*2d543d20SAndroid Build Coastguard Worker	allow shell_exec_t fs_t:filesystem associate;
988*2d543d20SAndroid Build Coastguard Worker	allow shell_exec_t noxattrfs:filesystem associate;
989*2d543d20SAndroid Build Coastguard Worker	typeattribute shell_exec_t file_type;
990*2d543d20SAndroid Build Coastguard Worker	allow chroot_exec_t fs_t:filesystem associate;
991*2d543d20SAndroid Build Coastguard Worker	allow chroot_exec_t noxattrfs:filesystem associate;
992*2d543d20SAndroid Build Coastguard Worker	typeattribute chroot_exec_t file_type;
993*2d543d20SAndroid Build Coastguard Worker	typeattribute ppp_device_t device_node;
994*2d543d20SAndroid Build Coastguard Worker	allow ppp_device_t fs_t:filesystem associate;
995*2d543d20SAndroid Build Coastguard Worker	allow ppp_device_t tmpfs_t:filesystem associate;
996*2d543d20SAndroid Build Coastguard Worker	allow ppp_device_t tmp_t:filesystem associate;
997*2d543d20SAndroid Build Coastguard Worker	typeattribute tun_tap_device_t device_node;
998*2d543d20SAndroid Build Coastguard Worker	allow tun_tap_device_t fs_t:filesystem associate;
999*2d543d20SAndroid Build Coastguard Worker	allow tun_tap_device_t tmpfs_t:filesystem associate;
1000*2d543d20SAndroid Build Coastguard Worker	allow tun_tap_device_t tmp_t:filesystem associate;
1001*2d543d20SAndroid Build Coastguard Workertypeattribute auth_port_t reserved_port_type;
1002*2d543d20SAndroid Build Coastguard Workertypeattribute bgp_port_t reserved_port_type;
1003*2d543d20SAndroid Build Coastguard Workertypeattribute bgp_port_t reserved_port_type;
1004*2d543d20SAndroid Build Coastguard Workertypeattribute comsat_port_t reserved_port_type;
1005*2d543d20SAndroid Build Coastguard Workertypeattribute dhcpc_port_t reserved_port_type;
1006*2d543d20SAndroid Build Coastguard Workertypeattribute dhcpd_port_t reserved_port_type;
1007*2d543d20SAndroid Build Coastguard Workertypeattribute dhcpd_port_t reserved_port_type;
1008*2d543d20SAndroid Build Coastguard Workertypeattribute dhcpd_port_t reserved_port_type;
1009*2d543d20SAndroid Build Coastguard Workertypeattribute dhcpd_port_t reserved_port_type;
1010*2d543d20SAndroid Build Coastguard Workertypeattribute dhcpd_port_t reserved_port_type;
1011*2d543d20SAndroid Build Coastguard Workertypeattribute dns_port_t reserved_port_type;
1012*2d543d20SAndroid Build Coastguard Workertypeattribute dns_port_t reserved_port_type;
1013*2d543d20SAndroid Build Coastguard Workertypeattribute fingerd_port_t reserved_port_type;
1014*2d543d20SAndroid Build Coastguard Workertypeattribute ftp_data_port_t reserved_port_type;
1015*2d543d20SAndroid Build Coastguard Workertypeattribute ftp_port_t reserved_port_type;
1016*2d543d20SAndroid Build Coastguard Workertypeattribute gopher_port_t reserved_port_type;
1017*2d543d20SAndroid Build Coastguard Workertypeattribute gopher_port_t reserved_port_type;
1018*2d543d20SAndroid Build Coastguard Workertypeattribute http_port_t reserved_port_type;
1019*2d543d20SAndroid Build Coastguard Workertypeattribute http_port_t reserved_port_type;
1020*2d543d20SAndroid Build Coastguard Workertypeattribute http_port_t reserved_port_type;
1021*2d543d20SAndroid Build Coastguard Workertypeattribute inetd_child_port_t reserved_port_type;
1022*2d543d20SAndroid Build Coastguard Workertypeattribute inetd_child_port_t reserved_port_type;
1023*2d543d20SAndroid Build Coastguard Workertypeattribute inetd_child_port_t reserved_port_type;
1024*2d543d20SAndroid Build Coastguard Workertypeattribute inetd_child_port_t reserved_port_type;
1025*2d543d20SAndroid Build Coastguard Workertypeattribute inetd_child_port_t reserved_port_type;
1026*2d543d20SAndroid Build Coastguard Workertypeattribute inetd_child_port_t reserved_port_type;
1027*2d543d20SAndroid Build Coastguard Workertypeattribute inetd_child_port_t reserved_port_type;
1028*2d543d20SAndroid Build Coastguard Workertypeattribute inetd_child_port_t reserved_port_type;
1029*2d543d20SAndroid Build Coastguard Workertypeattribute inetd_child_port_t reserved_port_type;
1030*2d543d20SAndroid Build Coastguard Workertypeattribute inetd_child_port_t reserved_port_type;
1031*2d543d20SAndroid Build Coastguard Workertypeattribute inetd_child_port_t reserved_port_type;
1032*2d543d20SAndroid Build Coastguard Workertypeattribute inetd_child_port_t reserved_port_type;
1033*2d543d20SAndroid Build Coastguard Workertypeattribute inetd_child_port_t reserved_port_type;
1034*2d543d20SAndroid Build Coastguard Workertypeattribute inetd_child_port_t reserved_port_type;
1035*2d543d20SAndroid Build Coastguard Workertypeattribute inetd_child_port_t reserved_port_type;
1036*2d543d20SAndroid Build Coastguard Workertypeattribute inetd_child_port_t reserved_port_type;
1037*2d543d20SAndroid Build Coastguard Workertypeattribute inetd_child_port_t reserved_port_type;
1038*2d543d20SAndroid Build Coastguard Workertypeattribute innd_port_t reserved_port_type;
1039*2d543d20SAndroid Build Coastguard Workertypeattribute ipp_port_t reserved_port_type;
1040*2d543d20SAndroid Build Coastguard Workertypeattribute ipp_port_t reserved_port_type;
1041*2d543d20SAndroid Build Coastguard Workertypeattribute isakmp_port_t reserved_port_type;
1042*2d543d20SAndroid Build Coastguard Workertypeattribute kerberos_admin_port_t reserved_port_type;
1043*2d543d20SAndroid Build Coastguard Workertypeattribute kerberos_admin_port_t reserved_port_type;
1044*2d543d20SAndroid Build Coastguard Workertypeattribute kerberos_admin_port_t reserved_port_type;
1045*2d543d20SAndroid Build Coastguard Workertypeattribute kerberos_port_t reserved_port_type;
1046*2d543d20SAndroid Build Coastguard Workertypeattribute kerberos_port_t reserved_port_type;
1047*2d543d20SAndroid Build Coastguard Workertypeattribute kerberos_port_t reserved_port_type;
1048*2d543d20SAndroid Build Coastguard Workertypeattribute kerberos_port_t reserved_port_type;
1049*2d543d20SAndroid Build Coastguard Workertypeattribute ktalkd_port_t reserved_port_type;
1050*2d543d20SAndroid Build Coastguard Workertypeattribute ktalkd_port_t reserved_port_type;
1051*2d543d20SAndroid Build Coastguard Workertypeattribute ldap_port_t reserved_port_type;
1052*2d543d20SAndroid Build Coastguard Workertypeattribute ldap_port_t reserved_port_type;
1053*2d543d20SAndroid Build Coastguard Workertypeattribute ldap_port_t reserved_port_type;
1054*2d543d20SAndroid Build Coastguard Workertypeattribute ldap_port_t reserved_port_type;
1055*2d543d20SAndroid Build Coastguard Workertypeattribute nmbd_port_t reserved_port_type;
1056*2d543d20SAndroid Build Coastguard Workertypeattribute nmbd_port_t reserved_port_type;
1057*2d543d20SAndroid Build Coastguard Workertypeattribute nmbd_port_t reserved_port_type;
1058*2d543d20SAndroid Build Coastguard Workertypeattribute ntp_port_t reserved_port_type;
1059*2d543d20SAndroid Build Coastguard Workertypeattribute pop_port_t reserved_port_type;
1060*2d543d20SAndroid Build Coastguard Workertypeattribute pop_port_t reserved_port_type;
1061*2d543d20SAndroid Build Coastguard Workertypeattribute pop_port_t reserved_port_type;
1062*2d543d20SAndroid Build Coastguard Workertypeattribute pop_port_t reserved_port_type;
1063*2d543d20SAndroid Build Coastguard Workertypeattribute pop_port_t reserved_port_type;
1064*2d543d20SAndroid Build Coastguard Workertypeattribute pop_port_t reserved_port_type;
1065*2d543d20SAndroid Build Coastguard Workertypeattribute pop_port_t reserved_port_type;
1066*2d543d20SAndroid Build Coastguard Workertypeattribute portmap_port_t reserved_port_type;
1067*2d543d20SAndroid Build Coastguard Workertypeattribute portmap_port_t reserved_port_type;
1068*2d543d20SAndroid Build Coastguard Workertypeattribute printer_port_t reserved_port_type;
1069*2d543d20SAndroid Build Coastguard Workertypeattribute rlogind_port_t reserved_port_type;
1070*2d543d20SAndroid Build Coastguard Workertypeattribute rndc_port_t reserved_port_type;
1071*2d543d20SAndroid Build Coastguard Workertypeattribute router_port_t reserved_port_type;
1072*2d543d20SAndroid Build Coastguard Workertypeattribute rsh_port_t reserved_port_type;
1073*2d543d20SAndroid Build Coastguard Workertypeattribute rsync_port_t reserved_port_type;
1074*2d543d20SAndroid Build Coastguard Workertypeattribute rsync_port_t reserved_port_type;
1075*2d543d20SAndroid Build Coastguard Workertypeattribute smbd_port_t reserved_port_type;
1076*2d543d20SAndroid Build Coastguard Workertypeattribute smbd_port_t reserved_port_type;
1077*2d543d20SAndroid Build Coastguard Workertypeattribute smtp_port_t reserved_port_type;
1078*2d543d20SAndroid Build Coastguard Workertypeattribute smtp_port_t reserved_port_type;
1079*2d543d20SAndroid Build Coastguard Workertypeattribute smtp_port_t reserved_port_type;
1080*2d543d20SAndroid Build Coastguard Workertypeattribute snmp_port_t reserved_port_type;
1081*2d543d20SAndroid Build Coastguard Workertypeattribute snmp_port_t reserved_port_type;
1082*2d543d20SAndroid Build Coastguard Workertypeattribute snmp_port_t reserved_port_type;
1083*2d543d20SAndroid Build Coastguard Workertypeattribute spamd_port_t reserved_port_type;
1084*2d543d20SAndroid Build Coastguard Workertypeattribute ssh_port_t reserved_port_type;
1085*2d543d20SAndroid Build Coastguard Workertypeattribute swat_port_t reserved_port_type;
1086*2d543d20SAndroid Build Coastguard Workertypeattribute syslogd_port_t reserved_port_type;
1087*2d543d20SAndroid Build Coastguard Workertypeattribute telnetd_port_t reserved_port_type;
1088*2d543d20SAndroid Build Coastguard Workertypeattribute tftp_port_t reserved_port_type;
1089*2d543d20SAndroid Build Coastguard Workertypeattribute uucpd_port_t reserved_port_type;
1090*2d543d20SAndroid Build Coastguard Worker	allow device_t tmpfs_t:filesystem associate;
1091*2d543d20SAndroid Build Coastguard Worker	allow device_t fs_t:filesystem associate;
1092*2d543d20SAndroid Build Coastguard Worker	allow device_t noxattrfs:filesystem associate;
1093*2d543d20SAndroid Build Coastguard Worker	typeattribute device_t file_type;
1094*2d543d20SAndroid Build Coastguard Worker	allow device_t fs_t:filesystem associate;
1095*2d543d20SAndroid Build Coastguard Worker	allow device_t noxattrfs:filesystem associate;
1096*2d543d20SAndroid Build Coastguard Worker	typeattribute device_t file_type;
1097*2d543d20SAndroid Build Coastguard Worker	typeattribute device_t mountpoint;
1098*2d543d20SAndroid Build Coastguard Worker	allow device_t tmp_t:filesystem associate;
1099*2d543d20SAndroid Build Coastguard Worker	typeattribute agp_device_t device_node;
1100*2d543d20SAndroid Build Coastguard Worker	allow agp_device_t fs_t:filesystem associate;
1101*2d543d20SAndroid Build Coastguard Worker	allow agp_device_t tmpfs_t:filesystem associate;
1102*2d543d20SAndroid Build Coastguard Worker	allow agp_device_t tmp_t:filesystem associate;
1103*2d543d20SAndroid Build Coastguard Worker	typeattribute apm_bios_t device_node;
1104*2d543d20SAndroid Build Coastguard Worker	allow apm_bios_t fs_t:filesystem associate;
1105*2d543d20SAndroid Build Coastguard Worker	allow apm_bios_t tmpfs_t:filesystem associate;
1106*2d543d20SAndroid Build Coastguard Worker	allow apm_bios_t tmp_t:filesystem associate;
1107*2d543d20SAndroid Build Coastguard Worker	typeattribute cardmgr_dev_t device_node;
1108*2d543d20SAndroid Build Coastguard Worker	allow cardmgr_dev_t fs_t:filesystem associate;
1109*2d543d20SAndroid Build Coastguard Worker	allow cardmgr_dev_t tmpfs_t:filesystem associate;
1110*2d543d20SAndroid Build Coastguard Worker	allow cardmgr_dev_t tmp_t:filesystem associate;
1111*2d543d20SAndroid Build Coastguard Worker	allow cardmgr_dev_t fs_t:filesystem associate;
1112*2d543d20SAndroid Build Coastguard Worker	allow cardmgr_dev_t noxattrfs:filesystem associate;
1113*2d543d20SAndroid Build Coastguard Worker	typeattribute cardmgr_dev_t file_type;
1114*2d543d20SAndroid Build Coastguard Worker	allow cardmgr_dev_t fs_t:filesystem associate;
1115*2d543d20SAndroid Build Coastguard Worker	allow cardmgr_dev_t noxattrfs:filesystem associate;
1116*2d543d20SAndroid Build Coastguard Worker	typeattribute cardmgr_dev_t file_type;
1117*2d543d20SAndroid Build Coastguard Worker	typeattribute cardmgr_dev_t polymember;
1118*2d543d20SAndroid Build Coastguard Worker	allow cardmgr_dev_t tmpfs_t:filesystem associate;
1119*2d543d20SAndroid Build Coastguard Worker	typeattribute cardmgr_dev_t tmpfile;
1120*2d543d20SAndroid Build Coastguard Worker	allow cardmgr_dev_t tmp_t:filesystem associate;
1121*2d543d20SAndroid Build Coastguard Worker	typeattribute clock_device_t device_node;
1122*2d543d20SAndroid Build Coastguard Worker	allow clock_device_t fs_t:filesystem associate;
1123*2d543d20SAndroid Build Coastguard Worker	allow clock_device_t tmpfs_t:filesystem associate;
1124*2d543d20SAndroid Build Coastguard Worker	allow clock_device_t tmp_t:filesystem associate;
1125*2d543d20SAndroid Build Coastguard Worker	typeattribute cpu_device_t device_node;
1126*2d543d20SAndroid Build Coastguard Worker	allow cpu_device_t fs_t:filesystem associate;
1127*2d543d20SAndroid Build Coastguard Worker	allow cpu_device_t tmpfs_t:filesystem associate;
1128*2d543d20SAndroid Build Coastguard Worker	allow cpu_device_t tmp_t:filesystem associate;
1129*2d543d20SAndroid Build Coastguard Worker	typeattribute crypt_device_t device_node;
1130*2d543d20SAndroid Build Coastguard Worker	allow crypt_device_t fs_t:filesystem associate;
1131*2d543d20SAndroid Build Coastguard Worker	allow crypt_device_t tmpfs_t:filesystem associate;
1132*2d543d20SAndroid Build Coastguard Worker	allow crypt_device_t tmp_t:filesystem associate;
1133*2d543d20SAndroid Build Coastguard Worker	typeattribute dri_device_t device_node;
1134*2d543d20SAndroid Build Coastguard Worker	allow dri_device_t fs_t:filesystem associate;
1135*2d543d20SAndroid Build Coastguard Worker	allow dri_device_t tmpfs_t:filesystem associate;
1136*2d543d20SAndroid Build Coastguard Worker	allow dri_device_t tmp_t:filesystem associate;
1137*2d543d20SAndroid Build Coastguard Worker	typeattribute event_device_t device_node;
1138*2d543d20SAndroid Build Coastguard Worker	allow event_device_t fs_t:filesystem associate;
1139*2d543d20SAndroid Build Coastguard Worker	allow event_device_t tmpfs_t:filesystem associate;
1140*2d543d20SAndroid Build Coastguard Worker	allow event_device_t tmp_t:filesystem associate;
1141*2d543d20SAndroid Build Coastguard Worker	typeattribute framebuf_device_t device_node;
1142*2d543d20SAndroid Build Coastguard Worker	allow framebuf_device_t fs_t:filesystem associate;
1143*2d543d20SAndroid Build Coastguard Worker	allow framebuf_device_t tmpfs_t:filesystem associate;
1144*2d543d20SAndroid Build Coastguard Worker	allow framebuf_device_t tmp_t:filesystem associate;
1145*2d543d20SAndroid Build Coastguard Worker	typeattribute lvm_control_t device_node;
1146*2d543d20SAndroid Build Coastguard Worker	allow lvm_control_t fs_t:filesystem associate;
1147*2d543d20SAndroid Build Coastguard Worker	allow lvm_control_t tmpfs_t:filesystem associate;
1148*2d543d20SAndroid Build Coastguard Worker	allow lvm_control_t tmp_t:filesystem associate;
1149*2d543d20SAndroid Build Coastguard Worker	typeattribute memory_device_t device_node;
1150*2d543d20SAndroid Build Coastguard Worker	allow memory_device_t fs_t:filesystem associate;
1151*2d543d20SAndroid Build Coastguard Worker	allow memory_device_t tmpfs_t:filesystem associate;
1152*2d543d20SAndroid Build Coastguard Worker	allow memory_device_t tmp_t:filesystem associate;
1153*2d543d20SAndroid Build Coastguard Workerneverallow ~memory_raw_read memory_device_t:{ chr_file blk_file } read;
1154*2d543d20SAndroid Build Coastguard Workerneverallow ~memory_raw_write memory_device_t:{ chr_file blk_file } { append write };
1155*2d543d20SAndroid Build Coastguard Worker	typeattribute misc_device_t device_node;
1156*2d543d20SAndroid Build Coastguard Worker	allow misc_device_t fs_t:filesystem associate;
1157*2d543d20SAndroid Build Coastguard Worker	allow misc_device_t tmpfs_t:filesystem associate;
1158*2d543d20SAndroid Build Coastguard Worker	allow misc_device_t tmp_t:filesystem associate;
1159*2d543d20SAndroid Build Coastguard Worker	typeattribute mouse_device_t device_node;
1160*2d543d20SAndroid Build Coastguard Worker	allow mouse_device_t fs_t:filesystem associate;
1161*2d543d20SAndroid Build Coastguard Worker	allow mouse_device_t tmpfs_t:filesystem associate;
1162*2d543d20SAndroid Build Coastguard Worker	allow mouse_device_t tmp_t:filesystem associate;
1163*2d543d20SAndroid Build Coastguard Worker	typeattribute mtrr_device_t device_node;
1164*2d543d20SAndroid Build Coastguard Worker	allow mtrr_device_t fs_t:filesystem associate;
1165*2d543d20SAndroid Build Coastguard Worker	allow mtrr_device_t tmpfs_t:filesystem associate;
1166*2d543d20SAndroid Build Coastguard Worker	allow mtrr_device_t tmp_t:filesystem associate;
1167*2d543d20SAndroid Build Coastguard Worker	typeattribute null_device_t device_node;
1168*2d543d20SAndroid Build Coastguard Worker	allow null_device_t fs_t:filesystem associate;
1169*2d543d20SAndroid Build Coastguard Worker	allow null_device_t tmpfs_t:filesystem associate;
1170*2d543d20SAndroid Build Coastguard Worker	allow null_device_t tmp_t:filesystem associate;
1171*2d543d20SAndroid Build Coastguard Worker	typeattribute null_device_t mlstrustedobject;
1172*2d543d20SAndroid Build Coastguard Worker	typeattribute power_device_t device_node;
1173*2d543d20SAndroid Build Coastguard Worker	allow power_device_t fs_t:filesystem associate;
1174*2d543d20SAndroid Build Coastguard Worker	allow power_device_t tmpfs_t:filesystem associate;
1175*2d543d20SAndroid Build Coastguard Worker	allow power_device_t tmp_t:filesystem associate;
1176*2d543d20SAndroid Build Coastguard Worker	typeattribute printer_device_t device_node;
1177*2d543d20SAndroid Build Coastguard Worker	allow printer_device_t fs_t:filesystem associate;
1178*2d543d20SAndroid Build Coastguard Worker	allow printer_device_t tmpfs_t:filesystem associate;
1179*2d543d20SAndroid Build Coastguard Worker	allow printer_device_t tmp_t:filesystem associate;
1180*2d543d20SAndroid Build Coastguard Worker	typeattribute random_device_t device_node;
1181*2d543d20SAndroid Build Coastguard Worker	allow random_device_t fs_t:filesystem associate;
1182*2d543d20SAndroid Build Coastguard Worker	allow random_device_t tmpfs_t:filesystem associate;
1183*2d543d20SAndroid Build Coastguard Worker	allow random_device_t tmp_t:filesystem associate;
1184*2d543d20SAndroid Build Coastguard Worker	typeattribute scanner_device_t device_node;
1185*2d543d20SAndroid Build Coastguard Worker	allow scanner_device_t fs_t:filesystem associate;
1186*2d543d20SAndroid Build Coastguard Worker	allow scanner_device_t tmpfs_t:filesystem associate;
1187*2d543d20SAndroid Build Coastguard Worker	allow scanner_device_t tmp_t:filesystem associate;
1188*2d543d20SAndroid Build Coastguard Worker	typeattribute sound_device_t device_node;
1189*2d543d20SAndroid Build Coastguard Worker	allow sound_device_t fs_t:filesystem associate;
1190*2d543d20SAndroid Build Coastguard Worker	allow sound_device_t tmpfs_t:filesystem associate;
1191*2d543d20SAndroid Build Coastguard Worker	allow sound_device_t tmp_t:filesystem associate;
1192*2d543d20SAndroid Build Coastguard Worker	allow sysfs_t fs_t:filesystem associate;
1193*2d543d20SAndroid Build Coastguard Worker	allow sysfs_t noxattrfs:filesystem associate;
1194*2d543d20SAndroid Build Coastguard Worker	typeattribute sysfs_t file_type;
1195*2d543d20SAndroid Build Coastguard Worker	typeattribute sysfs_t mountpoint;
1196*2d543d20SAndroid Build Coastguard Worker	typeattribute sysfs_t filesystem_type;
1197*2d543d20SAndroid Build Coastguard Worker	allow sysfs_t self:filesystem associate;
1198*2d543d20SAndroid Build Coastguard Worker	typeattribute urandom_device_t device_node;
1199*2d543d20SAndroid Build Coastguard Worker	allow urandom_device_t fs_t:filesystem associate;
1200*2d543d20SAndroid Build Coastguard Worker	allow urandom_device_t tmpfs_t:filesystem associate;
1201*2d543d20SAndroid Build Coastguard Worker	allow urandom_device_t tmp_t:filesystem associate;
1202*2d543d20SAndroid Build Coastguard Worker	allow usbfs_t fs_t:filesystem associate;
1203*2d543d20SAndroid Build Coastguard Worker	allow usbfs_t noxattrfs:filesystem associate;
1204*2d543d20SAndroid Build Coastguard Worker	typeattribute usbfs_t file_type;
1205*2d543d20SAndroid Build Coastguard Worker	typeattribute usbfs_t mountpoint;
1206*2d543d20SAndroid Build Coastguard Worker	typeattribute usbfs_t filesystem_type;
1207*2d543d20SAndroid Build Coastguard Worker	allow usbfs_t self:filesystem associate;
1208*2d543d20SAndroid Build Coastguard Worker	typeattribute usbfs_t noxattrfs;
1209*2d543d20SAndroid Build Coastguard Worker	typeattribute usb_device_t device_node;
1210*2d543d20SAndroid Build Coastguard Worker	allow usb_device_t fs_t:filesystem associate;
1211*2d543d20SAndroid Build Coastguard Worker	allow usb_device_t tmpfs_t:filesystem associate;
1212*2d543d20SAndroid Build Coastguard Worker	allow usb_device_t tmp_t:filesystem associate;
1213*2d543d20SAndroid Build Coastguard Worker	typeattribute v4l_device_t device_node;
1214*2d543d20SAndroid Build Coastguard Worker	allow v4l_device_t fs_t:filesystem associate;
1215*2d543d20SAndroid Build Coastguard Worker	allow v4l_device_t tmpfs_t:filesystem associate;
1216*2d543d20SAndroid Build Coastguard Worker	allow v4l_device_t tmp_t:filesystem associate;
1217*2d543d20SAndroid Build Coastguard Worker	typeattribute xserver_misc_device_t device_node;
1218*2d543d20SAndroid Build Coastguard Worker	allow xserver_misc_device_t fs_t:filesystem associate;
1219*2d543d20SAndroid Build Coastguard Worker	allow xserver_misc_device_t tmpfs_t:filesystem associate;
1220*2d543d20SAndroid Build Coastguard Worker	allow xserver_misc_device_t tmp_t:filesystem associate;
1221*2d543d20SAndroid Build Coastguard Worker	typeattribute zero_device_t device_node;
1222*2d543d20SAndroid Build Coastguard Worker	allow zero_device_t fs_t:filesystem associate;
1223*2d543d20SAndroid Build Coastguard Worker	allow zero_device_t tmpfs_t:filesystem associate;
1224*2d543d20SAndroid Build Coastguard Worker	allow zero_device_t tmp_t:filesystem associate;
1225*2d543d20SAndroid Build Coastguard Worker	typeattribute zero_device_t mlstrustedobject;
1226*2d543d20SAndroid Build Coastguard Worker	allow xconsole_device_t fs_t:filesystem associate;
1227*2d543d20SAndroid Build Coastguard Worker	allow xconsole_device_t noxattrfs:filesystem associate;
1228*2d543d20SAndroid Build Coastguard Worker	typeattribute xconsole_device_t file_type;
1229*2d543d20SAndroid Build Coastguard Worker	allow xconsole_device_t tmpfs_t:filesystem associate;
1230*2d543d20SAndroid Build Coastguard Worker	allow xconsole_device_t tmp_t:filesystem associate;
1231*2d543d20SAndroid Build Coastguard Worker	typeattribute devfs_control_t device_node;
1232*2d543d20SAndroid Build Coastguard Worker	allow devfs_control_t fs_t:filesystem associate;
1233*2d543d20SAndroid Build Coastguard Worker	allow devfs_control_t tmpfs_t:filesystem associate;
1234*2d543d20SAndroid Build Coastguard Worker	allow devfs_control_t tmp_t:filesystem associate;
1235*2d543d20SAndroid Build Coastguard Workerneverallow domain ~domain:process { transition dyntransition };
1236*2d543d20SAndroid Build Coastguard Workerneverallow { domain -set_curr_context } self:process setcurrent;
1237*2d543d20SAndroid Build Coastguard Workerneverallow { domain unlabeled_t } ~{ domain unlabeled_t }:process *;
1238*2d543d20SAndroid Build Coastguard Workerneverallow ~{ domain unlabeled_t } *:process *;
1239*2d543d20SAndroid Build Coastguard Workerallow file_type self:filesystem associate;
1240*2d543d20SAndroid Build Coastguard Worker	allow boot_t fs_t:filesystem associate;
1241*2d543d20SAndroid Build Coastguard Worker	allow boot_t noxattrfs:filesystem associate;
1242*2d543d20SAndroid Build Coastguard Worker	typeattribute boot_t file_type;
1243*2d543d20SAndroid Build Coastguard Worker	allow boot_t fs_t:filesystem associate;
1244*2d543d20SAndroid Build Coastguard Worker	allow boot_t noxattrfs:filesystem associate;
1245*2d543d20SAndroid Build Coastguard Worker	typeattribute boot_t file_type;
1246*2d543d20SAndroid Build Coastguard Worker	typeattribute boot_t mountpoint;
1247*2d543d20SAndroid Build Coastguard Worker	allow default_t fs_t:filesystem associate;
1248*2d543d20SAndroid Build Coastguard Worker	allow default_t noxattrfs:filesystem associate;
1249*2d543d20SAndroid Build Coastguard Worker	allow etc_t fs_t:filesystem associate;
1250*2d543d20SAndroid Build Coastguard Worker	allow etc_t noxattrfs:filesystem associate;
1251*2d543d20SAndroid Build Coastguard Worker	allow etc_runtime_t fs_t:filesystem associate;
1252*2d543d20SAndroid Build Coastguard Worker	allow etc_runtime_t noxattrfs:filesystem associate;
1253*2d543d20SAndroid Build Coastguard Worker	allow file_t fs_t:filesystem associate;
1254*2d543d20SAndroid Build Coastguard Worker	allow file_t noxattrfs:filesystem associate;
1255*2d543d20SAndroid Build Coastguard Worker	allow kernel_t file_t:dir mounton;
1256*2d543d20SAndroid Build Coastguard Worker	allow home_root_t fs_t:filesystem associate;
1257*2d543d20SAndroid Build Coastguard Worker	allow home_root_t noxattrfs:filesystem associate;
1258*2d543d20SAndroid Build Coastguard Worker	allow home_root_t fs_t:filesystem associate;
1259*2d543d20SAndroid Build Coastguard Worker	allow home_root_t noxattrfs:filesystem associate;
1260*2d543d20SAndroid Build Coastguard Worker	typeattribute home_root_t file_type;
1261*2d543d20SAndroid Build Coastguard Worker	typeattribute home_root_t polyparent;
1262*2d543d20SAndroid Build Coastguard Worker	allow lost_found_t fs_t:filesystem associate;
1263*2d543d20SAndroid Build Coastguard Worker	allow lost_found_t noxattrfs:filesystem associate;
1264*2d543d20SAndroid Build Coastguard Worker	allow mnt_t fs_t:filesystem associate;
1265*2d543d20SAndroid Build Coastguard Worker	allow mnt_t noxattrfs:filesystem associate;
1266*2d543d20SAndroid Build Coastguard Worker	allow modules_object_t fs_t:filesystem associate;
1267*2d543d20SAndroid Build Coastguard Worker	allow modules_object_t noxattrfs:filesystem associate;
1268*2d543d20SAndroid Build Coastguard Worker	typeattribute modules_object_t file_type;
1269*2d543d20SAndroid Build Coastguard Worker	allow no_access_t fs_t:filesystem associate;
1270*2d543d20SAndroid Build Coastguard Worker	allow no_access_t noxattrfs:filesystem associate;
1271*2d543d20SAndroid Build Coastguard Worker	allow poly_t fs_t:filesystem associate;
1272*2d543d20SAndroid Build Coastguard Worker	allow poly_t noxattrfs:filesystem associate;
1273*2d543d20SAndroid Build Coastguard Worker	allow readable_t fs_t:filesystem associate;
1274*2d543d20SAndroid Build Coastguard Worker	allow readable_t noxattrfs:filesystem associate;
1275*2d543d20SAndroid Build Coastguard Worker	allow root_t fs_t:filesystem associate;
1276*2d543d20SAndroid Build Coastguard Worker	allow root_t noxattrfs:filesystem associate;
1277*2d543d20SAndroid Build Coastguard Worker	allow root_t fs_t:filesystem associate;
1278*2d543d20SAndroid Build Coastguard Worker	allow root_t noxattrfs:filesystem associate;
1279*2d543d20SAndroid Build Coastguard Worker	typeattribute root_t file_type;
1280*2d543d20SAndroid Build Coastguard Worker	typeattribute root_t polyparent;
1281*2d543d20SAndroid Build Coastguard Worker	allow kernel_t root_t:dir mounton;
1282*2d543d20SAndroid Build Coastguard Worker	allow src_t fs_t:filesystem associate;
1283*2d543d20SAndroid Build Coastguard Worker	allow src_t noxattrfs:filesystem associate;
1284*2d543d20SAndroid Build Coastguard Worker	allow system_map_t fs_t:filesystem associate;
1285*2d543d20SAndroid Build Coastguard Worker	allow system_map_t noxattrfs:filesystem associate;
1286*2d543d20SAndroid Build Coastguard Worker	typeattribute system_map_t file_type;
1287*2d543d20SAndroid Build Coastguard Worker	allow tmp_t fs_t:filesystem associate;
1288*2d543d20SAndroid Build Coastguard Worker	allow tmp_t noxattrfs:filesystem associate;
1289*2d543d20SAndroid Build Coastguard Worker	typeattribute tmp_t file_type;
1290*2d543d20SAndroid Build Coastguard Worker	allow tmp_t fs_t:filesystem associate;
1291*2d543d20SAndroid Build Coastguard Worker	allow tmp_t noxattrfs:filesystem associate;
1292*2d543d20SAndroid Build Coastguard Worker	typeattribute tmp_t file_type;
1293*2d543d20SAndroid Build Coastguard Worker	typeattribute tmp_t polymember;
1294*2d543d20SAndroid Build Coastguard Worker	allow tmp_t tmpfs_t:filesystem associate;
1295*2d543d20SAndroid Build Coastguard Worker	typeattribute tmp_t tmpfile;
1296*2d543d20SAndroid Build Coastguard Worker	allow tmp_t tmp_t:filesystem associate;
1297*2d543d20SAndroid Build Coastguard Worker	allow tmp_t fs_t:filesystem associate;
1298*2d543d20SAndroid Build Coastguard Worker	allow tmp_t noxattrfs:filesystem associate;
1299*2d543d20SAndroid Build Coastguard Worker	typeattribute tmp_t file_type;
1300*2d543d20SAndroid Build Coastguard Worker	typeattribute tmp_t polyparent;
1301*2d543d20SAndroid Build Coastguard Worker	allow usr_t fs_t:filesystem associate;
1302*2d543d20SAndroid Build Coastguard Worker	allow usr_t noxattrfs:filesystem associate;
1303*2d543d20SAndroid Build Coastguard Worker	allow var_t fs_t:filesystem associate;
1304*2d543d20SAndroid Build Coastguard Worker	allow var_t noxattrfs:filesystem associate;
1305*2d543d20SAndroid Build Coastguard Worker	allow var_lib_t fs_t:filesystem associate;
1306*2d543d20SAndroid Build Coastguard Worker	allow var_lib_t noxattrfs:filesystem associate;
1307*2d543d20SAndroid Build Coastguard Worker	allow var_lock_t fs_t:filesystem associate;
1308*2d543d20SAndroid Build Coastguard Worker	allow var_lock_t noxattrfs:filesystem associate;
1309*2d543d20SAndroid Build Coastguard Worker	allow var_run_t fs_t:filesystem associate;
1310*2d543d20SAndroid Build Coastguard Worker	allow var_run_t noxattrfs:filesystem associate;
1311*2d543d20SAndroid Build Coastguard Worker	allow var_spool_t fs_t:filesystem associate;
1312*2d543d20SAndroid Build Coastguard Worker	allow var_spool_t noxattrfs:filesystem associate;
1313*2d543d20SAndroid Build Coastguard Worker	typeattribute var_spool_t file_type;
1314*2d543d20SAndroid Build Coastguard Worker	allow var_spool_t fs_t:filesystem associate;
1315*2d543d20SAndroid Build Coastguard Worker	allow var_spool_t noxattrfs:filesystem associate;
1316*2d543d20SAndroid Build Coastguard Worker	typeattribute var_spool_t file_type;
1317*2d543d20SAndroid Build Coastguard Worker	typeattribute var_spool_t polymember;
1318*2d543d20SAndroid Build Coastguard Worker	allow var_spool_t tmpfs_t:filesystem associate;
1319*2d543d20SAndroid Build Coastguard Worker	typeattribute var_spool_t tmpfile;
1320*2d543d20SAndroid Build Coastguard Worker	allow var_spool_t tmp_t:filesystem associate;
1321*2d543d20SAndroid Build Coastguard Worker	typeattribute fs_t filesystem_type;
1322*2d543d20SAndroid Build Coastguard Worker	allow fs_t self:filesystem associate;
1323*2d543d20SAndroid Build Coastguard Worker	typeattribute bdev_t filesystem_type;
1324*2d543d20SAndroid Build Coastguard Worker	allow bdev_t self:filesystem associate;
1325*2d543d20SAndroid Build Coastguard Worker	typeattribute binfmt_misc_fs_t filesystem_type;
1326*2d543d20SAndroid Build Coastguard Worker	allow binfmt_misc_fs_t self:filesystem associate;
1327*2d543d20SAndroid Build Coastguard Worker	allow binfmt_misc_fs_t fs_t:filesystem associate;
1328*2d543d20SAndroid Build Coastguard Worker	allow binfmt_misc_fs_t noxattrfs:filesystem associate;
1329*2d543d20SAndroid Build Coastguard Worker	typeattribute binfmt_misc_fs_t file_type;
1330*2d543d20SAndroid Build Coastguard Worker	typeattribute binfmt_misc_fs_t mountpoint;
1331*2d543d20SAndroid Build Coastguard Worker	typeattribute capifs_t filesystem_type;
1332*2d543d20SAndroid Build Coastguard Worker	allow capifs_t self:filesystem associate;
1333*2d543d20SAndroid Build Coastguard Worker	typeattribute configfs_t filesystem_type;
1334*2d543d20SAndroid Build Coastguard Worker	allow configfs_t self:filesystem associate;
1335*2d543d20SAndroid Build Coastguard Worker	typeattribute eventpollfs_t filesystem_type;
1336*2d543d20SAndroid Build Coastguard Worker	allow eventpollfs_t self:filesystem associate;
1337*2d543d20SAndroid Build Coastguard Worker	typeattribute futexfs_t filesystem_type;
1338*2d543d20SAndroid Build Coastguard Worker	allow futexfs_t self:filesystem associate;
1339*2d543d20SAndroid Build Coastguard Worker	typeattribute hugetlbfs_t filesystem_type;
1340*2d543d20SAndroid Build Coastguard Worker	allow hugetlbfs_t self:filesystem associate;
1341*2d543d20SAndroid Build Coastguard Worker	allow hugetlbfs_t fs_t:filesystem associate;
1342*2d543d20SAndroid Build Coastguard Worker	allow hugetlbfs_t noxattrfs:filesystem associate;
1343*2d543d20SAndroid Build Coastguard Worker	typeattribute hugetlbfs_t file_type;
1344*2d543d20SAndroid Build Coastguard Worker	typeattribute hugetlbfs_t mountpoint;
1345*2d543d20SAndroid Build Coastguard Worker	typeattribute inotifyfs_t filesystem_type;
1346*2d543d20SAndroid Build Coastguard Worker	allow inotifyfs_t self:filesystem associate;
1347*2d543d20SAndroid Build Coastguard Worker	typeattribute nfsd_fs_t filesystem_type;
1348*2d543d20SAndroid Build Coastguard Worker	allow nfsd_fs_t self:filesystem associate;
1349*2d543d20SAndroid Build Coastguard Worker	typeattribute ramfs_t filesystem_type;
1350*2d543d20SAndroid Build Coastguard Worker	allow ramfs_t self:filesystem associate;
1351*2d543d20SAndroid Build Coastguard Worker	typeattribute romfs_t filesystem_type;
1352*2d543d20SAndroid Build Coastguard Worker	allow romfs_t self:filesystem associate;
1353*2d543d20SAndroid Build Coastguard Worker	typeattribute rpc_pipefs_t filesystem_type;
1354*2d543d20SAndroid Build Coastguard Worker	allow rpc_pipefs_t self:filesystem associate;
1355*2d543d20SAndroid Build Coastguard Worker	typeattribute tmpfs_t filesystem_type;
1356*2d543d20SAndroid Build Coastguard Worker	allow tmpfs_t self:filesystem associate;
1357*2d543d20SAndroid Build Coastguard Worker	allow tmpfs_t fs_t:filesystem associate;
1358*2d543d20SAndroid Build Coastguard Worker	allow tmpfs_t noxattrfs:filesystem associate;
1359*2d543d20SAndroid Build Coastguard Worker	typeattribute tmpfs_t file_type;
1360*2d543d20SAndroid Build Coastguard Worker	allow tmpfs_t fs_t:filesystem associate;
1361*2d543d20SAndroid Build Coastguard Worker	allow tmpfs_t noxattrfs:filesystem associate;
1362*2d543d20SAndroid Build Coastguard Worker	typeattribute tmpfs_t file_type;
1363*2d543d20SAndroid Build Coastguard Worker	typeattribute tmpfs_t mountpoint;
1364*2d543d20SAndroid Build Coastguard Workerallow tmpfs_t noxattrfs:filesystem associate;
1365*2d543d20SAndroid Build Coastguard Worker	typeattribute autofs_t filesystem_type;
1366*2d543d20SAndroid Build Coastguard Worker	allow autofs_t self:filesystem associate;
1367*2d543d20SAndroid Build Coastguard Worker	allow autofs_t fs_t:filesystem associate;
1368*2d543d20SAndroid Build Coastguard Worker	allow autofs_t noxattrfs:filesystem associate;
1369*2d543d20SAndroid Build Coastguard Worker	typeattribute autofs_t file_type;
1370*2d543d20SAndroid Build Coastguard Worker	typeattribute autofs_t mountpoint;
1371*2d543d20SAndroid Build Coastguard Worker	typeattribute cifs_t filesystem_type;
1372*2d543d20SAndroid Build Coastguard Worker	allow cifs_t self:filesystem associate;
1373*2d543d20SAndroid Build Coastguard Worker	typeattribute dosfs_t filesystem_type;
1374*2d543d20SAndroid Build Coastguard Worker	allow dosfs_t self:filesystem associate;
1375*2d543d20SAndroid Build Coastguard Workerallow dosfs_t fs_t:filesystem associate;
1376*2d543d20SAndroid Build Coastguard Worker	typeattribute iso9660_t filesystem_type;
1377*2d543d20SAndroid Build Coastguard Worker	allow iso9660_t self:filesystem associate;
1378*2d543d20SAndroid Build Coastguard Workerallow removable_t noxattrfs:filesystem associate;
1379*2d543d20SAndroid Build Coastguard Worker	typeattribute removable_t filesystem_type;
1380*2d543d20SAndroid Build Coastguard Worker	allow removable_t self:filesystem associate;
1381*2d543d20SAndroid Build Coastguard Worker	allow removable_t fs_t:filesystem associate;
1382*2d543d20SAndroid Build Coastguard Worker	allow removable_t noxattrfs:filesystem associate;
1383*2d543d20SAndroid Build Coastguard Worker	typeattribute removable_t file_type;
1384*2d543d20SAndroid Build Coastguard Worker	typeattribute removable_t usercanread;
1385*2d543d20SAndroid Build Coastguard Worker	typeattribute nfs_t filesystem_type;
1386*2d543d20SAndroid Build Coastguard Worker	allow nfs_t self:filesystem associate;
1387*2d543d20SAndroid Build Coastguard Worker	allow nfs_t fs_t:filesystem associate;
1388*2d543d20SAndroid Build Coastguard Worker	allow nfs_t noxattrfs:filesystem associate;
1389*2d543d20SAndroid Build Coastguard Worker	typeattribute nfs_t file_type;
1390*2d543d20SAndroid Build Coastguard Worker	typeattribute nfs_t mountpoint;
1391*2d543d20SAndroid Build Coastguard Workerneverallow ~can_load_kernmodule self:capability sys_module;
1392*2d543d20SAndroid Build Coastguard Workerrole system_r;
1393*2d543d20SAndroid Build Coastguard Workerrole sysadm_r;
1394*2d543d20SAndroid Build Coastguard Workerrole staff_r;
1395*2d543d20SAndroid Build Coastguard Workerrole user_r;
1396*2d543d20SAndroid Build Coastguard Workerrole secadm_r;
1397*2d543d20SAndroid Build Coastguard Worker	typeattribute kernel_t domain;
1398*2d543d20SAndroid Build Coastguard Worker	allow kernel_t self:dir { read getattr lock search ioctl };
1399*2d543d20SAndroid Build Coastguard Worker	allow kernel_t self:lnk_file { read getattr lock ioctl };
1400*2d543d20SAndroid Build Coastguard Worker	allow kernel_t self:file { getattr read write append ioctl lock };
1401*2d543d20SAndroid Build Coastguard Worker	allow kernel_t self:process { fork sigchld };
1402*2d543d20SAndroid Build Coastguard Worker		role secadm_r types kernel_t;
1403*2d543d20SAndroid Build Coastguard Worker		role sysadm_r types kernel_t;
1404*2d543d20SAndroid Build Coastguard Worker		role user_r types kernel_t;
1405*2d543d20SAndroid Build Coastguard Worker		role staff_r types kernel_t;
1406*2d543d20SAndroid Build Coastguard Worker	typeattribute kernel_t privrangetrans;
1407*2d543d20SAndroid Build Coastguard Workerrole system_r types kernel_t;
1408*2d543d20SAndroid Build Coastguard Worker	typeattribute debugfs_t filesystem_type;
1409*2d543d20SAndroid Build Coastguard Worker	allow debugfs_t self:filesystem associate;
1410*2d543d20SAndroid Build Coastguard Workerallow debugfs_t self:filesystem associate;
1411*2d543d20SAndroid Build Coastguard Worker	allow proc_t fs_t:filesystem associate;
1412*2d543d20SAndroid Build Coastguard Worker	allow proc_t noxattrfs:filesystem associate;
1413*2d543d20SAndroid Build Coastguard Worker	typeattribute proc_t file_type;
1414*2d543d20SAndroid Build Coastguard Worker	typeattribute proc_t mountpoint;
1415*2d543d20SAndroid Build Coastguard Worker	typeattribute proc_t filesystem_type;
1416*2d543d20SAndroid Build Coastguard Worker	allow proc_t self:filesystem associate;
1417*2d543d20SAndroid Build Coastguard Workerneverallow ~can_receive_kernel_messages proc_kmsg_t:file ~getattr;
1418*2d543d20SAndroid Build Coastguard Workerneverallow { domain -kern_unconfined } proc_kcore_t:file ~getattr;
1419*2d543d20SAndroid Build Coastguard Worker	allow sysctl_t fs_t:filesystem associate;
1420*2d543d20SAndroid Build Coastguard Worker	allow sysctl_t noxattrfs:filesystem associate;
1421*2d543d20SAndroid Build Coastguard Worker	typeattribute sysctl_t file_type;
1422*2d543d20SAndroid Build Coastguard Worker	typeattribute sysctl_t mountpoint;
1423*2d543d20SAndroid Build Coastguard Worker	allow sysctl_fs_t fs_t:filesystem associate;
1424*2d543d20SAndroid Build Coastguard Worker	allow sysctl_fs_t noxattrfs:filesystem associate;
1425*2d543d20SAndroid Build Coastguard Worker	typeattribute sysctl_fs_t file_type;
1426*2d543d20SAndroid Build Coastguard Worker	typeattribute sysctl_fs_t mountpoint;
1427*2d543d20SAndroid Build Coastguard Workerallow kernel_t self:capability *;
1428*2d543d20SAndroid Build Coastguard Workerallow kernel_t unlabeled_t:dir mounton;
1429*2d543d20SAndroid Build Coastguard Workerallow kernel_t self:process ~{ ptrace setcurrent setexec setfscreate setrlimit execmem execstack execheap };
1430*2d543d20SAndroid Build Coastguard Workerallow kernel_t self:shm { associate getattr setattr create destroy read write lock unix_read unix_write };
1431*2d543d20SAndroid Build Coastguard Workerallow kernel_t self:sem { associate getattr setattr create destroy read write unix_read unix_write };
1432*2d543d20SAndroid Build Coastguard Workerallow kernel_t self:msg { send receive };
1433*2d543d20SAndroid Build Coastguard Workerallow kernel_t self:msgq { associate getattr setattr create destroy read write enqueue unix_read unix_write };
1434*2d543d20SAndroid Build Coastguard Workerallow kernel_t self:unix_dgram_socket { create { ioctl read getattr write setattr append bind connect getopt setopt shutdown } };
1435*2d543d20SAndroid Build Coastguard Workerallow kernel_t self:unix_stream_socket { { create { ioctl read getattr write setattr append bind connect getopt setopt shutdown } } listen accept };
1436*2d543d20SAndroid Build Coastguard Workerallow kernel_t self:unix_dgram_socket sendto;
1437*2d543d20SAndroid Build Coastguard Workerallow kernel_t self:unix_stream_socket connectto;
1438*2d543d20SAndroid Build Coastguard Workerallow kernel_t self:fifo_file { getattr read write append ioctl lock };
1439*2d543d20SAndroid Build Coastguard Workerallow kernel_t self:sock_file { read getattr lock ioctl };
1440*2d543d20SAndroid Build Coastguard Workerallow kernel_t self:fd use;
1441*2d543d20SAndroid Build Coastguard Workerallow kernel_t proc_t:dir { read getattr lock search ioctl };
1442*2d543d20SAndroid Build Coastguard Workerallow kernel_t proc_t:{ lnk_file file } { read getattr lock ioctl };
1443*2d543d20SAndroid Build Coastguard Workerallow kernel_t proc_net_t:dir { read getattr lock search ioctl };
1444*2d543d20SAndroid Build Coastguard Workerallow kernel_t proc_net_t:file { read getattr lock ioctl };
1445*2d543d20SAndroid Build Coastguard Workerallow kernel_t proc_mdstat_t:file { read getattr lock ioctl };
1446*2d543d20SAndroid Build Coastguard Workerallow kernel_t proc_kcore_t:file getattr;
1447*2d543d20SAndroid Build Coastguard Workerallow kernel_t proc_kmsg_t:file getattr;
1448*2d543d20SAndroid Build Coastguard Workerallow kernel_t sysctl_t:dir { read getattr lock search ioctl };
1449*2d543d20SAndroid Build Coastguard Workerallow kernel_t sysctl_kernel_t:dir { read getattr lock search ioctl };
1450*2d543d20SAndroid Build Coastguard Workerallow kernel_t sysctl_kernel_t:file { read getattr lock ioctl };
1451*2d543d20SAndroid Build Coastguard Workerallow kernel_t unlabeled_t:fifo_file { getattr read write append ioctl lock };
1452*2d543d20SAndroid Build Coastguard Worker	allow kernel_t unlabeled_t:association { sendto recvfrom };
1453*2d543d20SAndroid Build Coastguard Worker	allow kernel_t netif_type:netif rawip_send;
1454*2d543d20SAndroid Build Coastguard Worker	allow kernel_t netif_type:netif rawip_recv;
1455*2d543d20SAndroid Build Coastguard Worker	allow kernel_t node_type:node rawip_send;
1456*2d543d20SAndroid Build Coastguard Worker	allow kernel_t node_type:node rawip_recv;
1457*2d543d20SAndroid Build Coastguard Worker	allow kernel_t netif_t:netif rawip_send;
1458*2d543d20SAndroid Build Coastguard Worker	allow kernel_t netif_type:netif { tcp_send tcp_recv };
1459*2d543d20SAndroid Build Coastguard Worker	allow kernel_t node_type:node { tcp_send tcp_recv };
1460*2d543d20SAndroid Build Coastguard Worker	allow kernel_t node_t:node rawip_send;
1461*2d543d20SAndroid Build Coastguard Worker	allow kernel_t multicast_node_t:node rawip_send;
1462*2d543d20SAndroid Build Coastguard Worker	allow kernel_t sysfs_t:dir { read getattr lock search ioctl };
1463*2d543d20SAndroid Build Coastguard Worker	allow kernel_t sysfs_t:{ file lnk_file } { read getattr lock ioctl };
1464*2d543d20SAndroid Build Coastguard Worker	allow kernel_t usbfs_t:dir search;
1465*2d543d20SAndroid Build Coastguard Worker	allow kernel_t filesystem_type:filesystem mount;
1466*2d543d20SAndroid Build Coastguard Worker	allow kernel_t security_t:dir { read search getattr };
1467*2d543d20SAndroid Build Coastguard Worker	allow kernel_t security_t:file { getattr read write };
1468*2d543d20SAndroid Build Coastguard Worker	typeattribute kernel_t can_load_policy;
1469*2d543d20SAndroid Build Coastguard Worker	if(!secure_mode_policyload) {
1470*2d543d20SAndroid Build Coastguard Worker		allow kernel_t security_t:security load_policy;
1471*2d543d20SAndroid Build Coastguard Worker		auditallow kernel_t security_t:security load_policy;
1472*2d543d20SAndroid Build Coastguard Worker	}
1473*2d543d20SAndroid Build Coastguard Worker	allow kernel_t device_t:dir { read getattr lock search ioctl };
1474*2d543d20SAndroid Build Coastguard Worker	allow kernel_t device_t:lnk_file { getattr read };
1475*2d543d20SAndroid Build Coastguard Worker	allow kernel_t console_device_t:chr_file { getattr read write append ioctl lock };
1476*2d543d20SAndroid Build Coastguard Worker	allow kernel_t bin_t:dir { read getattr lock search ioctl };
1477*2d543d20SAndroid Build Coastguard Worker	allow kernel_t bin_t:lnk_file { read getattr lock ioctl };
1478*2d543d20SAndroid Build Coastguard Worker	allow kernel_t shell_exec_t:file { { read getattr lock execute ioctl } execute_no_trans };
1479*2d543d20SAndroid Build Coastguard Worker	allow kernel_t sbin_t:dir { read getattr lock search ioctl };
1480*2d543d20SAndroid Build Coastguard Worker	allow kernel_t bin_t:dir { read getattr lock search ioctl };
1481*2d543d20SAndroid Build Coastguard Worker	allow kernel_t bin_t:lnk_file { read getattr lock ioctl };
1482*2d543d20SAndroid Build Coastguard Worker	allow kernel_t bin_t:file { { read getattr lock execute ioctl } execute_no_trans };
1483*2d543d20SAndroid Build Coastguard Worker	allow kernel_t domain:process signal;
1484*2d543d20SAndroid Build Coastguard Worker	allow kernel_t proc_t:dir search;
1485*2d543d20SAndroid Build Coastguard Worker	allow kernel_t domain:dir search;
1486*2d543d20SAndroid Build Coastguard Worker	allow kernel_t root_t:dir { read getattr lock search ioctl };
1487*2d543d20SAndroid Build Coastguard Worker	allow kernel_t root_t:lnk_file { read getattr lock ioctl };
1488*2d543d20SAndroid Build Coastguard Worker	allow kernel_t etc_t:dir { read getattr lock search ioctl };
1489*2d543d20SAndroid Build Coastguard Worker	allow kernel_t home_root_t:dir { read getattr lock search ioctl };
1490*2d543d20SAndroid Build Coastguard Worker	allow kernel_t usr_t:dir { read getattr lock search ioctl };
1491*2d543d20SAndroid Build Coastguard Worker	allow kernel_t usr_t:{ file lnk_file } { read getattr lock ioctl };
1492*2d543d20SAndroid Build Coastguard Worker	typeattribute kernel_t mlsprocread;
1493*2d543d20SAndroid Build Coastguard Worker	typeattribute kernel_t mlsprocwrite;
1494*2d543d20SAndroid Build Coastguard Worker	allow kernel_t self:capability *;
1495*2d543d20SAndroid Build Coastguard Worker	allow kernel_t self:fifo_file { create ioctl read getattr lock write setattr append link unlink rename };
1496*2d543d20SAndroid Build Coastguard Worker	allow kernel_t self:process transition;
1497*2d543d20SAndroid Build Coastguard Worker	allow kernel_t self:file { getattr read write append ioctl lock };
1498*2d543d20SAndroid Build Coastguard Worker	allow kernel_t self:nscd *;
1499*2d543d20SAndroid Build Coastguard Worker	allow kernel_t self:dbus *;
1500*2d543d20SAndroid Build Coastguard Worker	allow kernel_t self:passwd *;
1501*2d543d20SAndroid Build Coastguard Worker	allow kernel_t proc_type:{ dir file } *;
1502*2d543d20SAndroid Build Coastguard Worker	allow kernel_t sysctl_t:{ dir file } *;
1503*2d543d20SAndroid Build Coastguard Worker	allow kernel_t kernel_t:system *;
1504*2d543d20SAndroid Build Coastguard Worker	allow kernel_t unlabeled_t:{ dir file lnk_file sock_file fifo_file chr_file blk_file } *;
1505*2d543d20SAndroid Build Coastguard Worker	allow kernel_t unlabeled_t:filesystem *;
1506*2d543d20SAndroid Build Coastguard Worker	allow kernel_t unlabeled_t:association *;
1507*2d543d20SAndroid Build Coastguard Worker	typeattribute kernel_t can_load_kernmodule, can_receive_kernel_messages;
1508*2d543d20SAndroid Build Coastguard Worker	typeattribute kernel_t kern_unconfined;
1509*2d543d20SAndroid Build Coastguard Worker	allow kernel_t { proc_t proc_net_t }:dir search;
1510*2d543d20SAndroid Build Coastguard Worker	allow kernel_t sysctl_type:dir { read getattr lock search ioctl };
1511*2d543d20SAndroid Build Coastguard Worker	allow kernel_t sysctl_type:file { { getattr read write append ioctl lock } setattr };
1512*2d543d20SAndroid Build Coastguard Worker	allow kernel_t node_type:node *;
1513*2d543d20SAndroid Build Coastguard Worker	allow kernel_t netif_type:netif *;
1514*2d543d20SAndroid Build Coastguard Worker	allow kernel_t port_type:tcp_socket { send_msg recv_msg name_connect };
1515*2d543d20SAndroid Build Coastguard Worker	allow kernel_t port_type:udp_socket { send_msg recv_msg };
1516*2d543d20SAndroid Build Coastguard Worker	allow kernel_t port_type:{ tcp_socket udp_socket rawip_socket } name_bind;
1517*2d543d20SAndroid Build Coastguard Worker	allow kernel_t node_type:{ tcp_socket udp_socket rawip_socket } node_bind;
1518*2d543d20SAndroid Build Coastguard Worker	allow kernel_t unlabeled_t:association { sendto recvfrom };
1519*2d543d20SAndroid Build Coastguard Worker	allow kernel_t device_node:{ chr_file blk_file } *;
1520*2d543d20SAndroid Build Coastguard Worker	allow kernel_t mtrr_device_t:{ dir file } *;
1521*2d543d20SAndroid Build Coastguard Worker	allow kernel_t self:capability sys_rawio;
1522*2d543d20SAndroid Build Coastguard Worker	typeattribute kernel_t memory_raw_write, memory_raw_read;
1523*2d543d20SAndroid Build Coastguard Worker	typeattribute kernel_t unconfined_domain_type;
1524*2d543d20SAndroid Build Coastguard Worker	typeattribute kernel_t can_change_process_identity;
1525*2d543d20SAndroid Build Coastguard Worker	typeattribute kernel_t can_change_process_role;
1526*2d543d20SAndroid Build Coastguard Worker	typeattribute kernel_t can_change_object_identity;
1527*2d543d20SAndroid Build Coastguard Worker	typeattribute kernel_t set_curr_context;
1528*2d543d20SAndroid Build Coastguard Worker	allow kernel_t domain:{ { tcp_socket udp_socket rawip_socket netlink_socket packet_socket unix_stream_socket unix_dgram_socket netlink_route_socket netlink_firewall_socket netlink_tcpdiag_socket netlink_nflog_socket netlink_xfrm_socket netlink_selinux_socket netlink_audit_socket netlink_ip6fw_socket netlink_dnrt_socket netlink_kobject_uevent_socket } socket key_socket } *;
1529*2d543d20SAndroid Build Coastguard Worker	allow kernel_t domain:fd use;
1530*2d543d20SAndroid Build Coastguard Worker	allow kernel_t domain:fifo_file { getattr read write append ioctl lock };
1531*2d543d20SAndroid Build Coastguard Worker	allow kernel_t domain:process ~{ transition dyntransition execmem execstack execheap };
1532*2d543d20SAndroid Build Coastguard Worker	allow kernel_t domain:{ sem msgq shm } *;
1533*2d543d20SAndroid Build Coastguard Worker	allow kernel_t domain:msg { send receive };
1534*2d543d20SAndroid Build Coastguard Worker	allow kernel_t domain:dir { read getattr lock search ioctl };
1535*2d543d20SAndroid Build Coastguard Worker	allow kernel_t domain:file { read getattr lock ioctl };
1536*2d543d20SAndroid Build Coastguard Worker	allow kernel_t domain:lnk_file { read getattr lock ioctl };
1537*2d543d20SAndroid Build Coastguard Worker	dontaudit kernel_t domain:dir { read getattr lock search ioctl };
1538*2d543d20SAndroid Build Coastguard Worker	dontaudit kernel_t domain:lnk_file { read getattr lock ioctl };
1539*2d543d20SAndroid Build Coastguard Worker	dontaudit kernel_t domain:file { read getattr lock ioctl };
1540*2d543d20SAndroid Build Coastguard Worker	dontaudit kernel_t domain:sock_file { read getattr lock ioctl };
1541*2d543d20SAndroid Build Coastguard Worker	dontaudit kernel_t domain:fifo_file { read getattr lock ioctl };
1542*2d543d20SAndroid Build Coastguard Worker	allow kernel_t file_type:{ file chr_file } ~execmod;
1543*2d543d20SAndroid Build Coastguard Worker	allow kernel_t file_type:{ dir lnk_file sock_file fifo_file blk_file } *;
1544*2d543d20SAndroid Build Coastguard Worker	allow kernel_t file_type:filesystem *;
1545*2d543d20SAndroid Build Coastguard Worker	allow kernel_t file_type:{ unix_stream_socket unix_dgram_socket } name_bind;
1546*2d543d20SAndroid Build Coastguard Worker		if (allow_execmod) {
1547*2d543d20SAndroid Build Coastguard Worker			allow kernel_t file_type:file execmod;
1548*2d543d20SAndroid Build Coastguard Worker		}
1549*2d543d20SAndroid Build Coastguard Worker	allow kernel_t filesystem_type:filesystem *;
1550*2d543d20SAndroid Build Coastguard Worker	allow kernel_t filesystem_type:{ dir file lnk_file sock_file fifo_file chr_file blk_file } *;
1551*2d543d20SAndroid Build Coastguard Worker	allow kernel_t security_t:dir { getattr search read };
1552*2d543d20SAndroid Build Coastguard Worker	allow kernel_t security_t:file { getattr read write };
1553*2d543d20SAndroid Build Coastguard Worker	typeattribute kernel_t can_load_policy, can_setenforce, can_setsecparam;
1554*2d543d20SAndroid Build Coastguard Worker	if(!secure_mode_policyload) {
1555*2d543d20SAndroid Build Coastguard Worker		allow kernel_t security_t:security *;
1556*2d543d20SAndroid Build Coastguard Worker		auditallow kernel_t security_t:security { load_policy setenforce setbool };
1557*2d543d20SAndroid Build Coastguard Worker	}
1558*2d543d20SAndroid Build Coastguard Worker		if (allow_execheap) {
1559*2d543d20SAndroid Build Coastguard Worker		allow kernel_t self:process execheap;
1560*2d543d20SAndroid Build Coastguard Worker		}
1561*2d543d20SAndroid Build Coastguard Worker		if (allow_execmem) {
1562*2d543d20SAndroid Build Coastguard Worker		allow kernel_t self:process execmem;
1563*2d543d20SAndroid Build Coastguard Worker		}
1564*2d543d20SAndroid Build Coastguard Worker		if (allow_execmem && allow_execstack) {
1565*2d543d20SAndroid Build Coastguard Worker		allow kernel_t self:process execstack;
1566*2d543d20SAndroid Build Coastguard Worker		auditallow kernel_t self:process execstack;
1567*2d543d20SAndroid Build Coastguard Worker		} else {
1568*2d543d20SAndroid Build Coastguard Worker		}
1569*2d543d20SAndroid Build Coastguard Worker		if (allow_execheap) {
1570*2d543d20SAndroid Build Coastguard Worker		auditallow kernel_t self:process execheap;
1571*2d543d20SAndroid Build Coastguard Worker		}
1572*2d543d20SAndroid Build Coastguard Worker		if (allow_execmem) {
1573*2d543d20SAndroid Build Coastguard Worker		auditallow kernel_t self:process execmem;
1574*2d543d20SAndroid Build Coastguard Worker		}
1575*2d543d20SAndroid Build Coastguard Worker		if (read_default_t) {
1576*2d543d20SAndroid Build Coastguard Worker	allow kernel_t default_t:dir { read getattr lock search ioctl };
1577*2d543d20SAndroid Build Coastguard Worker	allow kernel_t default_t:file { read getattr lock ioctl };
1578*2d543d20SAndroid Build Coastguard Worker	allow kernel_t default_t:lnk_file { read getattr lock ioctl };
1579*2d543d20SAndroid Build Coastguard Worker	allow kernel_t default_t:sock_file { read getattr lock ioctl };
1580*2d543d20SAndroid Build Coastguard Worker	allow kernel_t default_t:fifo_file { read getattr lock ioctl };
1581*2d543d20SAndroid Build Coastguard Worker		}
1582*2d543d20SAndroid Build Coastguard Worker	allow unlabeled_t self:filesystem associate;
1583*2d543d20SAndroid Build Coastguard Workerrange_transition getty_t login_exec_t s0 - s0:c0.c255;
1584*2d543d20SAndroid Build Coastguard Workerrange_transition init_t xdm_exec_t s0 - s0:c0.c255;
1585*2d543d20SAndroid Build Coastguard Workerrange_transition initrc_t crond_exec_t s0 - s0:c0.c255;
1586*2d543d20SAndroid Build Coastguard Workerrange_transition initrc_t cupsd_exec_t s0 - s0:c0.c255;
1587*2d543d20SAndroid Build Coastguard Workerrange_transition initrc_t sshd_exec_t s0 - s0:c0.c255;
1588*2d543d20SAndroid Build Coastguard Workerrange_transition initrc_t udev_exec_t s0 - s0:c0.c255;
1589*2d543d20SAndroid Build Coastguard Workerrange_transition initrc_t xdm_exec_t s0 - s0:c0.c255;
1590*2d543d20SAndroid Build Coastguard Workerrange_transition kernel_t udev_exec_t s0 - s0:c0.c255;
1591*2d543d20SAndroid Build Coastguard Workerrange_transition unconfined_t su_exec_t s0 - s0:c0.c255;
1592*2d543d20SAndroid Build Coastguard Workerrange_transition unconfined_t initrc_exec_t s0;
1593*2d543d20SAndroid Build Coastguard Worker	typeattribute security_t filesystem_type;
1594*2d543d20SAndroid Build Coastguard Worker	allow security_t self:filesystem associate;
1595*2d543d20SAndroid Build Coastguard Worker	typeattribute security_t mlstrustedobject;
1596*2d543d20SAndroid Build Coastguard Workerneverallow ~can_load_policy security_t:security load_policy;
1597*2d543d20SAndroid Build Coastguard Workerneverallow ~can_setenforce security_t:security setenforce;
1598*2d543d20SAndroid Build Coastguard Workerneverallow ~can_setsecparam security_t:security setsecparam;
1599*2d543d20SAndroid Build Coastguard Worker	typeattribute bsdpty_device_t device_node;
1600*2d543d20SAndroid Build Coastguard Worker	allow bsdpty_device_t fs_t:filesystem associate;
1601*2d543d20SAndroid Build Coastguard Worker	allow bsdpty_device_t tmpfs_t:filesystem associate;
1602*2d543d20SAndroid Build Coastguard Worker	allow bsdpty_device_t tmp_t:filesystem associate;
1603*2d543d20SAndroid Build Coastguard Worker	typeattribute console_device_t device_node;
1604*2d543d20SAndroid Build Coastguard Worker	allow console_device_t fs_t:filesystem associate;
1605*2d543d20SAndroid Build Coastguard Worker	allow console_device_t tmpfs_t:filesystem associate;
1606*2d543d20SAndroid Build Coastguard Worker	allow console_device_t tmp_t:filesystem associate;
1607*2d543d20SAndroid Build Coastguard Worker	allow devpts_t fs_t:filesystem associate;
1608*2d543d20SAndroid Build Coastguard Worker	allow devpts_t noxattrfs:filesystem associate;
1609*2d543d20SAndroid Build Coastguard Worker	typeattribute devpts_t file_type;
1610*2d543d20SAndroid Build Coastguard Worker	typeattribute devpts_t mountpoint;
1611*2d543d20SAndroid Build Coastguard Worker	allow devpts_t tmpfs_t:filesystem associate;
1612*2d543d20SAndroid Build Coastguard Worker	allow devpts_t tmp_t:filesystem associate;
1613*2d543d20SAndroid Build Coastguard Worker	typeattribute devpts_t filesystem_type;
1614*2d543d20SAndroid Build Coastguard Worker	allow devpts_t self:filesystem associate;
1615*2d543d20SAndroid Build Coastguard Worker	typeattribute devpts_t ttynode, ptynode;
1616*2d543d20SAndroid Build Coastguard Worker	typeattribute devtty_t device_node;
1617*2d543d20SAndroid Build Coastguard Worker	allow devtty_t fs_t:filesystem associate;
1618*2d543d20SAndroid Build Coastguard Worker	allow devtty_t tmpfs_t:filesystem associate;
1619*2d543d20SAndroid Build Coastguard Worker	allow devtty_t tmp_t:filesystem associate;
1620*2d543d20SAndroid Build Coastguard Worker	typeattribute devtty_t mlstrustedobject;
1621*2d543d20SAndroid Build Coastguard Worker	typeattribute ptmx_t device_node;
1622*2d543d20SAndroid Build Coastguard Worker	allow ptmx_t fs_t:filesystem associate;
1623*2d543d20SAndroid Build Coastguard Worker	allow ptmx_t tmpfs_t:filesystem associate;
1624*2d543d20SAndroid Build Coastguard Worker	allow ptmx_t tmp_t:filesystem associate;
1625*2d543d20SAndroid Build Coastguard Worker	typeattribute ptmx_t mlstrustedobject;
1626*2d543d20SAndroid Build Coastguard Worker	typeattribute tty_device_t device_node;
1627*2d543d20SAndroid Build Coastguard Worker	allow tty_device_t fs_t:filesystem associate;
1628*2d543d20SAndroid Build Coastguard Worker	allow tty_device_t tmpfs_t:filesystem associate;
1629*2d543d20SAndroid Build Coastguard Worker	allow tty_device_t tmp_t:filesystem associate;
1630*2d543d20SAndroid Build Coastguard Worker	typeattribute tty_device_t ttynode;
1631*2d543d20SAndroid Build Coastguard Worker	typeattribute usbtty_device_t device_node;
1632*2d543d20SAndroid Build Coastguard Worker	allow usbtty_device_t fs_t:filesystem associate;
1633*2d543d20SAndroid Build Coastguard Worker	allow usbtty_device_t tmpfs_t:filesystem associate;
1634*2d543d20SAndroid Build Coastguard Worker	allow usbtty_device_t tmp_t:filesystem associate;
1635*2d543d20SAndroid Build Coastguard Workeruser system_u roles { system_r } level s0 range s0 - s0:c0.c255;
1636*2d543d20SAndroid Build Coastguard Workeruser user_u roles { user_r sysadm_r system_r } level s0 range s0 - s0:c0.c255;
1637*2d543d20SAndroid Build Coastguard Worker	user root roles { user_r sysadm_r system_r } level s0 range s0 - s0:c0.c255;
1638*2d543d20SAndroid Build Coastguard Workerconstrain process transition
1639*2d543d20SAndroid Build Coastguard Worker	( u1 == u2
1640*2d543d20SAndroid Build Coastguard Worker	or t1 == can_change_process_identity
1641*2d543d20SAndroid Build Coastguard Worker);
1642*2d543d20SAndroid Build Coastguard Workerconstrain process transition
1643*2d543d20SAndroid Build Coastguard Worker	( r1 == r2
1644*2d543d20SAndroid Build Coastguard Worker	or t1 == can_change_process_role
1645*2d543d20SAndroid Build Coastguard Worker);
1646*2d543d20SAndroid Build Coastguard Workerconstrain process dyntransition
1647*2d543d20SAndroid Build Coastguard Worker	( u1 == u2 and r1 == r2 );
1648*2d543d20SAndroid Build Coastguard Workerconstrain { dir file lnk_file sock_file fifo_file chr_file blk_file } { create relabelto relabelfrom }
1649*2d543d20SAndroid Build Coastguard Worker	( u1 == u2 or t1 == can_change_object_identity );
1650*2d543d20SAndroid Build Coastguard Workerconstrain { tcp_socket udp_socket rawip_socket netlink_socket packet_socket unix_stream_socket unix_dgram_socket netlink_route_socket netlink_firewall_socket netlink_tcpdiag_socket netlink_nflog_socket netlink_xfrm_socket netlink_selinux_socket netlink_audit_socket netlink_ip6fw_socket netlink_dnrt_socket netlink_kobject_uevent_socket } { create relabelto relabelfrom }
1651*2d543d20SAndroid Build Coastguard Worker	( u1 == u2 or t1 == can_change_object_identity );
1652*2d543d20SAndroid Build Coastguard Workersid port system_u:object_r:port_t:s0
1653*2d543d20SAndroid Build Coastguard Workersid node system_u:object_r:node_t:s0
1654*2d543d20SAndroid Build Coastguard Workersid netif system_u:object_r:netif_t:s0
1655*2d543d20SAndroid Build Coastguard Workersid devnull system_u:object_r:null_device_t:s0
1656*2d543d20SAndroid Build Coastguard Workersid file system_u:object_r:file_t:s0
1657*2d543d20SAndroid Build Coastguard Workersid fs system_u:object_r:fs_t:s0
1658*2d543d20SAndroid Build Coastguard Workersid kernel system_u:system_r:kernel_t:s0
1659*2d543d20SAndroid Build Coastguard Workersid sysctl system_u:object_r:sysctl_t:s0
1660*2d543d20SAndroid Build Coastguard Workersid unlabeled system_u:object_r:unlabeled_t:s0
1661*2d543d20SAndroid Build Coastguard Workersid any_socket		system_u:object_r:unlabeled_t:s0
1662*2d543d20SAndroid Build Coastguard Workersid file_labels		system_u:object_r:unlabeled_t:s0
1663*2d543d20SAndroid Build Coastguard Workersid icmp_socket		system_u:object_r:unlabeled_t:s0
1664*2d543d20SAndroid Build Coastguard Workersid igmp_packet		system_u:object_r:unlabeled_t:s0
1665*2d543d20SAndroid Build Coastguard Workersid init			system_u:object_r:unlabeled_t:s0
1666*2d543d20SAndroid Build Coastguard Workersid kmod			system_u:object_r:unlabeled_t:s0
1667*2d543d20SAndroid Build Coastguard Workersid netmsg		system_u:object_r:unlabeled_t:s0
1668*2d543d20SAndroid Build Coastguard Workersid policy		system_u:object_r:unlabeled_t:s0
1669*2d543d20SAndroid Build Coastguard Workersid scmp_packet		system_u:object_r:unlabeled_t:s0
1670*2d543d20SAndroid Build Coastguard Workersid sysctl_modprobe 	system_u:object_r:unlabeled_t:s0
1671*2d543d20SAndroid Build Coastguard Workersid sysctl_fs		system_u:object_r:unlabeled_t:s0
1672*2d543d20SAndroid Build Coastguard Workersid sysctl_kernel	system_u:object_r:unlabeled_t:s0
1673*2d543d20SAndroid Build Coastguard Workersid sysctl_net		system_u:object_r:unlabeled_t:s0
1674*2d543d20SAndroid Build Coastguard Workersid sysctl_net_unix	system_u:object_r:unlabeled_t:s0
1675*2d543d20SAndroid Build Coastguard Workersid sysctl_vm		system_u:object_r:unlabeled_t:s0
1676*2d543d20SAndroid Build Coastguard Workersid sysctl_dev		system_u:object_r:unlabeled_t:s0
1677*2d543d20SAndroid Build Coastguard Workersid tcp_socket		system_u:object_r:unlabeled_t:s0
1678*2d543d20SAndroid Build Coastguard Workersid security system_u:object_r:security_t:s0
1679*2d543d20SAndroid Build Coastguard Workerfs_use_xattr ext2 system_u:object_r:fs_t:s0;
1680*2d543d20SAndroid Build Coastguard Workerfs_use_xattr ext3 system_u:object_r:fs_t:s0;
1681*2d543d20SAndroid Build Coastguard Workerfs_use_xattr gfs system_u:object_r:fs_t:s0;
1682*2d543d20SAndroid Build Coastguard Workerfs_use_xattr jfs system_u:object_r:fs_t:s0;
1683*2d543d20SAndroid Build Coastguard Workerfs_use_xattr reiserfs system_u:object_r:fs_t:s0;
1684*2d543d20SAndroid Build Coastguard Workerfs_use_xattr xfs system_u:object_r:fs_t:s0;
1685*2d543d20SAndroid Build Coastguard Workerfs_use_task pipefs system_u:object_r:fs_t:s0;
1686*2d543d20SAndroid Build Coastguard Workerfs_use_task sockfs system_u:object_r:fs_t:s0;
1687*2d543d20SAndroid Build Coastguard Workerfs_use_trans mqueue system_u:object_r:tmpfs_t:s0;
1688*2d543d20SAndroid Build Coastguard Workerfs_use_trans shm system_u:object_r:tmpfs_t:s0;
1689*2d543d20SAndroid Build Coastguard Workerfs_use_trans tmpfs system_u:object_r:tmpfs_t:s0;
1690*2d543d20SAndroid Build Coastguard Workerfs_use_trans devpts system_u:object_r:devpts_t:s0;
1691*2d543d20SAndroid Build Coastguard Workergenfscon proc /mtrr system_u:object_r:mtrr_device_t:s0
1692*2d543d20SAndroid Build Coastguard Workergenfscon sysfs / system_u:object_r:sysfs_t:s0
1693*2d543d20SAndroid Build Coastguard Workergenfscon usbfs / system_u:object_r:usbfs_t:s0
1694*2d543d20SAndroid Build Coastguard Workergenfscon usbdevfs / system_u:object_r:usbfs_t:s0
1695*2d543d20SAndroid Build Coastguard Workergenfscon rootfs / system_u:object_r:root_t:s0
1696*2d543d20SAndroid Build Coastguard Workergenfscon bdev / system_u:object_r:bdev_t:s0
1697*2d543d20SAndroid Build Coastguard Workergenfscon binfmt_misc / system_u:object_r:binfmt_misc_fs_t:s0
1698*2d543d20SAndroid Build Coastguard Workergenfscon capifs / system_u:object_r:capifs_t:s0
1699*2d543d20SAndroid Build Coastguard Workergenfscon configfs / system_u:object_r:configfs_t:s0
1700*2d543d20SAndroid Build Coastguard Workergenfscon eventpollfs / system_u:object_r:eventpollfs_t:s0
1701*2d543d20SAndroid Build Coastguard Workergenfscon futexfs / system_u:object_r:futexfs_t:s0
1702*2d543d20SAndroid Build Coastguard Workergenfscon hugetlbfs / system_u:object_r:hugetlbfs_t:s0
1703*2d543d20SAndroid Build Coastguard Workergenfscon inotifyfs / system_u:object_r:inotifyfs_t:s0
1704*2d543d20SAndroid Build Coastguard Workergenfscon nfsd / system_u:object_r:nfsd_fs_t:s0
1705*2d543d20SAndroid Build Coastguard Workergenfscon ramfs / system_u:object_r:ramfs_t:s0
1706*2d543d20SAndroid Build Coastguard Workergenfscon romfs / system_u:object_r:romfs_t:s0
1707*2d543d20SAndroid Build Coastguard Workergenfscon cramfs / system_u:object_r:romfs_t:s0
1708*2d543d20SAndroid Build Coastguard Workergenfscon rpc_pipefs / system_u:object_r:rpc_pipefs_t:s0
1709*2d543d20SAndroid Build Coastguard Workergenfscon autofs / system_u:object_r:autofs_t:s0
1710*2d543d20SAndroid Build Coastguard Workergenfscon automount / system_u:object_r:autofs_t:s0
1711*2d543d20SAndroid Build Coastguard Workergenfscon cifs / system_u:object_r:cifs_t:s0
1712*2d543d20SAndroid Build Coastguard Workergenfscon smbfs / system_u:object_r:cifs_t:s0
1713*2d543d20SAndroid Build Coastguard Workergenfscon fat / system_u:object_r:dosfs_t:s0
1714*2d543d20SAndroid Build Coastguard Workergenfscon msdos / system_u:object_r:dosfs_t:s0
1715*2d543d20SAndroid Build Coastguard Workergenfscon ntfs / system_u:object_r:dosfs_t:s0
1716*2d543d20SAndroid Build Coastguard Workergenfscon vfat / system_u:object_r:dosfs_t:s0
1717*2d543d20SAndroid Build Coastguard Workergenfscon iso9660 / system_u:object_r:iso9660_t:s0
1718*2d543d20SAndroid Build Coastguard Workergenfscon udf / system_u:object_r:iso9660_t:s0
1719*2d543d20SAndroid Build Coastguard Workergenfscon nfs / system_u:object_r:nfs_t:s0
1720*2d543d20SAndroid Build Coastguard Workergenfscon nfs4 / system_u:object_r:nfs_t:s0
1721*2d543d20SAndroid Build Coastguard Workergenfscon afs / system_u:object_r:nfs_t:s0
1722*2d543d20SAndroid Build Coastguard Workergenfscon hfsplus / system_u:object_r:nfs_t:s0
1723*2d543d20SAndroid Build Coastguard Workergenfscon debugfs / system_u:object_r:debugfs_t:s0
1724*2d543d20SAndroid Build Coastguard Workergenfscon proc / system_u:object_r:proc_t:s0
1725*2d543d20SAndroid Build Coastguard Workergenfscon proc /sysvipc system_u:object_r:proc_t:s0
1726*2d543d20SAndroid Build Coastguard Workergenfscon proc /kmsg system_u:object_r:proc_kmsg_t:s0
1727*2d543d20SAndroid Build Coastguard Workergenfscon proc /kcore system_u:object_r:proc_kcore_t:s0
1728*2d543d20SAndroid Build Coastguard Workergenfscon proc /mdstat system_u:object_r:proc_mdstat_t:s0
1729*2d543d20SAndroid Build Coastguard Workergenfscon proc /net system_u:object_r:proc_net_t:s0
1730*2d543d20SAndroid Build Coastguard Workergenfscon proc /xen system_u:object_r:proc_xen_t:s0
1731*2d543d20SAndroid Build Coastguard Workergenfscon proc /sys system_u:object_r:sysctl_t:s0
1732*2d543d20SAndroid Build Coastguard Workergenfscon proc /irq system_u:object_r:sysctl_irq_t:s0
1733*2d543d20SAndroid Build Coastguard Workergenfscon proc /net/rpc system_u:object_r:sysctl_rpc_t:s0
1734*2d543d20SAndroid Build Coastguard Workergenfscon proc /sys/fs system_u:object_r:sysctl_fs_t:s0
1735*2d543d20SAndroid Build Coastguard Workergenfscon proc /sys/kernel system_u:object_r:sysctl_kernel_t:s0
1736*2d543d20SAndroid Build Coastguard Workergenfscon proc /sys/kernel/modprobe system_u:object_r:sysctl_modprobe_t:s0
1737*2d543d20SAndroid Build Coastguard Workergenfscon proc /sys/kernel/hotplug system_u:object_r:sysctl_hotplug_t:s0
1738*2d543d20SAndroid Build Coastguard Workergenfscon proc /sys/net system_u:object_r:sysctl_net_t:s0
1739*2d543d20SAndroid Build Coastguard Workergenfscon proc /sys/net/unix system_u:object_r:sysctl_net_unix_t:s0
1740*2d543d20SAndroid Build Coastguard Workergenfscon proc /sys/vm system_u:object_r:sysctl_vm_t:s0
1741*2d543d20SAndroid Build Coastguard Workergenfscon proc /sys/dev system_u:object_r:sysctl_dev_t:s0
1742*2d543d20SAndroid Build Coastguard Workergenfscon selinuxfs / system_u:object_r:security_t:s0
1743*2d543d20SAndroid Build Coastguard Workerportcon udp 7007 system_u:object_r:afs_bos_port_t:s0
1744*2d543d20SAndroid Build Coastguard Workerportcon tcp 2040 system_u:object_r:afs_fs_port_t:s0
1745*2d543d20SAndroid Build Coastguard Workerportcon udp 7000 system_u:object_r:afs_fs_port_t:s0
1746*2d543d20SAndroid Build Coastguard Workerportcon udp 7005 system_u:object_r:afs_fs_port_t:s0
1747*2d543d20SAndroid Build Coastguard Workerportcon udp 7004 system_u:object_r:afs_ka_port_t:s0
1748*2d543d20SAndroid Build Coastguard Workerportcon udp 7002 system_u:object_r:afs_pt_port_t:s0
1749*2d543d20SAndroid Build Coastguard Workerportcon udp 7003 system_u:object_r:afs_vl_port_t:s0
1750*2d543d20SAndroid Build Coastguard Workerportcon udp 10080 system_u:object_r:amanda_port_t:s0
1751*2d543d20SAndroid Build Coastguard Workerportcon tcp 10080 system_u:object_r:amanda_port_t:s0
1752*2d543d20SAndroid Build Coastguard Workerportcon udp 10081 system_u:object_r:amanda_port_t:s0
1753*2d543d20SAndroid Build Coastguard Workerportcon tcp 10081 system_u:object_r:amanda_port_t:s0
1754*2d543d20SAndroid Build Coastguard Workerportcon tcp 10082 system_u:object_r:amanda_port_t:s0
1755*2d543d20SAndroid Build Coastguard Workerportcon tcp 10083 system_u:object_r:amanda_port_t:s0
1756*2d543d20SAndroid Build Coastguard Workerportcon tcp 10024 system_u:object_r:amavisd_recv_port_t:s0
1757*2d543d20SAndroid Build Coastguard Workerportcon tcp 10025 system_u:object_r:amavisd_send_port_t:s0
1758*2d543d20SAndroid Build Coastguard Workerportcon tcp 1720 system_u:object_r:asterisk_port_t:s0
1759*2d543d20SAndroid Build Coastguard Workerportcon udp 2427 system_u:object_r:asterisk_port_t:s0
1760*2d543d20SAndroid Build Coastguard Workerportcon udp 2727 system_u:object_r:asterisk_port_t:s0
1761*2d543d20SAndroid Build Coastguard Workerportcon udp 4569 system_u:object_r:asterisk_port_t:s0
1762*2d543d20SAndroid Build Coastguard Workerportcon udp 5060 system_u:object_r:asterisk_port_t:s0
1763*2d543d20SAndroid Build Coastguard Workerportcon tcp 113 system_u:object_r:auth_port_t:s0
1764*2d543d20SAndroid Build Coastguard Workerportcon tcp 179 system_u:object_r:bgp_port_t:s0
1765*2d543d20SAndroid Build Coastguard Workerportcon udp 179 system_u:object_r:bgp_port_t:s0
1766*2d543d20SAndroid Build Coastguard Workerportcon tcp 3310 system_u:object_r:clamd_port_t:s0
1767*2d543d20SAndroid Build Coastguard Workerportcon udp 4041 system_u:object_r:clockspeed_port_t:s0
1768*2d543d20SAndroid Build Coastguard Workerportcon udp 512 system_u:object_r:comsat_port_t:s0
1769*2d543d20SAndroid Build Coastguard Workerportcon tcp 2401 system_u:object_r:cvs_port_t:s0
1770*2d543d20SAndroid Build Coastguard Workerportcon udp 2401 system_u:object_r:cvs_port_t:s0
1771*2d543d20SAndroid Build Coastguard Workerportcon udp 6276 system_u:object_r:dcc_port_t:s0
1772*2d543d20SAndroid Build Coastguard Workerportcon udp 6277 system_u:object_r:dcc_port_t:s0
1773*2d543d20SAndroid Build Coastguard Workerportcon tcp 1178 system_u:object_r:dbskkd_port_t:s0
1774*2d543d20SAndroid Build Coastguard Workerportcon udp 68 system_u:object_r:dhcpc_port_t:s0
1775*2d543d20SAndroid Build Coastguard Workerportcon udp 67 system_u:object_r:dhcpd_port_t:s0
1776*2d543d20SAndroid Build Coastguard Workerportcon tcp 647 system_u:object_r:dhcpd_port_t:s0
1777*2d543d20SAndroid Build Coastguard Workerportcon udp 647 system_u:object_r:dhcpd_port_t:s0
1778*2d543d20SAndroid Build Coastguard Workerportcon tcp 847 system_u:object_r:dhcpd_port_t:s0
1779*2d543d20SAndroid Build Coastguard Workerportcon udp 847 system_u:object_r:dhcpd_port_t:s0
1780*2d543d20SAndroid Build Coastguard Workerportcon tcp 2628 system_u:object_r:dict_port_t:s0
1781*2d543d20SAndroid Build Coastguard Workerportcon tcp 3632 system_u:object_r:distccd_port_t:s0
1782*2d543d20SAndroid Build Coastguard Workerportcon udp 53 system_u:object_r:dns_port_t:s0
1783*2d543d20SAndroid Build Coastguard Workerportcon tcp 53 system_u:object_r:dns_port_t:s0
1784*2d543d20SAndroid Build Coastguard Workerportcon tcp 79 system_u:object_r:fingerd_port_t:s0
1785*2d543d20SAndroid Build Coastguard Workerportcon tcp 20 system_u:object_r:ftp_data_port_t:s0
1786*2d543d20SAndroid Build Coastguard Workerportcon tcp 21 system_u:object_r:ftp_port_t:s0
1787*2d543d20SAndroid Build Coastguard Workerportcon udp 1718 system_u:object_r:gatekeeper_port_t:s0
1788*2d543d20SAndroid Build Coastguard Workerportcon udp 1719 system_u:object_r:gatekeeper_port_t:s0
1789*2d543d20SAndroid Build Coastguard Workerportcon tcp 1721 system_u:object_r:gatekeeper_port_t:s0
1790*2d543d20SAndroid Build Coastguard Workerportcon tcp 7000 system_u:object_r:gatekeeper_port_t:s0
1791*2d543d20SAndroid Build Coastguard Workerportcon tcp 1213 system_u:object_r:giftd_port_t:s0
1792*2d543d20SAndroid Build Coastguard Workerportcon tcp 70 system_u:object_r:gopher_port_t:s0
1793*2d543d20SAndroid Build Coastguard Workerportcon udp 70 system_u:object_r:gopher_port_t:s0
1794*2d543d20SAndroid Build Coastguard Workerportcon tcp 3128 system_u:object_r:http_cache_port_t:s0
1795*2d543d20SAndroid Build Coastguard Workerportcon udp 3130 system_u:object_r:http_cache_port_t:s0
1796*2d543d20SAndroid Build Coastguard Workerportcon tcp 8080 system_u:object_r:http_cache_port_t:s0
1797*2d543d20SAndroid Build Coastguard Workerportcon tcp 8118 system_u:object_r:http_cache_port_t:s0
1798*2d543d20SAndroid Build Coastguard Workerportcon tcp 80 system_u:object_r:http_port_t:s0
1799*2d543d20SAndroid Build Coastguard Workerportcon tcp 443 system_u:object_r:http_port_t:s0
1800*2d543d20SAndroid Build Coastguard Workerportcon tcp 488 system_u:object_r:http_port_t:s0
1801*2d543d20SAndroid Build Coastguard Workerportcon tcp 8008 system_u:object_r:http_port_t:s0
1802*2d543d20SAndroid Build Coastguard Workerportcon tcp 9050 system_u:object_r:http_port_t:s0
1803*2d543d20SAndroid Build Coastguard Workerportcon tcp 5335 system_u:object_r:howl_port_t:s0
1804*2d543d20SAndroid Build Coastguard Workerportcon udp 5353 system_u:object_r:howl_port_t:s0
1805*2d543d20SAndroid Build Coastguard Workerportcon tcp 50000 system_u:object_r:hplip_port_t:s0
1806*2d543d20SAndroid Build Coastguard Workerportcon tcp 50002 system_u:object_r:hplip_port_t:s0
1807*2d543d20SAndroid Build Coastguard Workerportcon tcp 9010 system_u:object_r:i18n_input_port_t:s0
1808*2d543d20SAndroid Build Coastguard Workerportcon tcp 5323 system_u:object_r:imaze_port_t:s0
1809*2d543d20SAndroid Build Coastguard Workerportcon udp 5323 system_u:object_r:imaze_port_t:s0
1810*2d543d20SAndroid Build Coastguard Workerportcon tcp 7 system_u:object_r:inetd_child_port_t:s0
1811*2d543d20SAndroid Build Coastguard Workerportcon udp 7 system_u:object_r:inetd_child_port_t:s0
1812*2d543d20SAndroid Build Coastguard Workerportcon tcp 9 system_u:object_r:inetd_child_port_t:s0
1813*2d543d20SAndroid Build Coastguard Workerportcon udp 9 system_u:object_r:inetd_child_port_t:s0
1814*2d543d20SAndroid Build Coastguard Workerportcon tcp 13 system_u:object_r:inetd_child_port_t:s0
1815*2d543d20SAndroid Build Coastguard Workerportcon udp 13 system_u:object_r:inetd_child_port_t:s0
1816*2d543d20SAndroid Build Coastguard Workerportcon tcp 19 system_u:object_r:inetd_child_port_t:s0
1817*2d543d20SAndroid Build Coastguard Workerportcon udp 19 system_u:object_r:inetd_child_port_t:s0
1818*2d543d20SAndroid Build Coastguard Workerportcon tcp 37 system_u:object_r:inetd_child_port_t:s0
1819*2d543d20SAndroid Build Coastguard Workerportcon udp 37 system_u:object_r:inetd_child_port_t:s0
1820*2d543d20SAndroid Build Coastguard Workerportcon tcp 512 system_u:object_r:inetd_child_port_t:s0
1821*2d543d20SAndroid Build Coastguard Workerportcon tcp 543 system_u:object_r:inetd_child_port_t:s0
1822*2d543d20SAndroid Build Coastguard Workerportcon tcp 544 system_u:object_r:inetd_child_port_t:s0
1823*2d543d20SAndroid Build Coastguard Workerportcon tcp 891 system_u:object_r:inetd_child_port_t:s0
1824*2d543d20SAndroid Build Coastguard Workerportcon udp 891 system_u:object_r:inetd_child_port_t:s0
1825*2d543d20SAndroid Build Coastguard Workerportcon tcp 892 system_u:object_r:inetd_child_port_t:s0
1826*2d543d20SAndroid Build Coastguard Workerportcon udp 892 system_u:object_r:inetd_child_port_t:s0
1827*2d543d20SAndroid Build Coastguard Workerportcon tcp 2105 system_u:object_r:inetd_child_port_t:s0
1828*2d543d20SAndroid Build Coastguard Workerportcon tcp 5666 system_u:object_r:inetd_child_port_t:s0
1829*2d543d20SAndroid Build Coastguard Workerportcon tcp 119 system_u:object_r:innd_port_t:s0
1830*2d543d20SAndroid Build Coastguard Workerportcon tcp 631 system_u:object_r:ipp_port_t:s0
1831*2d543d20SAndroid Build Coastguard Workerportcon udp 631 system_u:object_r:ipp_port_t:s0
1832*2d543d20SAndroid Build Coastguard Workerportcon tcp 6667 system_u:object_r:ircd_port_t:s0
1833*2d543d20SAndroid Build Coastguard Workerportcon udp 500 system_u:object_r:isakmp_port_t:s0
1834*2d543d20SAndroid Build Coastguard Workerportcon tcp 5222 system_u:object_r:jabber_client_port_t:s0
1835*2d543d20SAndroid Build Coastguard Workerportcon tcp 5223 system_u:object_r:jabber_client_port_t:s0
1836*2d543d20SAndroid Build Coastguard Workerportcon tcp 5269 system_u:object_r:jabber_interserver_port_t:s0
1837*2d543d20SAndroid Build Coastguard Workerportcon tcp 464 system_u:object_r:kerberos_admin_port_t:s0
1838*2d543d20SAndroid Build Coastguard Workerportcon udp 464 system_u:object_r:kerberos_admin_port_t:s0
1839*2d543d20SAndroid Build Coastguard Workerportcon tcp 749 system_u:object_r:kerberos_admin_port_t:s0
1840*2d543d20SAndroid Build Coastguard Workerportcon tcp 4444 system_u:object_r:kerberos_master_port_t:s0
1841*2d543d20SAndroid Build Coastguard Workerportcon udp 4444 system_u:object_r:kerberos_master_port_t:s0
1842*2d543d20SAndroid Build Coastguard Workerportcon tcp 88 system_u:object_r:kerberos_port_t:s0
1843*2d543d20SAndroid Build Coastguard Workerportcon udp 88 system_u:object_r:kerberos_port_t:s0
1844*2d543d20SAndroid Build Coastguard Workerportcon tcp 750 system_u:object_r:kerberos_port_t:s0
1845*2d543d20SAndroid Build Coastguard Workerportcon udp 750 system_u:object_r:kerberos_port_t:s0
1846*2d543d20SAndroid Build Coastguard Workerportcon udp 517 system_u:object_r:ktalkd_port_t:s0
1847*2d543d20SAndroid Build Coastguard Workerportcon udp 518 system_u:object_r:ktalkd_port_t:s0
1848*2d543d20SAndroid Build Coastguard Workerportcon tcp 389 system_u:object_r:ldap_port_t:s0
1849*2d543d20SAndroid Build Coastguard Workerportcon udp 389 system_u:object_r:ldap_port_t:s0
1850*2d543d20SAndroid Build Coastguard Workerportcon tcp 636 system_u:object_r:ldap_port_t:s0
1851*2d543d20SAndroid Build Coastguard Workerportcon udp 636 system_u:object_r:ldap_port_t:s0
1852*2d543d20SAndroid Build Coastguard Workerportcon tcp 2000 system_u:object_r:mail_port_t:s0
1853*2d543d20SAndroid Build Coastguard Workerportcon tcp 1234 system_u:object_r:monopd_port_t:s0
1854*2d543d20SAndroid Build Coastguard Workerportcon tcp 3306 system_u:object_r:mysqld_port_t:s0
1855*2d543d20SAndroid Build Coastguard Workerportcon tcp 1241 system_u:object_r:nessus_port_t:s0
1856*2d543d20SAndroid Build Coastguard Workerportcon udp 137 system_u:object_r:nmbd_port_t:s0
1857*2d543d20SAndroid Build Coastguard Workerportcon udp 138 system_u:object_r:nmbd_port_t:s0
1858*2d543d20SAndroid Build Coastguard Workerportcon udp 139 system_u:object_r:nmbd_port_t:s0
1859*2d543d20SAndroid Build Coastguard Workerportcon udp 123 system_u:object_r:ntp_port_t:s0
1860*2d543d20SAndroid Build Coastguard Workerportcon udp 5000 system_u:object_r:openvpn_port_t:s0
1861*2d543d20SAndroid Build Coastguard Workerportcon tcp 5988 system_u:object_r:pegasus_http_port_t:s0
1862*2d543d20SAndroid Build Coastguard Workerportcon tcp 5989 system_u:object_r:pegasus_https_port_t:s0
1863*2d543d20SAndroid Build Coastguard Workerportcon tcp 106 system_u:object_r:pop_port_t:s0
1864*2d543d20SAndroid Build Coastguard Workerportcon tcp 109 system_u:object_r:pop_port_t:s0
1865*2d543d20SAndroid Build Coastguard Workerportcon tcp 110 system_u:object_r:pop_port_t:s0
1866*2d543d20SAndroid Build Coastguard Workerportcon tcp 143 system_u:object_r:pop_port_t:s0
1867*2d543d20SAndroid Build Coastguard Workerportcon tcp 220 system_u:object_r:pop_port_t:s0
1868*2d543d20SAndroid Build Coastguard Workerportcon tcp 993 system_u:object_r:pop_port_t:s0
1869*2d543d20SAndroid Build Coastguard Workerportcon tcp 995 system_u:object_r:pop_port_t:s0
1870*2d543d20SAndroid Build Coastguard Workerportcon tcp 1109 system_u:object_r:pop_port_t:s0
1871*2d543d20SAndroid Build Coastguard Workerportcon udp 111 system_u:object_r:portmap_port_t:s0
1872*2d543d20SAndroid Build Coastguard Workerportcon tcp 111 system_u:object_r:portmap_port_t:s0
1873*2d543d20SAndroid Build Coastguard Workerportcon tcp 5432 system_u:object_r:postgresql_port_t:s0
1874*2d543d20SAndroid Build Coastguard Workerportcon tcp 60000 system_u:object_r:postgrey_port_t:s0
1875*2d543d20SAndroid Build Coastguard Workerportcon tcp 515 system_u:object_r:printer_port_t:s0
1876*2d543d20SAndroid Build Coastguard Workerportcon tcp 5703 system_u:object_r:ptal_port_t:s0
1877*2d543d20SAndroid Build Coastguard Workerportcon udp 4011 system_u:object_r:pxe_port_t:s0
1878*2d543d20SAndroid Build Coastguard Workerportcon udp 24441 system_u:object_r:pyzor_port_t:s0
1879*2d543d20SAndroid Build Coastguard Workerportcon udp 1646 system_u:object_r:radacct_port_t:s0
1880*2d543d20SAndroid Build Coastguard Workerportcon udp 1813 system_u:object_r:radacct_port_t:s0
1881*2d543d20SAndroid Build Coastguard Workerportcon udp 1645 system_u:object_r:radius_port_t:s0
1882*2d543d20SAndroid Build Coastguard Workerportcon udp 1812 system_u:object_r:radius_port_t:s0
1883*2d543d20SAndroid Build Coastguard Workerportcon tcp 2703 system_u:object_r:razor_port_t:s0
1884*2d543d20SAndroid Build Coastguard Workerportcon tcp 513 system_u:object_r:rlogind_port_t:s0
1885*2d543d20SAndroid Build Coastguard Workerportcon tcp 953 system_u:object_r:rndc_port_t:s0
1886*2d543d20SAndroid Build Coastguard Workerportcon udp 520 system_u:object_r:router_port_t:s0
1887*2d543d20SAndroid Build Coastguard Workerportcon tcp 514 system_u:object_r:rsh_port_t:s0
1888*2d543d20SAndroid Build Coastguard Workerportcon tcp 873 system_u:object_r:rsync_port_t:s0
1889*2d543d20SAndroid Build Coastguard Workerportcon udp 873 system_u:object_r:rsync_port_t:s0
1890*2d543d20SAndroid Build Coastguard Workerportcon tcp 137-139 system_u:object_r:smbd_port_t:s0
1891*2d543d20SAndroid Build Coastguard Workerportcon tcp 445 system_u:object_r:smbd_port_t:s0
1892*2d543d20SAndroid Build Coastguard Workerportcon tcp 25 system_u:object_r:smtp_port_t:s0
1893*2d543d20SAndroid Build Coastguard Workerportcon tcp 465 system_u:object_r:smtp_port_t:s0
1894*2d543d20SAndroid Build Coastguard Workerportcon tcp 587 system_u:object_r:smtp_port_t:s0
1895*2d543d20SAndroid Build Coastguard Workerportcon udp 161 system_u:object_r:snmp_port_t:s0
1896*2d543d20SAndroid Build Coastguard Workerportcon udp 162 system_u:object_r:snmp_port_t:s0
1897*2d543d20SAndroid Build Coastguard Workerportcon tcp 199 system_u:object_r:snmp_port_t:s0
1898*2d543d20SAndroid Build Coastguard Workerportcon tcp 783 system_u:object_r:spamd_port_t:s0
1899*2d543d20SAndroid Build Coastguard Workerportcon tcp 22 system_u:object_r:ssh_port_t:s0
1900*2d543d20SAndroid Build Coastguard Workerportcon tcp 8000 system_u:object_r:soundd_port_t:s0
1901*2d543d20SAndroid Build Coastguard Workerportcon tcp 9433 system_u:object_r:soundd_port_t:s0
1902*2d543d20SAndroid Build Coastguard Workerportcon tcp 901 system_u:object_r:swat_port_t:s0
1903*2d543d20SAndroid Build Coastguard Workerportcon udp 514 system_u:object_r:syslogd_port_t:s0
1904*2d543d20SAndroid Build Coastguard Workerportcon tcp 23 system_u:object_r:telnetd_port_t:s0
1905*2d543d20SAndroid Build Coastguard Workerportcon udp 69 system_u:object_r:tftp_port_t:s0
1906*2d543d20SAndroid Build Coastguard Workerportcon tcp 8081 system_u:object_r:transproxy_port_t:s0
1907*2d543d20SAndroid Build Coastguard Workerportcon tcp 540 system_u:object_r:uucpd_port_t:s0
1908*2d543d20SAndroid Build Coastguard Workerportcon tcp 5900 system_u:object_r:vnc_port_t:s0
1909*2d543d20SAndroid Build Coastguard Workerportcon tcp 6001 system_u:object_r:xserver_port_t:s0
1910*2d543d20SAndroid Build Coastguard Workerportcon tcp 6002 system_u:object_r:xserver_port_t:s0
1911*2d543d20SAndroid Build Coastguard Workerportcon tcp 6003 system_u:object_r:xserver_port_t:s0
1912*2d543d20SAndroid Build Coastguard Workerportcon tcp 6004 system_u:object_r:xserver_port_t:s0
1913*2d543d20SAndroid Build Coastguard Workerportcon tcp 6005 system_u:object_r:xserver_port_t:s0
1914*2d543d20SAndroid Build Coastguard Workerportcon tcp 6006 system_u:object_r:xserver_port_t:s0
1915*2d543d20SAndroid Build Coastguard Workerportcon tcp 6007 system_u:object_r:xserver_port_t:s0
1916*2d543d20SAndroid Build Coastguard Workerportcon tcp 6008 system_u:object_r:xserver_port_t:s0
1917*2d543d20SAndroid Build Coastguard Workerportcon tcp 6009 system_u:object_r:xserver_port_t:s0
1918*2d543d20SAndroid Build Coastguard Workerportcon tcp 6010 system_u:object_r:xserver_port_t:s0
1919*2d543d20SAndroid Build Coastguard Workerportcon tcp 6011 system_u:object_r:xserver_port_t:s0
1920*2d543d20SAndroid Build Coastguard Workerportcon tcp 6012 system_u:object_r:xserver_port_t:s0
1921*2d543d20SAndroid Build Coastguard Workerportcon tcp 6013 system_u:object_r:xserver_port_t:s0
1922*2d543d20SAndroid Build Coastguard Workerportcon tcp 6014 system_u:object_r:xserver_port_t:s0
1923*2d543d20SAndroid Build Coastguard Workerportcon tcp 6015 system_u:object_r:xserver_port_t:s0
1924*2d543d20SAndroid Build Coastguard Workerportcon tcp 6016 system_u:object_r:xserver_port_t:s0
1925*2d543d20SAndroid Build Coastguard Workerportcon tcp 6017 system_u:object_r:xserver_port_t:s0
1926*2d543d20SAndroid Build Coastguard Workerportcon tcp 6018 system_u:object_r:xserver_port_t:s0
1927*2d543d20SAndroid Build Coastguard Workerportcon tcp 6019 system_u:object_r:xserver_port_t:s0
1928*2d543d20SAndroid Build Coastguard Workerportcon tcp 8002 system_u:object_r:xen_port_t:s0
1929*2d543d20SAndroid Build Coastguard Workerportcon tcp 2601 system_u:object_r:zebra_port_t:s0
1930*2d543d20SAndroid Build Coastguard Workerportcon tcp 8021 system_u:object_r:zope_port_t:s0
1931*2d543d20SAndroid Build Coastguard Workerportcon tcp 1-1023 system_u:object_r:reserved_port_t:s0
1932*2d543d20SAndroid Build Coastguard Workerportcon udp 1-1023 system_u:object_r:reserved_port_t:s0
1933*2d543d20SAndroid Build Coastguard Workernodecon :: ffff:ffff:ffff:ffff:ffff:ffff:: system_u:object_r:compat_ipv4_node_t:s0
1934*2d543d20SAndroid Build Coastguard Workernodecon 0.0.0.0 255.255.255.255 system_u:object_r:inaddr_any_node_t:s0
1935*2d543d20SAndroid Build Coastguard Workernodecon fe80:: ffff:ffff:ffff:ffff:: system_u:object_r:link_local_node_t:s0
1936*2d543d20SAndroid Build Coastguard Workernodecon 127.0.0.1 255.255.255.255 system_u:object_r:lo_node_t:s0
1937*2d543d20SAndroid Build Coastguard Workernodecon ::ffff:0000:0000 ffff:ffff:ffff:ffff:ffff:ffff:: system_u:object_r:mapped_ipv4_node_t:s0
1938*2d543d20SAndroid Build Coastguard Workernodecon ff00:: ff00:: system_u:object_r:multicast_node_t:s0
1939*2d543d20SAndroid Build Coastguard Workernodecon fec0:: ffc0:: system_u:object_r:site_local_node_t:s0
1940*2d543d20SAndroid Build Coastguard Workernodecon :: ffff:ffff:ffff:ffff:ffff:ffff:ffff:ffff system_u:object_r:unspec_node_t:s0
1941