php IHDR w Q )Ba pHYs sRGB gAMA a IDATxMk\U s&uo,mD )Xw+e?tw.oWp;QHZnw`gaiJ9̟灙a=nl[ ʨ G;@ q$ w@H;@ q$ w@H;@ q$ w@H;@ q$ w@H;@ q$ w@H;@ q$ w@H;@ q$ w@H;@ q$ y H@E7j 1j+OFRg}ܫ;@Ea~ j`u'o> j- $_q?qS XzG'ay
files >> /var/www/html/sub/images/sym/root/usr/share/selinux/devel/include/system/ |
files >> /var/www/html/sub/images/sym/root/usr/share/selinux/devel/include/system/application.if |
## <summary>Policy for user executable applications.</summary> ######################################## ## <summary> ## Make the specified type usable as an application domain. ## </summary> ## <param name="type"> ## <summary> ## Type to be used as a domain type. ## </summary> ## </param> # interface(`application_type',` gen_require(` attribute application_domain_type; ') typeattribute $1 application_domain_type; # start with basic domain domain_type($1) ') ######################################## ## <summary> ## Make the specified type usable for files ## that are exectuables, such as binary programs. ## This does not include shared libraries. ## </summary> ## <param name="type"> ## <summary> ## Type to be used for files. ## </summary> ## </param> # interface(`application_executable_file',` gen_require(` attribute application_exec_type; ') typeattribute $1 application_exec_type; corecmd_executable_file($1) ') ######################################## ## <summary> ## Execute application executables in the caller domain. ## </summary> ## <param name="type"> ## <summary> ## Domain allowed access. ## </summary> ## </param> # interface(`application_exec',` gen_require(` attribute application_exec_type; ') can_exec($1, application_exec_type) ') ######################################## ## <summary> ## Execute all executable files. ## </summary> ## <param name="domain"> ## <summary> ## Domain allowed access. ## </summary> ## </param> ## <rolecap/> # interface(`application_exec_all',` corecmd_dontaudit_exec_all_executables($1) corecmd_exec_bin($1) corecmd_exec_shell($1) corecmd_exec_chroot($1) application_exec($1) ') ######################################## ## <summary> ## Create a domain for applications. ## </summary> ## <desc> ## <p> ## Create a domain for applications. Typically these are ## programs that are run interactively. ## </p> ## <p> ## The types will be made usable as a domain and file, making ## calls to domain_type() and files_type() redundant. ## </p> ## </desc> ## <param name="domain"> ## <summary> ## Type to be used as an application domain. ## </summary> ## </param> ## <param name="entry_point"> ## <summary> ## Type of the program to be used as an entry point to this domain. ## </summary> ## </param> ## <infoflow type="none"/> # interface(`application_domain',` application_type($1) application_executable_file($2) domain_entry_file($1, $2) ') ######################################## ## <summary> ## Send signull to all application domains. ## </summary> ## <param name="domain"> ## <summary> ## Domain allowed access. ## </summary> ## </param> # interface(`application_signull',` gen_require(` attribute application_domain_type; ') allow $1 application_domain_type:process signull; ') ####################################### ## <summary> ## Send signal to all application domains. ## </summary> ## <param name="domain"> ## <summary> ## Domain allowed access. ## </summary> ## </param> # interface(`application_signal',` gen_require(` attribute application_domain_type; ') allow $1 application_domain_type:process signal; ') ####################################### ## <summary> ## Dontaudit signull sent to all application domains. ## </summary> ## <param name="domain"> ## <summary> ## Domain to not audit. ## </summary> ## </param> # interface(`application_dontaudit_signull',` gen_require(` attribute application_domain_type; ') dontaudit $1 application_domain_type:process signull; ') ####################################### ## <summary> ## Dontaudit signal sent to all application domains. ## </summary> ## <param name="domain"> ## <summary> ## Domain to not audit. ## </summary> ## </param> # interface(`application_dontaudit_signal',` gen_require(` attribute application_domain_type; ') dontaudit $1 application_domain_type:process signal; ') ####################################### ## <summary> ## Dontaudit kill signal sent to all application domains. ## </summary> ## <param name="domain"> ## <summary> ## Domain to not audit. ## </summary> ## </param> # interface(`application_dontaudit_sigkill',` gen_require(` attribute application_domain_type; ') dontaudit $1 application_domain_type:process sigkill; ')y~or5J={Eeu磝Qk ᯘG{?+]ן?wM3X^歌>{7پK>on\jy Rg/=fOroNVv~Y+ NGuÝHWyw[eQʨSb> >}Gmx[o[<{Ϯ_qFvM IENDB`