diff options
author | John Turner <jturner.usa@gmail.com> | 2025-08-16 14:43:06 -0400 |
---|---|---|
committer | John Turner <jturner.usa@gmail.com> | 2025-08-16 14:43:06 -0400 |
commit | 58ffeaf9b49e662e49d24a2d71dcdc9fac2949f8 (patch) | |
tree | 84c645e32aac8eb468f41df33fbac7b0a8584887 /src/fs | |
parent | cfd55472db08f37b2123c350ce76fb3d916d25f6 (diff) | |
download | selinux-policy-58ffeaf9b49e662e49d24a2d71dcdc9fac2949f8.tar.gz |
auto format all files
Diffstat (limited to 'src/fs')
43 files changed, 251 insertions, 251 deletions
diff --git a/src/fs/noseclabelfs.cil b/src/fs/noseclabelfs.cil index 66a75c1..80cf86d 100644 --- a/src/fs/noseclabelfs.cil +++ b/src/fs/noseclabelfs.cil @@ -1,37 +1,37 @@ -;; SPDX-FileCopyrightText: © 2025 Dominick Grift <dominick.grift@defensec.nl> +;; SPDX-FileCopyrightText: M-BM-) 2025 Dominick Grift <dominick.grift@defensec.nl> ;; SPDX-License-Identifier: Unlicense (block noseclabelfs - (macro type ((type ARG1)) - (typeattributeset typeattr ARG1)) + (macro type ((type ARG1)) + (typeattributeset typeattr ARG1)) - (typeattribute typeattr) + (typeattribute typeattr) - (blockinherit .file.all_macro_template_dirs) - (blockinherit .file.all_macro_template_fifo_files) - (blockinherit .file.all_macro_template_files) - (blockinherit .file.all_macro_template_lnk_files) - (blockinherit .file.all_macro_template_sock_files) - (blockinherit .fs.all_macro_template_fs) + (blockinherit .file.all_macro_template_dirs) + (blockinherit .file.all_macro_template_fifo_files) + (blockinherit .file.all_macro_template_files) + (blockinherit .file.all_macro_template_lnk_files) + (blockinherit .file.all_macro_template_sock_files) + (blockinherit .fs.all_macro_template_fs) - (allow typeattr self (filesystem (associate))) + (allow typeattr self (filesystem (associate))) - (call .fs.type (typeattr)) + (call .fs.type (typeattr)) - (block base_template + (block base_template - (blockabstract base_template) + (blockabstract base_template) - (blockinherit .fs.base_template) + (blockinherit .fs.base_template) - (call .noseclabelfs.type (fs))) + (call .noseclabelfs.type (fs))) - (block template + (block template - (blockabstract template) + (blockabstract template) - (blockinherit .fs.macro_template_dirs) - (blockinherit .fs.macro_template_files) - (blockinherit .fs.macro_template_fs) - (blockinherit .noseclabelfs.base_template))) + (blockinherit .fs.macro_template_dirs) + (blockinherit .fs.macro_template_files) + (blockinherit .fs.macro_template_fs) + (blockinherit .noseclabelfs.base_template))) diff --git a/src/fs/noseclabelfs/aionoseclabelfs.cil b/src/fs/noseclabelfs/aionoseclabelfs.cil index 48d59b7..e1b3f92 100644 --- a/src/fs/noseclabelfs/aionoseclabelfs.cil +++ b/src/fs/noseclabelfs/aionoseclabelfs.cil @@ -1,9 +1,9 @@ -;; SPDX-FileCopyrightText: © 2025 Dominick Grift <dominick.grift@defensec.nl> +;; SPDX-FileCopyrightText: M-BM-) 2025 Dominick Grift <dominick.grift@defensec.nl> ;; SPDX-License-Identifier: Unlicense (block aio - (genfscon "aio" "/" fs_context) + (genfscon "aio" "/" fs_context) - (blockinherit .fs.macro_template_fs) - (blockinherit .noseclabelfs.base_template)) + (blockinherit .fs.macro_template_fs) + (blockinherit .noseclabelfs.base_template)) diff --git a/src/fs/noseclabelfs/anoninodenoseclabelfs.cil b/src/fs/noseclabelfs/anoninodenoseclabelfs.cil index d7156a2..a1e8dee 100644 --- a/src/fs/noseclabelfs/anoninodenoseclabelfs.cil +++ b/src/fs/noseclabelfs/anoninodenoseclabelfs.cil @@ -1,8 +1,8 @@ -;; SPDX-FileCopyrightText: © 2025 Dominick Grift <dominick.grift@defensec.nl> +;; SPDX-FileCopyrightText: M-BM-) 2025 Dominick Grift <dominick.grift@defensec.nl> ;; SPDX-License-Identifier: Unlicense (block anoninode - (genfscon "anon_inodefs" "/" fs_context) + (genfscon "anon_inodefs" "/" fs_context) - (blockinherit .noseclabelfs.base_template)) + (blockinherit .noseclabelfs.base_template)) diff --git a/src/fs/noseclabelfs/autonoseclabelfs.cil b/src/fs/noseclabelfs/autonoseclabelfs.cil index 6180533..d22b133 100644 --- a/src/fs/noseclabelfs/autonoseclabelfs.cil +++ b/src/fs/noseclabelfs/autonoseclabelfs.cil @@ -1,14 +1,14 @@ -;; SPDX-FileCopyrightText: © 2025 Dominick Grift <dominick.grift@defensec.nl> +;; SPDX-FileCopyrightText: M-BM-) 2025 Dominick Grift <dominick.grift@defensec.nl> ;; SPDX-License-Identifier: Unlicense (block auto - (genfscon "autofs" "/" fs_context) - (genfscon "automount" "/" fs_context) + (genfscon "autofs" "/" fs_context) + (genfscon "automount" "/" fs_context) - (macro getattr_fs_dirs ((type ARG1)) - (allow ARG1 fs (dir (getattr)))) + (macro getattr_fs_dirs ((type ARG1)) + (allow ARG1 fs (dir (getattr)))) - (blockinherit .fs.macro_template_dirs) - (blockinherit .fs.macro_template_fs) - (blockinherit .noseclabelfs.base_template)) + (blockinherit .fs.macro_template_dirs) + (blockinherit .fs.macro_template_fs) + (blockinherit .noseclabelfs.base_template)) diff --git a/src/fs/noseclabelfs/bdevnoseclabelfs.cil b/src/fs/noseclabelfs/bdevnoseclabelfs.cil index b0a7369..2109eda 100644 --- a/src/fs/noseclabelfs/bdevnoseclabelfs.cil +++ b/src/fs/noseclabelfs/bdevnoseclabelfs.cil @@ -1,9 +1,9 @@ -;; SPDX-FileCopyrightText: © 2025 Dominick Grift <dominick.grift@defensec.nl> +;; SPDX-FileCopyrightText: M-BM-) 2025 Dominick Grift <dominick.grift@defensec.nl> ;; SPDX-License-Identifier: Unlicense (block bdev - (genfscon "bdev" "/" fs_context) + (genfscon "bdev" "/" fs_context) - (blockinherit .fs.macro_template_fs) - (blockinherit .noseclabelfs.base_template)) + (blockinherit .fs.macro_template_fs) + (blockinherit .noseclabelfs.base_template)) diff --git a/src/fs/noseclabelfs/binfmtmiscnoseclabelfs.cil b/src/fs/noseclabelfs/binfmtmiscnoseclabelfs.cil index 0b36870..beaa0e3 100644 --- a/src/fs/noseclabelfs/binfmtmiscnoseclabelfs.cil +++ b/src/fs/noseclabelfs/binfmtmiscnoseclabelfs.cil @@ -1,8 +1,8 @@ -;; SPDX-FileCopyrightText: © 2025 Dominick Grift <dominick.grift@defensec.nl> +;; SPDX-FileCopyrightText: M-BM-) 2025 Dominick Grift <dominick.grift@defensec.nl> ;; SPDX-License-Identifier: Unlicense (block binfmtmisc - (genfscon "binfmt_misc" "/" fs_context) + (genfscon "binfmt_misc" "/" fs_context) - (blockinherit .noseclabelfs.template)) + (blockinherit .noseclabelfs.template)) diff --git a/src/fs/noseclabelfs/bpfnoseclabelfs.cil b/src/fs/noseclabelfs/bpfnoseclabelfs.cil index 6e855ff..99d59dc 100644 --- a/src/fs/noseclabelfs/bpfnoseclabelfs.cil +++ b/src/fs/noseclabelfs/bpfnoseclabelfs.cil @@ -1,4 +1,4 @@ -;; SPDX-FileCopyrightText: © 2025 Dominick Grift <dominick.grift@defensec.nl> +;; SPDX-FileCopyrightText: M-BM-) 2025 Dominick Grift <dominick.grift@defensec.nl> ;; SPDX-License-Identifier: Unlicense (block bpf @@ -7,5 +7,5 @@ (filecon "/sys/fs/bpf/.*" any ()) (genfscon "bpf" "/" fs_context) - + (blockinherit .noseclabelfs.template)) diff --git a/src/fs/noseclabelfs/cinoseclabelfs.cil b/src/fs/noseclabelfs/cinoseclabelfs.cil index a23198b..dbad070 100644 --- a/src/fs/noseclabelfs/cinoseclabelfs.cil +++ b/src/fs/noseclabelfs/cinoseclabelfs.cil @@ -1,14 +1,14 @@ -;; SPDX-FileCopyrightText: © 2025 Dominick Grift <dominick.grift@defensec.nl> +;; SPDX-FileCopyrightText: M-BM-) 2025 Dominick Grift <dominick.grift@defensec.nl> ;; SPDX-License-Identifier: Unlicense (block ci - (genfscon "cifs" "/" fs_context) - (genfscon "smbfs" "/" fs_context) + (genfscon "cifs" "/" fs_context) + (genfscon "smbfs" "/" fs_context) - (macro map_fs_files ((type ARG1)) - (allow ARG1 fs (file (map)))) + (macro map_fs_files ((type ARG1)) + (allow ARG1 fs (file (map)))) - (blockinherit .noseclabelfs.template) + (blockinherit .noseclabelfs.template) - (call .rbacsep.exempt.obj.type (fs))) + (call .rbacsep.exempt.obj.type (fs))) diff --git a/src/fs/noseclabelfs/confignoseclabelfs.cil b/src/fs/noseclabelfs/confignoseclabelfs.cil index 78bf7ea..a0dde62 100644 --- a/src/fs/noseclabelfs/confignoseclabelfs.cil +++ b/src/fs/noseclabelfs/confignoseclabelfs.cil @@ -1,10 +1,10 @@ -;; SPDX-FileCopyrightText: © 2025 Dominick Grift <dominick.grift@defensec.nl> +;; SPDX-FileCopyrightText: M-BM-) 2025 Dominick Grift <dominick.grift@defensec.nl> ;; SPDX-License-Identifier: Unlicense (block config - (genfscon "configfs" "/" fs_context) + (genfscon "configfs" "/" fs_context) - (blockinherit .fs.macro_template_dirs) - (blockinherit .fs.macro_template_fs) - (blockinherit .noseclabelfs.base_template)) + (blockinherit .fs.macro_template_dirs) + (blockinherit .fs.macro_template_fs) + (blockinherit .noseclabelfs.base_template)) diff --git a/src/fs/noseclabelfs/cpusetnoseclabelfs.cil b/src/fs/noseclabelfs/cpusetnoseclabelfs.cil index c241ba8..9e1c1d7 100644 --- a/src/fs/noseclabelfs/cpusetnoseclabelfs.cil +++ b/src/fs/noseclabelfs/cpusetnoseclabelfs.cil @@ -1,9 +1,9 @@ -;; SPDX-FileCopyrightText: © 2025 Dominick Grift <dominick.grift@defensec.nl> +;; SPDX-FileCopyrightText: M-BM-) 2025 Dominick Grift <dominick.grift@defensec.nl> ;; SPDX-License-Identifier: Unlicense (block cpuset - (genfscon "cpuset" "/" fs_context) + (genfscon "cpuset" "/" fs_context) - (blockinherit .fs.macro_template_fs) - (blockinherit .noseclabelfs.base_template)) + (blockinherit .fs.macro_template_fs) + (blockinherit .noseclabelfs.base_template)) diff --git a/src/fs/noseclabelfs/dosnoseclabelfs.cil b/src/fs/noseclabelfs/dosnoseclabelfs.cil index b3e0996..dc1412a 100644 --- a/src/fs/noseclabelfs/dosnoseclabelfs.cil +++ b/src/fs/noseclabelfs/dosnoseclabelfs.cil @@ -1,21 +1,21 @@ -;; SPDX-FileCopyrightText: © 2025 Dominick Grift <dominick.grift@defensec.nl> +;; SPDX-FileCopyrightText: M-BM-) 2025 Dominick Grift <dominick.grift@defensec.nl> ;; SPDX-License-Identifier: Unlicense (block dos - (genfscon "fat" "/" fs_context) - (genfscon "hfs" "/" fs_context) - (genfscon "hfsplus" "/" fs_context) - (genfscon "msdos" "/" fs_context) - (genfscon "ntfs" "/" fs_context) - (genfscon "ntfs-3g" "/" fs_context) - (genfscon "ntfs3" "/" fs_context) - (genfscon "vfat" "/" fs_context) - (genfscon "exfat" "/" fs_context) + (genfscon "fat" "/" fs_context) + (genfscon "hfs" "/" fs_context) + (genfscon "hfsplus" "/" fs_context) + (genfscon "msdos" "/" fs_context) + (genfscon "ntfs" "/" fs_context) + (genfscon "ntfs-3g" "/" fs_context) + (genfscon "ntfs3" "/" fs_context) + (genfscon "vfat" "/" fs_context) + (genfscon "exfat" "/" fs_context) - (macro map_fs_files ((type ARG1)) - (allow ARG1 fs (file (map)))) + (macro map_fs_files ((type ARG1)) + (allow ARG1 fs (file (map)))) - (blockinherit .noseclabelfs.template) + (blockinherit .noseclabelfs.template) - (call .rbacsep.exempt.obj.type (fs))) + (call .rbacsep.exempt.obj.type (fs))) diff --git a/src/fs/noseclabelfs/drmnoseclabelfs.cil b/src/fs/noseclabelfs/drmnoseclabelfs.cil index 8b20c7c..ac6c075 100644 --- a/src/fs/noseclabelfs/drmnoseclabelfs.cil +++ b/src/fs/noseclabelfs/drmnoseclabelfs.cil @@ -1,9 +1,9 @@ -;; SPDX-FileCopyrightText: © 2025 Dominick Grift <dominick.grift@defensec.nl> +;; SPDX-FileCopyrightText: M-BM-) 2025 Dominick Grift <dominick.grift@defensec.nl> ;; SPDX-License-Identifier: Unlicense (block drm - (genfscon "drm" "/" fs_context) + (genfscon "drm" "/" fs_context) - (blockinherit .fs.macro_template_fs) - (blockinherit .noseclabelfs.base_template)) + (blockinherit .fs.macro_template_fs) + (blockinherit .noseclabelfs.base_template)) diff --git a/src/fs/noseclabelfs/efivarnoseclabelfs.cil b/src/fs/noseclabelfs/efivarnoseclabelfs.cil index 2c7d931..7ff8fd2 100644 --- a/src/fs/noseclabelfs/efivarnoseclabelfs.cil +++ b/src/fs/noseclabelfs/efivarnoseclabelfs.cil @@ -1,8 +1,8 @@ -;; SPDX-FileCopyrightText: © 2025 Dominick Grift <dominick.grift@defensec.nl> +;; SPDX-FileCopyrightText: M-BM-) 2025 Dominick Grift <dominick.grift@defensec.nl> ;; SPDX-License-Identifier: Unlicense (block efivar - (genfscon "efivarfs" "/" fs_context) + (genfscon "efivarfs" "/" fs_context) - (blockinherit .noseclabelfs.template)) + (blockinherit .noseclabelfs.template)) diff --git a/src/fs/noseclabelfs/fusenoseclabelfs.cil b/src/fs/noseclabelfs/fusenoseclabelfs.cil index 9ebbbfd..f714975 100644 --- a/src/fs/noseclabelfs/fusenoseclabelfs.cil +++ b/src/fs/noseclabelfs/fusenoseclabelfs.cil @@ -1,4 +1,4 @@ -;; SPDX-FileCopyrightText: © 2025 Dominick Grift <dominick.grift@defensec.nl> +;; SPDX-FileCopyrightText: M-BM-) 2025 Dominick Grift <dominick.grift@defensec.nl> ;; SPDX-License-Identifier: Unlicense (in fuse @@ -8,7 +8,7 @@ (genfscon "fusectl" "/" fs_context) (macro map_fs_files ((type ARG1)) - (allow ARG1 fs (file (map)))) + (allow ARG1 fs (file (map)))) (blockinherit .fs.macro_template_lnk_files) (blockinherit .noseclabelfs.template) diff --git a/src/fs/noseclabelfs/iso9660noseclabelfs.cil b/src/fs/noseclabelfs/iso9660noseclabelfs.cil index c54d335..4a0916b 100644 --- a/src/fs/noseclabelfs/iso9660noseclabelfs.cil +++ b/src/fs/noseclabelfs/iso9660noseclabelfs.cil @@ -1,8 +1,8 @@ -;; SPDX-FileCopyrightText: © 2025 Dominick Grift <dominick.grift@defensec.nl> +;; SPDX-FileCopyrightText: M-BM-) 2025 Dominick Grift <dominick.grift@defensec.nl> ;; SPDX-License-Identifier: Unlicense (block iso9660 - (genfscon "iso9660" "/" fs_context) + (genfscon "iso9660" "/" fs_context) - (blockinherit .noseclabelfs.template)) + (blockinherit .noseclabelfs.template)) diff --git a/src/fs/noseclabelfs/nfsdnoseclabelfs.cil b/src/fs/noseclabelfs/nfsdnoseclabelfs.cil index 0ecd907..93d82ad 100644 --- a/src/fs/noseclabelfs/nfsdnoseclabelfs.cil +++ b/src/fs/noseclabelfs/nfsdnoseclabelfs.cil @@ -1,8 +1,8 @@ -;; SPDX-FileCopyrightText: © 2025 Dominick Grift <dominick.grift@defensec.nl> +;; SPDX-FileCopyrightText: M-BM-) 2025 Dominick Grift <dominick.grift@defensec.nl> ;; SPDX-License-Identifier: Unlicense (block nfsd - (genfscon "nfsd" "/" fs_context) + (genfscon "nfsd" "/" fs_context) - (blockinherit .noseclabelfs.template)) + (blockinherit .noseclabelfs.template)) diff --git a/src/fs/noseclabelfs/nfsnoseclabelfs.cil b/src/fs/noseclabelfs/nfsnoseclabelfs.cil index 92898d9..0ce9073 100644 --- a/src/fs/noseclabelfs/nfsnoseclabelfs.cil +++ b/src/fs/noseclabelfs/nfsnoseclabelfs.cil @@ -1,17 +1,17 @@ -;; SPDX-FileCopyrightText: © 2025 Dominick Grift <dominick.grift@defensec.nl> +;; SPDX-FileCopyrightText: M-BM-) 2025 Dominick Grift <dominick.grift@defensec.nl> ;; SPDX-License-Identifier: Unlicense (block nfs - (genfscon "afs" "/" fs_context) - (genfscon "nfs" "/" fs_context) + (genfscon "afs" "/" fs_context) + (genfscon "nfs" "/" fs_context) - (macro map_fs_files ((type ARG1)) - (allow ARG1 fs (file (map)))) + (macro map_fs_files ((type ARG1)) + (allow ARG1 fs (file (map)))) - (blockinherit .fs.macro_template_fifo_files) - (blockinherit .fs.macro_template_lnk_files) - (blockinherit .fs.macro_template_sock_files) - (blockinherit .noseclabelfs.template) + (blockinherit .fs.macro_template_fifo_files) + (blockinherit .fs.macro_template_lnk_files) + (blockinherit .fs.macro_template_sock_files) + (blockinherit .noseclabelfs.template) - (call .rbacsep.exempt.obj.type (fs))) + (call .rbacsep.exempt.obj.type (fs))) diff --git a/src/fs/noseclabelfs/nsnoseclabelfs.cil b/src/fs/noseclabelfs/nsnoseclabelfs.cil index 1927e67..06bc2ed 100644 --- a/src/fs/noseclabelfs/nsnoseclabelfs.cil +++ b/src/fs/noseclabelfs/nsnoseclabelfs.cil @@ -1,8 +1,8 @@ -;; SPDX-FileCopyrightText: © 2025 Dominick Grift <dominick.grift@defensec.nl> +;; SPDX-FileCopyrightText: M-BM-) 2025 Dominick Grift <dominick.grift@defensec.nl> ;; SPDX-License-Identifier: Unlicense (block ns - (genfscon "nsfs" "/" fs_context) + (genfscon "nsfs" "/" fs_context) - (blockinherit .noseclabelfs.template)) + (blockinherit .noseclabelfs.template)) diff --git a/src/fs/noseclabelfs/pidnoseclabelfs.cil b/src/fs/noseclabelfs/pidnoseclabelfs.cil index 90cb19a..1d575b9 100644 --- a/src/fs/noseclabelfs/pidnoseclabelfs.cil +++ b/src/fs/noseclabelfs/pidnoseclabelfs.cil @@ -1,8 +1,8 @@ -;; SPDX-FileCopyrightText: © 2025 Dominick Grift <dominick.grift@defensec.nl> +;; SPDX-FileCopyrightText: M-BM-) 2025 Dominick Grift <dominick.grift@defensec.nl> ;; SPDX-License-Identifier: Unlicense (block pid - (genfscon "pidfs" "/" fs_context) + (genfscon "pidfs" "/" fs_context) - (blockinherit .noseclabelfs.template)) + (blockinherit .noseclabelfs.template)) diff --git a/src/fs/noseclabelfs/procnoseclabelfs.cil b/src/fs/noseclabelfs/procnoseclabelfs.cil index c4401e8..8ab7f96 100644 --- a/src/fs/noseclabelfs/procnoseclabelfs.cil +++ b/src/fs/noseclabelfs/procnoseclabelfs.cil @@ -1,9 +1,9 @@ -;; SPDX-FileCopyrightText: © 2025 Dominick Grift <dominick.grift@defensec.nl> +;; SPDX-FileCopyrightText: M-BM-) 2025 Dominick Grift <dominick.grift@defensec.nl> ;; SPDX-License-Identifier: Unlicense (block proc - (genfscon "proc" "/" fs_context) + (genfscon "proc" "/" fs_context) - (blockinherit .fs.macro_template_lnk_files) - (blockinherit .noseclabelfs.template)) + (blockinherit .fs.macro_template_lnk_files) + (blockinherit .noseclabelfs.template)) diff --git a/src/fs/noseclabelfs/removablenoseclabelfs.cil b/src/fs/noseclabelfs/removablenoseclabelfs.cil index eb69a6a..cb0c7f7 100644 --- a/src/fs/noseclabelfs/removablenoseclabelfs.cil +++ b/src/fs/noseclabelfs/removablenoseclabelfs.cil @@ -1,4 +1,4 @@ -;; SPDX-FileCopyrightText: © 2025 Dominick Grift <dominick.grift@defensec.nl> +;; SPDX-FileCopyrightText: M-BM-) 2025 Dominick Grift <dominick.grift@defensec.nl> ;; SPDX-License-Identifier: Unlicense (in removable diff --git a/src/fs/noseclabelfs/resctrlnoseclabelfs.cil b/src/fs/noseclabelfs/resctrlnoseclabelfs.cil index 20d84b7..4e16e68 100644 --- a/src/fs/noseclabelfs/resctrlnoseclabelfs.cil +++ b/src/fs/noseclabelfs/resctrlnoseclabelfs.cil @@ -1,11 +1,11 @@ -;; SPDX-FileCopyrightText: © 2025 Dominick Grift <dominick.grift@defensec.nl> +;; SPDX-FileCopyrightText: M-BM-) 2025 Dominick Grift <dominick.grift@defensec.nl> ;; SPDX-License-Identifier: Unlicense (block resctrl - (filecon "/sys/fs/resctrl" dir ()) - (filecon "/sys/fs/resctrl/.*" any ()) + (filecon "/sys/fs/resctrl" dir ()) + (filecon "/sys/fs/resctrl/.*" any ()) - (genfscon "resctrl" "/" fs_context) + (genfscon "resctrl" "/" fs_context) - (blockinherit .noseclabelfs.template)) + (blockinherit .noseclabelfs.template)) diff --git a/src/fs/noseclabelfs/rpcpipenoseclabelfs.cil b/src/fs/noseclabelfs/rpcpipenoseclabelfs.cil index f7608fc..e2be422 100644 --- a/src/fs/noseclabelfs/rpcpipenoseclabelfs.cil +++ b/src/fs/noseclabelfs/rpcpipenoseclabelfs.cil @@ -1,9 +1,9 @@ -;; SPDX-FileCopyrightText: © 2025 Dominick Grift <dominick.grift@defensec.nl> +;; SPDX-FileCopyrightText: M-BM-) 2025 Dominick Grift <dominick.grift@defensec.nl> ;; SPDX-License-Identifier: Unlicense (block rpcpipe - (genfscon "rpc_pipefs" "/" fs_context) + (genfscon "rpc_pipefs" "/" fs_context) - (blockinherit .fs.macro_template_fs) - (blockinherit .noseclabelfs.base_template)) + (blockinherit .fs.macro_template_fs) + (blockinherit .noseclabelfs.base_template)) diff --git a/src/fs/noseclabelfs/securitynoseclabelfs.cil b/src/fs/noseclabelfs/securitynoseclabelfs.cil index 59c5e3b..a0b7a8d 100644 --- a/src/fs/noseclabelfs/securitynoseclabelfs.cil +++ b/src/fs/noseclabelfs/securitynoseclabelfs.cil @@ -1,9 +1,9 @@ -;; SPDX-FileCopyrightText: © 2025 Dominick Grift <dominick.grift@defensec.nl> +;; SPDX-FileCopyrightText: M-BM-) 2025 Dominick Grift <dominick.grift@defensec.nl> ;; SPDX-License-Identifier: Unlicense (block security - (genfscon "securityfs" "/" fs_context) + (genfscon "securityfs" "/" fs_context) - (blockinherit .fs.macro_template_lnk_files) - (blockinherit .noseclabelfs.template)) + (blockinherit .fs.macro_template_lnk_files) + (blockinherit .noseclabelfs.template)) diff --git a/src/fs/noseclabelfs/selinuxnoseclabelfs.cil b/src/fs/noseclabelfs/selinuxnoseclabelfs.cil index 1245921..8d27ba7 100644 --- a/src/fs/noseclabelfs/selinuxnoseclabelfs.cil +++ b/src/fs/noseclabelfs/selinuxnoseclabelfs.cil @@ -1,4 +1,4 @@ -;; SPDX-FileCopyrightText: © 2025 Dominick Grift <dominick.grift@defensec.nl> +;; SPDX-FileCopyrightText: M-BM-) 2025 Dominick Grift <dominick.grift@defensec.nl> ;; SPDX-License-Identifier: Unlicense (in selinux diff --git a/src/fs/noseclabelfs/udfnoseclabelfs.cil b/src/fs/noseclabelfs/udfnoseclabelfs.cil index 4f2ec42..d096086 100644 --- a/src/fs/noseclabelfs/udfnoseclabelfs.cil +++ b/src/fs/noseclabelfs/udfnoseclabelfs.cil @@ -1,8 +1,8 @@ -;; SPDX-FileCopyrightText: © 2025 Dominick Grift <dominick.grift@defensec.nl> +;; SPDX-FileCopyrightText: M-BM-) 2025 Dominick Grift <dominick.grift@defensec.nl> ;; SPDX-License-Identifier: Unlicense (block udf - (genfscon "udf" "/" fs_context) + (genfscon "udf" "/" fs_context) - (blockinherit .noseclabelfs.template)) + (blockinherit .noseclabelfs.template)) diff --git a/src/fs/seclabelfs.cil b/src/fs/seclabelfs.cil index 7b6a6ef..d21caaa 100644 --- a/src/fs/seclabelfs.cil +++ b/src/fs/seclabelfs.cil @@ -1,37 +1,37 @@ -;; SPDX-FileCopyrightText: © 2025 Dominick Grift <dominick.grift@defensec.nl> +;; SPDX-FileCopyrightText: M-BM-) 2025 Dominick Grift <dominick.grift@defensec.nl> ;; SPDX-License-Identifier: Unlicense (block seclabelfs - (macro type ((type ARG1)) - (typeattributeset typeattr ARG1)) + (macro type ((type ARG1)) + (typeattributeset typeattr ARG1)) - (typeattribute typeattr) + (typeattribute typeattr) - (blockinherit .fs.all_macro_template_fs) + (blockinherit .fs.all_macro_template_fs) - (blockinherit .file.all_macro_template_all_files) - (blockinherit .file.all_macro_template_blk_files) - (blockinherit .file.all_macro_template_chr_files) - (blockinherit .file.all_macro_template_dirs) - (blockinherit .file.all_macro_template_fifo_files) - (blockinherit .file.all_macro_template_files) - (blockinherit .file.all_macro_template_lnk_files) - (blockinherit .file.all_macro_template_sock_files) + (blockinherit .file.all_macro_template_all_files) + (blockinherit .file.all_macro_template_blk_files) + (blockinherit .file.all_macro_template_chr_files) + (blockinherit .file.all_macro_template_dirs) + (blockinherit .file.all_macro_template_fifo_files) + (blockinherit .file.all_macro_template_files) + (blockinherit .file.all_macro_template_lnk_files) + (blockinherit .file.all_macro_template_sock_files) - (call .fs.type (typeattr)) + (call .fs.type (typeattr)) - (block base_template + (block base_template - (blockabstract base_template) + (blockabstract base_template) - (blockinherit .fs.base_template) + (blockinherit .fs.base_template) - (call .seclabelfs.type (fs))) + (call .seclabelfs.type (fs))) - (block template + (block template - (blockabstract template) + (blockabstract template) - (blockinherit .fs.macro_template_fs) - (blockinherit .seclabelfs.base_template))) + (blockinherit .fs.macro_template_fs) + (blockinherit .seclabelfs.base_template))) diff --git a/src/fs/seclabelfs/cgroupseclabelfs.cil b/src/fs/seclabelfs/cgroupseclabelfs.cil index 18266a1..0a0f9ef 100644 --- a/src/fs/seclabelfs/cgroupseclabelfs.cil +++ b/src/fs/seclabelfs/cgroupseclabelfs.cil @@ -1,4 +1,4 @@ -;; SPDX-FileCopyrightText: © 2025 Dominick Grift <dominick.grift@defensec.nl> +;; SPDX-FileCopyrightText: M-BM-) 2025 Dominick Grift <dominick.grift@defensec.nl> ;; SPDX-License-Identifier: Unlicense (block cgroup diff --git a/src/fs/seclabelfs/debugseclabelfs.cil b/src/fs/seclabelfs/debugseclabelfs.cil index bb2a336..1a99048 100644 --- a/src/fs/seclabelfs/debugseclabelfs.cil +++ b/src/fs/seclabelfs/debugseclabelfs.cil @@ -1,4 +1,4 @@ -;; SPDX-FileCopyrightText: © 2025 Dominick Grift <dominick.grift@defensec.nl> +;; SPDX-FileCopyrightText: M-BM-) 2025 Dominick Grift <dominick.grift@defensec.nl> ;; SPDX-License-Identifier: Unlicense (in debug diff --git a/src/fs/seclabelfs/devptsseclabelfs.cil b/src/fs/seclabelfs/devptsseclabelfs.cil index 59d4789..4545f1f 100644 --- a/src/fs/seclabelfs/devptsseclabelfs.cil +++ b/src/fs/seclabelfs/devptsseclabelfs.cil @@ -1,11 +1,11 @@ -;; SPDX-FileCopyrightText: © 2025 Dominick Grift <dominick.grift@defensec.nl> +;; SPDX-FileCopyrightText: M-BM-) 2025 Dominick Grift <dominick.grift@defensec.nl> ;; SPDX-License-Identifier: Unlicense (block devpts - (fsuse trans "devpts" fs_context) + (fsuse trans "devpts" fs_context) - (blockinherit .fs.macro_template_dirs) - (blockinherit .fs.macro_template_chr_files) - (blockinherit .fs.macro_template_fs) - (blockinherit .seclabelfs.base_template)) + (blockinherit .fs.macro_template_dirs) + (blockinherit .fs.macro_template_chr_files) + (blockinherit .fs.macro_template_fs) + (blockinherit .seclabelfs.base_template)) diff --git a/src/fs/seclabelfs/devtmpseclabelfs.cil b/src/fs/seclabelfs/devtmpseclabelfs.cil index a5a35e2..fdfc120 100644 --- a/src/fs/seclabelfs/devtmpseclabelfs.cil +++ b/src/fs/seclabelfs/devtmpseclabelfs.cil @@ -1,16 +1,16 @@ -;; SPDX-FileCopyrightText: © 2025 Dominick Grift <dominick.grift@defensec.nl> +;; SPDX-FileCopyrightText: M-BM-) 2025 Dominick Grift <dominick.grift@defensec.nl> ;; SPDX-License-Identifier: Unlicense (block devtmp - (fsuse trans "devtmpfs" fs_context) + (fsuse trans "devtmpfs" fs_context) - (blockinherit .fs.macro_template_all_files) - (blockinherit .fs.macro_template_blk_files) - (blockinherit .fs.macro_template_chr_files) - (blockinherit .fs.macro_template_dirs) - (blockinherit .fs.macro_template_fifo_files) - (blockinherit .fs.macro_template_files) - (blockinherit .fs.macro_template_lnk_files) - (blockinherit .fs.macro_template_sock_files) - (blockinherit .seclabelfs.template)) + (blockinherit .fs.macro_template_all_files) + (blockinherit .fs.macro_template_blk_files) + (blockinherit .fs.macro_template_chr_files) + (blockinherit .fs.macro_template_dirs) + (blockinherit .fs.macro_template_fifo_files) + (blockinherit .fs.macro_template_files) + (blockinherit .fs.macro_template_lnk_files) + (blockinherit .fs.macro_template_sock_files) + (blockinherit .seclabelfs.template)) diff --git a/src/fs/seclabelfs/eventpollseclabelfs.cil b/src/fs/seclabelfs/eventpollseclabelfs.cil index 1ec86f8..dcabbc2 100644 --- a/src/fs/seclabelfs/eventpollseclabelfs.cil +++ b/src/fs/seclabelfs/eventpollseclabelfs.cil @@ -1,8 +1,8 @@ -;; SPDX-FileCopyrightText: © 2025 Dominick Grift <dominick.grift@defensec.nl> +;; SPDX-FileCopyrightText: M-BM-) 2025 Dominick Grift <dominick.grift@defensec.nl> ;; SPDX-License-Identifier: Unlicense (block eventpoll - (fsuse task "eventpollfs" fs_context) + (fsuse task "eventpollfs" fs_context) - (blockinherit .seclabelfs.base_template)) + (blockinherit .seclabelfs.base_template)) diff --git a/src/fs/seclabelfs/hugetlbseclabelfs.cil b/src/fs/seclabelfs/hugetlbseclabelfs.cil index a2474d4..81f7a86 100644 --- a/src/fs/seclabelfs/hugetlbseclabelfs.cil +++ b/src/fs/seclabelfs/hugetlbseclabelfs.cil @@ -1,10 +1,10 @@ -;; SPDX-FileCopyrightText: © 2025 Dominick Grift <dominick.grift@defensec.nl> +;; SPDX-FileCopyrightText: M-BM-) 2025 Dominick Grift <dominick.grift@defensec.nl> ;; SPDX-License-Identifier: Unlicense (block hugetlb - (fsuse trans "hugetlbfs" fs_context) + (fsuse trans "hugetlbfs" fs_context) - (blockinherit .fs.macro_template_dirs) - (blockinherit .fs.macro_template_files) - (blockinherit .seclabelfs.template)) + (blockinherit .fs.macro_template_dirs) + (blockinherit .fs.macro_template_files) + (blockinherit .seclabelfs.template)) diff --git a/src/fs/seclabelfs/mqueueseclabelfs.cil b/src/fs/seclabelfs/mqueueseclabelfs.cil index 7307449..431afb5 100644 --- a/src/fs/seclabelfs/mqueueseclabelfs.cil +++ b/src/fs/seclabelfs/mqueueseclabelfs.cil @@ -1,12 +1,12 @@ -;; SPDX-FileCopyrightText: © 2025 Dominick Grift <dominick.grift@defensec.nl> +;; SPDX-FileCopyrightText: M-BM-) 2025 Dominick Grift <dominick.grift@defensec.nl> ;; SPDX-License-Identifier: Unlicense (block mqueue - (fsuse trans "mqueue" fs_context) + (fsuse trans "mqueue" fs_context) - (blockinherit .fs.macro_template_dirs) - (blockinherit .fs.macro_template_files) - (blockinherit .seclabelfs.template) + (blockinherit .fs.macro_template_dirs) + (blockinherit .fs.macro_template_files) + (blockinherit .seclabelfs.template) - (call .rbacsep.exempt.obj.type (fs))) + (call .rbacsep.exempt.obj.type (fs))) diff --git a/src/fs/seclabelfs/nfs4seclabelfs.cil b/src/fs/seclabelfs/nfs4seclabelfs.cil index 752aa01..25c1fed 100644 --- a/src/fs/seclabelfs/nfs4seclabelfs.cil +++ b/src/fs/seclabelfs/nfs4seclabelfs.cil @@ -1,10 +1,10 @@ -;; SPDX-FileCopyrightText: © 2025 Dominick Grift <dominick.grift@defensec.nl> +;; SPDX-FileCopyrightText: M-BM-) 2025 Dominick Grift <dominick.grift@defensec.nl> ;; SPDX-License-Identifier: Unlicense (block nfs4 - (genfscon "nfs4" "/" fs_context) + (genfscon "nfs4" "/" fs_context) - (blockinherit .seclabelfs.template) + (blockinherit .seclabelfs.template) - (allow fs self (filesystem (associate)))) + (allow fs self (filesystem (associate)))) diff --git a/src/fs/seclabelfs/pipeseclabelfs.cil b/src/fs/seclabelfs/pipeseclabelfs.cil index 3496562..0de2d3f 100644 --- a/src/fs/seclabelfs/pipeseclabelfs.cil +++ b/src/fs/seclabelfs/pipeseclabelfs.cil @@ -1,8 +1,8 @@ -;; SPDX-FileCopyrightText: © 2025 Dominick Grift <dominick.grift@defensec.nl> +;; SPDX-FileCopyrightText: M-BM-) 2025 Dominick Grift <dominick.grift@defensec.nl> ;; SPDX-License-Identifier: Unlicense (block pipe - (fsuse task "pipefs" fs_context) + (fsuse task "pipefs" fs_context) - (blockinherit .seclabelfs.base_template)) + (blockinherit .seclabelfs.base_template)) diff --git a/src/fs/seclabelfs/pstoreseclabelfs.cil b/src/fs/seclabelfs/pstoreseclabelfs.cil index 10ef8f3..92c272a 100644 --- a/src/fs/seclabelfs/pstoreseclabelfs.cil +++ b/src/fs/seclabelfs/pstoreseclabelfs.cil @@ -1,12 +1,12 @@ -;; SPDX-FileCopyrightText: © 2025 Dominick Grift <dominick.grift@defensec.nl> +;; SPDX-FileCopyrightText: M-BM-) 2025 Dominick Grift <dominick.grift@defensec.nl> ;; SPDX-License-Identifier: Unlicense (block pstore - (genfscon "pstore" "/" fs_context) + (genfscon "pstore" "/" fs_context) - (blockinherit .fs.macro_template_dirs) - (blockinherit .fs.macro_template_files) - (blockinherit .seclabelfs.template) + (blockinherit .fs.macro_template_dirs) + (blockinherit .fs.macro_template_files) + (blockinherit .seclabelfs.template) - (allow fs self (filesystem (associate)))) + (allow fs self (filesystem (associate)))) diff --git a/src/fs/seclabelfs/rootseclabelfs.cil b/src/fs/seclabelfs/rootseclabelfs.cil index 7c86c65..2170132 100644 --- a/src/fs/seclabelfs/rootseclabelfs.cil +++ b/src/fs/seclabelfs/rootseclabelfs.cil @@ -1,4 +1,4 @@ -;; SPDX-FileCopyrightText: © 2025 Dominick Grift <dominick.grift@defensec.nl> +;; SPDX-FileCopyrightText: M-BM-) 2025 Dominick Grift <dominick.grift@defensec.nl> ;; SPDX-License-Identifier: Unlicense (in root diff --git a/src/fs/seclabelfs/sockseclabelfs.cil b/src/fs/seclabelfs/sockseclabelfs.cil index 84ba42c..4f8f6e4 100644 --- a/src/fs/seclabelfs/sockseclabelfs.cil +++ b/src/fs/seclabelfs/sockseclabelfs.cil @@ -1,8 +1,8 @@ -;; SPDX-FileCopyrightText: © 2025 Dominick Grift <dominick.grift@defensec.nl> +;; SPDX-FileCopyrightText: M-BM-) 2025 Dominick Grift <dominick.grift@defensec.nl> ;; SPDX-License-Identifier: Unlicense (block sock - (fsuse task "sockfs" fs_context) + (fsuse task "sockfs" fs_context) - (blockinherit .seclabelfs.base_template)) + (blockinherit .seclabelfs.base_template)) diff --git a/src/fs/seclabelfs/sysseclabelfs.cil b/src/fs/seclabelfs/sysseclabelfs.cil index a0c3fc6..622d34d 100644 --- a/src/fs/seclabelfs/sysseclabelfs.cil +++ b/src/fs/seclabelfs/sysseclabelfs.cil @@ -1,4 +1,4 @@ -;; SPDX-FileCopyrightText: © 2025 Dominick Grift <dominick.grift@defensec.nl> +;; SPDX-FileCopyrightText: M-BM-) 2025 Dominick Grift <dominick.grift@defensec.nl> ;; SPDX-License-Identifier: Unlicense (in sys diff --git a/src/fs/seclabelfs/tmpseclabelfs.cil b/src/fs/seclabelfs/tmpseclabelfs.cil index a37e0fc..8bcd891 100644 --- a/src/fs/seclabelfs/tmpseclabelfs.cil +++ b/src/fs/seclabelfs/tmpseclabelfs.cil @@ -1,18 +1,18 @@ -;; SPDX-FileCopyrightText: © 2025 Dominick Grift <dominick.grift@defensec.nl> +;; SPDX-FileCopyrightText: M-BM-) 2025 Dominick Grift <dominick.grift@defensec.nl> ;; SPDX-License-Identifier: Unlicense (block tmp - (fsuse trans "ramfs" fs_context) - (fsuse trans "shm" fs_context) - (fsuse trans "tmpfs" fs_context) + (fsuse trans "ramfs" fs_context) + (fsuse trans "shm" fs_context) + (fsuse trans "tmpfs" fs_context) - (blockinherit .fs.macro_template_all_files) - (blockinherit .fs.macro_template_blk_files) - (blockinherit .fs.macro_template_chr_files) - (blockinherit .fs.macro_template_dirs) - (blockinherit .fs.macro_template_fifo_files) - (blockinherit .fs.macro_template_files) - (blockinherit .fs.macro_template_lnk_files) - (blockinherit .fs.macro_template_sock_files) - (blockinherit .seclabelfs.template)) + (blockinherit .fs.macro_template_all_files) + (blockinherit .fs.macro_template_blk_files) + (blockinherit .fs.macro_template_chr_files) + (blockinherit .fs.macro_template_dirs) + (blockinherit .fs.macro_template_fifo_files) + (blockinherit .fs.macro_template_files) + (blockinherit .fs.macro_template_lnk_files) + (blockinherit .fs.macro_template_sock_files) + (blockinherit .seclabelfs.template)) diff --git a/src/fs/seclabelfs/traceseclabelfs.cil b/src/fs/seclabelfs/traceseclabelfs.cil index f52d51e..1589181 100644 --- a/src/fs/seclabelfs/traceseclabelfs.cil +++ b/src/fs/seclabelfs/traceseclabelfs.cil @@ -1,10 +1,10 @@ -;; SPDX-FileCopyrightText: © 2025 Dominick Grift <dominick.grift@defensec.nl> +;; SPDX-FileCopyrightText: M-BM-) 2025 Dominick Grift <dominick.grift@defensec.nl> ;; SPDX-License-Identifier: Unlicense (block trace - (genfscon "tracefs" "/" fs_context) + (genfscon "tracefs" "/" fs_context) - (blockinherit .fs.macro_template_dirs) - (blockinherit .fs.macro_template_files) - (blockinherit .seclabelfs.template)) + (blockinherit .fs.macro_template_dirs) + (blockinherit .fs.macro_template_files) + (blockinherit .seclabelfs.template)) diff --git a/src/fs/seclabelfs/xattrseclabelfs.cil b/src/fs/seclabelfs/xattrseclabelfs.cil index bdc02a2..fbe64ff 100644 --- a/src/fs/seclabelfs/xattrseclabelfs.cil +++ b/src/fs/seclabelfs/xattrseclabelfs.cil @@ -1,36 +1,36 @@ -;; SPDX-FileCopyrightText: © 2025 Dominick Grift <dominick.grift@defensec.nl> +;; SPDX-FileCopyrightText: M-BM-) 2025 Dominick Grift <dominick.grift@defensec.nl> ;; SPDX-License-Identifier: Unlicense (block xattr - (fsuse xattr "bcachefs" fs_context) - (fsuse xattr "btrfs" fs_context) - (fsuse xattr "ceph" fs_context) - (fsuse xattr "encfs" fs_context) - (fsuse xattr "erofs" fs_context) - (fsuse xattr "ext2" fs_context) - (fsuse xattr "ext3" fs_context) - (fsuse xattr "ext4" fs_context) - (fsuse xattr "ext4dev" fs_context) - (fsuse xattr "f2fs" fs_context) - (fsuse xattr "gfs" fs_context) - (fsuse xattr "gfs2" fs_context) - (fsuse xattr "gpfs" fs_context) - (fsuse xattr "incremental-fs" fs_context) - (fsuse xattr "jffs2" fs_context) - (fsuse xattr "jfs" fs_context) - (fsuse xattr "lustre" fs_context) - (fsuse xattr "ocfs2" fs_context) - (fsuse xattr "odms" fs_context) - (fsuse xattr "overlay" fs_context) - (fsuse xattr "shiftfs" fs_context) - (fsuse xattr "squashfs" fs_context) - (fsuse xattr "ubifs" fs_context) - (fsuse xattr "virtiofs" fs_context) - (fsuse xattr "vxclonefs" fs_context) - (fsuse xattr "vxfs" fs_context) - (fsuse xattr "xfs" fs_context) - (fsuse xattr "yaffs2" fs_context) - (fsuse xattr "zfs" fs_context) + (fsuse xattr "bcachefs" fs_context) + (fsuse xattr "btrfs" fs_context) + (fsuse xattr "ceph" fs_context) + (fsuse xattr "encfs" fs_context) + (fsuse xattr "erofs" fs_context) + (fsuse xattr "ext2" fs_context) + (fsuse xattr "ext3" fs_context) + (fsuse xattr "ext4" fs_context) + (fsuse xattr "ext4dev" fs_context) + (fsuse xattr "f2fs" fs_context) + (fsuse xattr "gfs" fs_context) + (fsuse xattr "gfs2" fs_context) + (fsuse xattr "gpfs" fs_context) + (fsuse xattr "incremental-fs" fs_context) + (fsuse xattr "jffs2" fs_context) + (fsuse xattr "jfs" fs_context) + (fsuse xattr "lustre" fs_context) + (fsuse xattr "ocfs2" fs_context) + (fsuse xattr "odms" fs_context) + (fsuse xattr "overlay" fs_context) + (fsuse xattr "shiftfs" fs_context) + (fsuse xattr "squashfs" fs_context) + (fsuse xattr "ubifs" fs_context) + (fsuse xattr "virtiofs" fs_context) + (fsuse xattr "vxclonefs" fs_context) + (fsuse xattr "vxfs" fs_context) + (fsuse xattr "xfs" fs_context) + (fsuse xattr "yaffs2" fs_context) + (fsuse xattr "zfs" fs_context) - (blockinherit .seclabelfs.template)) + (blockinherit .seclabelfs.template)) |