summaryrefslogtreecommitdiff
path: root/src/misc/conf.cil
blob: f7c70d4259275aa4c7ad2dcf75ae304f66c01a2e (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
;; SPDX-FileCopyrightText: © 2023 Dominick Grift <dominick.grift@defensec.nl>
;; SPDX-License-Identifier: Unlicense

(handleunknown allow)
(mls true)

(policycap "always_check_network")
(policycap "cgroup_seclabel")
(policycap "extended_socket_class")
(policycap "genfs_seclabel_symlinks")
(policycap "network_peer_controls")
(policycap "nnp_nosuid_transition")
(policycap "open_perms")

;; SELinux 3.4/Linux 5.18
;; (policycap "ioctl_skip_cloexec")