parent
c29c5deff8
commit
d94db1166e
|
@ -229,11 +229,12 @@ type demo, domain;
|
||||||
type demo_exec, exec_type, vendor_file_type, file_type;
|
type demo_exec, exec_type, vendor_file_type, file_type;
|
||||||
init_daemon_domain(demo)
|
init_daemon_domain(demo)
|
||||||
|
|
||||||
|
net_domain(demo)
|
||||||
|
unix_socket_connect(demo, netd, netd)
|
||||||
|
|
||||||
allow demo self:capability { net_admin net_raw net_bind_service };
|
allow demo self:capability { net_admin net_raw net_bind_service };
|
||||||
allow demo device:dir { create open read write ioctl };
|
allow demo device:dir { create open read write ioctl };
|
||||||
allow demo self:tcp_socket { create connect name_connect lock append bind name_bind listen accept recvfrom sendto read write getattr setattr getopt setopt };
|
allow demo self:tcp_socket { create connect name_connect lock append bind name_bind listen accept recvfrom sendto read write getattr setattr getopt setopt };
|
||||||
allow demo port:tcp_socket { create connect name_connect lock append bind name_bind listen accept recvfrom sendto read write getattr setattr getopt setopt };
|
allow demo port:tcp_socket { create connect name_connect lock append bind name_bind listen accept recvfrom sendto read write getattr setattr getopt setopt };
|
||||||
allow demo fwmarkd_socket:sock_file { write };
|
allow demo fwmarkd_socket:sock_file { write };
|
||||||
net_domain(demo)
|
|
||||||
unix_socket_connect(demo, netd, netd);
|
|
||||||
```
|
```
|
||||||
|
|
Loading…
Reference in New Issue