type linkerconfig, domain, coredomain; | |
type linkerconfig_exec, exec_type, file_type, system_file_type; | |
init_daemon_domain(linkerconfig) | |
## Read and write linkerconfig subdirectory. | |
allow linkerconfig linkerconfig_file:dir rw_dir_perms; | |
allow linkerconfig linkerconfig_file:file create_file_perms; | |
# Allow linkerconfig to log to the kernel. | |
allow linkerconfig kmsg_device:chr_file w_file_perms; | |
neverallow { domain -init -linkerconfig } linkerconfig_exec:file no_x_file_perms; |