/usr/share/selinux/ubuntu/include/system/mount.if is in selinux-policy-ubuntu-dev 0.2.20091117-0ubuntu2.
This file is owned by root:root, with mode 0o644.
The actual contents of the file can be viewed below.
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139 140 141 142 143 144 145 146 147 148 149 150 151 152 153 154 155 156 157 158 159 160 161 162 163 164 165 166 167 168 169 170 171 172 173 174 175 176 177 178 179 | ## <summary>Policy for mount.</summary>
########################################
## <summary>
## Execute mount in the mount domain.
## </summary>
## <param name="domain">
## <summary>
## The type of the process performing this action.
## </summary>
## </param>
#
interface(`mount_domtrans',`
gen_require(`
type mount_t, mount_exec_t;
')
domtrans_pattern($1, mount_exec_t, mount_t)
')
########################################
## <summary>
## Execute mount in the mount domain, and
## allow the specified role the mount domain,
## and use the caller's terminal.
## </summary>
## <param name="domain">
## <summary>
## The type of the process performing this action.
## </summary>
## </param>
## <param name="role">
## <summary>
## The role to be allowed the mount domain.
## </summary>
## </param>
## <rolecap/>
#
interface(`mount_run',`
gen_require(`
type mount_t;
')
mount_domtrans($1)
role $2 types mount_t;
optional_policy(`
samba_run_smbmount($1, $2)
')
')
########################################
## <summary>
## Execute mount in the caller domain.
## </summary>
## <param name="domain">
## <summary>
## The type of the process performing this action.
## </summary>
## </param>
#
interface(`mount_exec',`
gen_require(`
type mount_exec_t;
')
# cjp: this should be removed:
allow $1 mount_exec_t:dir list_dir_perms;
allow $1 mount_exec_t:lnk_file read_lnk_file_perms;
can_exec($1, mount_exec_t)
')
########################################
## <summary>
## Send a generic signal to mount.
## </summary>
## <param name="domain">
## <summary>
## Domain allowed access.
## </summary>
## </param>
#
interface(`mount_signal',`
gen_require(`
type mount_t;
')
allow $1 mount_t:process signal;
')
########################################
## <summary>
## Use file descriptors for mount.
## </summary>
## <param name="domain">
## <summary>
## The type of the process performing this action.
## </summary>
## </param>
#
interface(`mount_use_fds',`
gen_require(`
type mount_t;
')
allow $1 mount_t:fd use;
')
########################################
## <summary>
## Allow the mount domain to send nfs requests for mounting
## network drives
## </summary>
## <desc>
## <p>
## Allow the mount domain to send nfs requests for mounting
## network drives
## </p>
## <p>
## This interface has been deprecated as these rules were
## a side effect of leaked mount file descriptors. This
## interface has no effect.
## </p>
## </desc>
## <param name="domain">
## <summary>
## Domain allowed access.
## </summary>
## </param>
#
interface(`mount_send_nfs_client_request',`
refpolicywarn(`$0($*) has been deprecated.')
')
########################################
## <summary>
## Execute mount in the unconfined mount domain.
## </summary>
## <param name="domain">
## <summary>
## Domain allowed access.
## </summary>
## </param>
#
interface(`mount_domtrans_unconfined',`
gen_require(`
type unconfined_mount_t, mount_exec_t;
')
domtrans_pattern($1, mount_exec_t, unconfined_mount_t)
')
########################################
## <summary>
## Execute mount in the unconfined mount domain, and
## allow the specified role the unconfined mount domain,
## and use the caller's terminal.
## </summary>
## <param name="domain">
## <summary>
## Domain allowed access.
## </summary>
## </param>
## <param name="role">
## <summary>
## The role to be allowed the unconfined mount domain.
## </summary>
## </param>
## <rolecap/>
#
interface(`mount_run_unconfined',`
gen_require(`
type unconfined_mount_t;
')
mount_domtrans_unconfined($1)
role $2 types unconfined_mount_t;
')
|