PERFORCE change 109971 for review

Todd Miller millert at FreeBSD.org
Tue Nov 14 19:08:22 UTC 2006


http://perforce.freebsd.org/chv.cgi?CH=109971

Change 109971 by millert at millert_g5tower on 2006/11/14 19:02:14

	Sync generated versions of flask headers with policy.

Affected files ...

.. //depot/projects/trustedbsd/sedarwin8/policies/sedarwin/libselinux/include/selinux/av_permissions.h#4 edit
.. //depot/projects/trustedbsd/sedarwin8/policies/sedarwin/libselinux/include/selinux/flask.h#3 edit
.. //depot/projects/trustedbsd/sedarwin8/policies/sedarwin/libselinux/src/av_inherit.h#3 edit
.. //depot/projects/trustedbsd/sedarwin8/policies/sedarwin/libselinux/src/av_perm_to_string.h#3 edit
.. //depot/projects/trustedbsd/sedarwin8/policies/sedarwin/libselinux/src/class_to_string.h#3 edit
.. //depot/projects/trustedbsd/sedarwin8/policies/sedarwin/libselinux/src/common_perm_to_string.h#3 edit
.. //depot/projects/trustedbsd/sedarwin8/policies/sedarwin/libsepol/include/sepol/policydb/flask.h#2 edit
.. //depot/projects/trustedbsd/sedarwin8/policies/sedarwin/libsepol/src/av_permissions.h#2 edit

Differences ...

==== //depot/projects/trustedbsd/sedarwin8/policies/sedarwin/libselinux/include/selinux/av_permissions.h#4 (text+ko) ====

@@ -16,7 +16,6 @@
 #define COMMON_FILE__SWAPON                              0x00004000UL
 #define COMMON_FILE__QUOTAON                             0x00008000UL
 #define COMMON_FILE__MOUNTON                             0x00010000UL
-
 #define COMMON_SOCKET__IOCTL                             0x00000001UL
 #define COMMON_SOCKET__READ                              0x00000002UL
 #define COMMON_SOCKET__WRITE                             0x00000004UL
@@ -39,7 +38,6 @@
 #define COMMON_SOCKET__RECV_MSG                          0x00080000UL
 #define COMMON_SOCKET__SEND_MSG                          0x00100000UL
 #define COMMON_SOCKET__NAME_BIND                         0x00200000UL
-
 #define COMMON_IPC__CREATE                               0x00000001UL
 #define COMMON_IPC__DESTROY                              0x00000002UL
 #define COMMON_IPC__GETATTR                              0x00000004UL
@@ -49,7 +47,6 @@
 #define COMMON_IPC__ASSOCIATE                            0x00000040UL
 #define COMMON_IPC__UNIX_READ                            0x00000080UL
 #define COMMON_IPC__UNIX_WRITE                           0x00000100UL
-
 #define FILESYSTEM__MOUNT                         0x00000001UL
 #define FILESYSTEM__REMOUNT                       0x00000002UL
 #define FILESYSTEM__UNMOUNT                       0x00000004UL
@@ -60,7 +57,6 @@
 #define FILESYSTEM__ASSOCIATE                     0x00000080UL
 #define FILESYSTEM__QUOTAMOD                      0x00000100UL
 #define FILESYSTEM__QUOTAGET                      0x00000200UL
-
 #define DIR__IOCTL                                0x00000001UL
 #define DIR__READ                                 0x00000002UL
 #define DIR__WRITE                                0x00000004UL
@@ -78,13 +74,11 @@
 #define DIR__SWAPON                               0x00004000UL
 #define DIR__QUOTAON                              0x00008000UL
 #define DIR__MOUNTON                              0x00010000UL
-
 #define DIR__ADD_NAME                             0x00020000UL
 #define DIR__REMOVE_NAME                          0x00040000UL
 #define DIR__REPARENT                             0x00080000UL
 #define DIR__SEARCH                               0x00100000UL
 #define DIR__RMDIR                                0x00200000UL
-
 #define FILE__IOCTL                               0x00000001UL
 #define FILE__READ                                0x00000002UL
 #define FILE__WRITE                               0x00000004UL
@@ -102,11 +96,9 @@
 #define FILE__SWAPON                              0x00004000UL
 #define FILE__QUOTAON                             0x00008000UL
 #define FILE__MOUNTON                             0x00010000UL
-
 #define FILE__EXECUTE_NO_TRANS                    0x00020000UL
 #define FILE__ENTRYPOINT                          0x00040000UL
 #define FILE__EXECMOD                             0x00080000UL
-
 #define LNK_FILE__IOCTL                           0x00000001UL
 #define LNK_FILE__READ                            0x00000002UL
 #define LNK_FILE__WRITE                           0x00000004UL
@@ -124,7 +116,6 @@
 #define LNK_FILE__SWAPON                          0x00004000UL
 #define LNK_FILE__QUOTAON                         0x00008000UL
 #define LNK_FILE__MOUNTON                         0x00010000UL
-
 #define CHR_FILE__IOCTL                           0x00000001UL
 #define CHR_FILE__READ                            0x00000002UL
 #define CHR_FILE__WRITE                           0x00000004UL
@@ -142,11 +133,9 @@
 #define CHR_FILE__SWAPON                          0x00004000UL
 #define CHR_FILE__QUOTAON                         0x00008000UL
 #define CHR_FILE__MOUNTON                         0x00010000UL
-
 #define CHR_FILE__EXECUTE_NO_TRANS                0x00020000UL
 #define CHR_FILE__ENTRYPOINT                      0x00040000UL
 #define CHR_FILE__EXECMOD                         0x00080000UL
-
 #define BLK_FILE__IOCTL                           0x00000001UL
 #define BLK_FILE__READ                            0x00000002UL
 #define BLK_FILE__WRITE                           0x00000004UL
@@ -164,7 +153,6 @@
 #define BLK_FILE__SWAPON                          0x00004000UL
 #define BLK_FILE__QUOTAON                         0x00008000UL
 #define BLK_FILE__MOUNTON                         0x00010000UL
-
 #define SOCK_FILE__IOCTL                          0x00000001UL
 #define SOCK_FILE__READ                           0x00000002UL
 #define SOCK_FILE__WRITE                          0x00000004UL
@@ -182,7 +170,6 @@
 #define SOCK_FILE__SWAPON                         0x00004000UL
 #define SOCK_FILE__QUOTAON                        0x00008000UL
 #define SOCK_FILE__MOUNTON                        0x00010000UL
-
 #define FIFO_FILE__IOCTL                          0x00000001UL
 #define FIFO_FILE__READ                           0x00000002UL
 #define FIFO_FILE__WRITE                          0x00000004UL
@@ -200,9 +187,7 @@
 #define FIFO_FILE__SWAPON                         0x00004000UL
 #define FIFO_FILE__QUOTAON                        0x00008000UL
 #define FIFO_FILE__MOUNTON                        0x00010000UL
-
 #define FD__USE                                   0x00000001UL
-
 #define SOCKET__IOCTL                             0x00000001UL
 #define SOCKET__READ                              0x00000002UL
 #define SOCKET__WRITE                             0x00000004UL
@@ -225,7 +210,6 @@
 #define SOCKET__RECV_MSG                          0x00080000UL
 #define SOCKET__SEND_MSG                          0x00100000UL
 #define SOCKET__NAME_BIND                         0x00200000UL
-
 #define TCP_SOCKET__IOCTL                         0x00000001UL
 #define TCP_SOCKET__READ                          0x00000002UL
 #define TCP_SOCKET__WRITE                         0x00000004UL
@@ -248,13 +232,11 @@
 #define TCP_SOCKET__RECV_MSG                      0x00080000UL
 #define TCP_SOCKET__SEND_MSG                      0x00100000UL
 #define TCP_SOCKET__NAME_BIND                     0x00200000UL
-
 #define TCP_SOCKET__CONNECTTO                     0x00400000UL
 #define TCP_SOCKET__NEWCONN                       0x00800000UL
 #define TCP_SOCKET__ACCEPTFROM                    0x01000000UL
 #define TCP_SOCKET__NODE_BIND                     0x02000000UL
 #define TCP_SOCKET__NAME_CONNECT                  0x04000000UL
-
 #define UDP_SOCKET__IOCTL                         0x00000001UL
 #define UDP_SOCKET__READ                          0x00000002UL
 #define UDP_SOCKET__WRITE                         0x00000004UL
@@ -277,9 +259,7 @@
 #define UDP_SOCKET__RECV_MSG                      0x00080000UL
 #define UDP_SOCKET__SEND_MSG                      0x00100000UL
 #define UDP_SOCKET__NAME_BIND                     0x00200000UL
-
 #define UDP_SOCKET__NODE_BIND                     0x00400000UL
-
 #define RAWIP_SOCKET__IOCTL                       0x00000001UL
 #define RAWIP_SOCKET__READ                        0x00000002UL
 #define RAWIP_SOCKET__WRITE                       0x00000004UL
@@ -302,9 +282,7 @@
 #define RAWIP_SOCKET__RECV_MSG                    0x00080000UL
 #define RAWIP_SOCKET__SEND_MSG                    0x00100000UL
 #define RAWIP_SOCKET__NAME_BIND                   0x00200000UL
-
 #define RAWIP_SOCKET__NODE_BIND                   0x00400000UL
-
 #define NODE__TCP_RECV                            0x00000001UL
 #define NODE__TCP_SEND                            0x00000002UL
 #define NODE__UDP_RECV                            0x00000004UL
@@ -312,14 +290,12 @@
 #define NODE__RAWIP_RECV                          0x00000010UL
 #define NODE__RAWIP_SEND                          0x00000020UL
 #define NODE__ENFORCE_DEST                        0x00000040UL
-
 #define NETIF__TCP_RECV                           0x00000001UL
 #define NETIF__TCP_SEND                           0x00000002UL
 #define NETIF__UDP_RECV                           0x00000004UL
 #define NETIF__UDP_SEND                           0x00000008UL
 #define NETIF__RAWIP_RECV                         0x00000010UL
 #define NETIF__RAWIP_SEND                         0x00000020UL
-
 #define NETLINK_SOCKET__IOCTL                     0x00000001UL
 #define NETLINK_SOCKET__READ                      0x00000002UL
 #define NETLINK_SOCKET__WRITE                     0x00000004UL
@@ -342,7 +318,6 @@
 #define NETLINK_SOCKET__RECV_MSG                  0x00080000UL
 #define NETLINK_SOCKET__SEND_MSG                  0x00100000UL
 #define NETLINK_SOCKET__NAME_BIND                 0x00200000UL
-
 #define PACKET_SOCKET__IOCTL                      0x00000001UL
 #define PACKET_SOCKET__READ                       0x00000002UL
 #define PACKET_SOCKET__WRITE                      0x00000004UL
@@ -365,7 +340,6 @@
 #define PACKET_SOCKET__RECV_MSG                   0x00080000UL
 #define PACKET_SOCKET__SEND_MSG                   0x00100000UL
 #define PACKET_SOCKET__NAME_BIND                  0x00200000UL
-
 #define KEY_SOCKET__IOCTL                         0x00000001UL
 #define KEY_SOCKET__READ                          0x00000002UL
 #define KEY_SOCKET__WRITE                         0x00000004UL
@@ -388,7 +362,6 @@
 #define KEY_SOCKET__RECV_MSG                      0x00080000UL
 #define KEY_SOCKET__SEND_MSG                      0x00100000UL
 #define KEY_SOCKET__NAME_BIND                     0x00200000UL
-
 #define UNIX_STREAM_SOCKET__IOCTL                 0x00000001UL
 #define UNIX_STREAM_SOCKET__READ                  0x00000002UL
 #define UNIX_STREAM_SOCKET__WRITE                 0x00000004UL
@@ -411,11 +384,9 @@
 #define UNIX_STREAM_SOCKET__RECV_MSG              0x00080000UL
 #define UNIX_STREAM_SOCKET__SEND_MSG              0x00100000UL
 #define UNIX_STREAM_SOCKET__NAME_BIND             0x00200000UL
-
 #define UNIX_STREAM_SOCKET__CONNECTTO             0x00400000UL
 #define UNIX_STREAM_SOCKET__NEWCONN               0x00800000UL
 #define UNIX_STREAM_SOCKET__ACCEPTFROM            0x01000000UL
-
 #define UNIX_DGRAM_SOCKET__IOCTL                  0x00000001UL
 #define UNIX_DGRAM_SOCKET__READ                   0x00000002UL
 #define UNIX_DGRAM_SOCKET__WRITE                  0x00000004UL
@@ -438,7 +409,6 @@
 #define UNIX_DGRAM_SOCKET__RECV_MSG               0x00080000UL
 #define UNIX_DGRAM_SOCKET__SEND_MSG               0x00100000UL
 #define UNIX_DGRAM_SOCKET__NAME_BIND              0x00200000UL
-
 #define PROCESS__FORK                             0x00000001UL
 #define PROCESS__TRANSITION                       0x00000002UL
 #define PROCESS__SIGCHLD                          0x00000004UL
@@ -468,8 +438,7 @@
 #define PROCESS__EXECSTACK                        0x04000000UL
 #define PROCESS__EXECHEAP                         0x08000000UL
 #define PROCESS__SETKEYCREATE                     0x10000000UL
-#define PROCESS__SETSOCKCREATE                    0x20000000UL
-
+#define PROCESS__TASKFORPID                       0x20000000UL
 #define IPC__CREATE                               0x00000001UL
 #define IPC__DESTROY                              0x00000002UL
 #define IPC__GETATTR                              0x00000004UL
@@ -479,7 +448,6 @@
 #define IPC__ASSOCIATE                            0x00000040UL
 #define IPC__UNIX_READ                            0x00000080UL
 #define IPC__UNIX_WRITE                           0x00000100UL
-
 #define SEM__CREATE                               0x00000001UL
 #define SEM__DESTROY                              0x00000002UL
 #define SEM__GETATTR                              0x00000004UL
@@ -489,7 +457,6 @@
 #define SEM__ASSOCIATE                            0x00000040UL
 #define SEM__UNIX_READ                            0x00000080UL
 #define SEM__UNIX_WRITE                           0x00000100UL
-
 #define MSGQ__CREATE                              0x00000001UL
 #define MSGQ__DESTROY                             0x00000002UL
 #define MSGQ__GETATTR                             0x00000004UL
@@ -499,12 +466,9 @@
 #define MSGQ__ASSOCIATE                           0x00000040UL
 #define MSGQ__UNIX_READ                           0x00000080UL
 #define MSGQ__UNIX_WRITE                          0x00000100UL
-
 #define MSGQ__ENQUEUE                             0x00000200UL
-
 #define MSG__SEND                                 0x00000001UL
 #define MSG__RECEIVE                              0x00000002UL
-
 #define SHM__CREATE                               0x00000001UL
 #define SHM__DESTROY                              0x00000002UL
 #define SHM__GETATTR                              0x00000004UL
@@ -514,9 +478,7 @@
 #define SHM__ASSOCIATE                            0x00000040UL
 #define SHM__UNIX_READ                            0x00000080UL
 #define SHM__UNIX_WRITE                           0x00000100UL
-
 #define SHM__LOCK                                 0x00000200UL
-
 #define SECURITY__COMPUTE_AV                      0x00000001UL
 #define SECURITY__COMPUTE_CREATE                  0x00000002UL
 #define SECURITY__COMPUTE_MEMBER                  0x00000004UL
@@ -528,12 +490,10 @@
 #define SECURITY__SETBOOL                         0x00000100UL
 #define SECURITY__SETSECPARAM                     0x00000200UL
 #define SECURITY__SETCHECKREQPROT                 0x00000400UL
-
 #define SYSTEM__IPC_INFO                          0x00000001UL
 #define SYSTEM__SYSLOG_READ                       0x00000002UL
 #define SYSTEM__SYSLOG_MOD                        0x00000004UL
 #define SYSTEM__SYSLOG_CONSOLE                    0x00000008UL
-
 #define CAPABILITY__CHOWN                         0x00000001UL
 #define CAPABILITY__DAC_OVERRIDE                  0x00000002UL
 #define CAPABILITY__DAC_READ_SEARCH               0x00000004UL
@@ -565,24 +525,20 @@
 #define CAPABILITY__LEASE                         0x10000000UL
 #define CAPABILITY__AUDIT_WRITE                   0x20000000UL
 #define CAPABILITY__AUDIT_CONTROL                 0x40000000UL
-
 #define PASSWD__PASSWD                            0x00000001UL
 #define PASSWD__CHFN                              0x00000002UL
 #define PASSWD__CHSH                              0x00000004UL
 #define PASSWD__ROOTOK                            0x00000008UL
 #define PASSWD__CRONTAB                           0x00000010UL
-
 #define DRAWABLE__CREATE                          0x00000001UL
 #define DRAWABLE__DESTROY                         0x00000002UL
 #define DRAWABLE__DRAW                            0x00000004UL
 #define DRAWABLE__COPY                            0x00000008UL
 #define DRAWABLE__GETATTR                         0x00000010UL
-
 #define GC__CREATE                                0x00000001UL
 #define GC__FREE                                  0x00000002UL
 #define GC__GETATTR                               0x00000004UL
 #define GC__SETATTR                               0x00000008UL
-
 #define WINDOW__ADDCHILD                          0x00000001UL
 #define WINDOW__CREATE                            0x00000002UL
 #define WINDOW__DESTROY                           0x00000004UL
@@ -609,12 +565,10 @@
 #define WINDOW__WINDOWCHANGEREQUEST               0x00800000UL
 #define WINDOW__SERVERCHANGEEVENT                 0x01000000UL
 #define WINDOW__EXTENSIONEVENT                    0x02000000UL
-
 #define FONT__LOAD                                0x00000001UL
 #define FONT__FREE                                0x00000002UL
 #define FONT__GETATTR                             0x00000004UL
 #define FONT__USE                                 0x00000008UL
-
 #define COLORMAP__CREATE                          0x00000001UL
 #define COLORMAP__FREE                            0x00000002UL
 #define COLORMAP__INSTALL                         0x00000004UL
@@ -624,20 +578,16 @@
 #define COLORMAP__STORE                           0x00000040UL
 #define COLORMAP__GETATTR                         0x00000080UL
 #define COLORMAP__SETATTR                         0x00000100UL
-
 #define PROPERTY__CREATE                          0x00000001UL
 #define PROPERTY__FREE                            0x00000002UL
 #define PROPERTY__READ                            0x00000004UL
 #define PROPERTY__WRITE                           0x00000008UL
-
 #define CURSOR__CREATE                            0x00000001UL
 #define CURSOR__CREATEGLYPH                       0x00000002UL
 #define CURSOR__FREE                              0x00000004UL
 #define CURSOR__ASSIGN                            0x00000008UL
 #define CURSOR__SETATTR                           0x00000010UL
-
 #define XCLIENT__KILL                             0x00000001UL
-
 #define XINPUT__LOOKUP                            0x00000001UL
 #define XINPUT__GETATTR                           0x00000002UL
 #define XINPUT__SETATTR                           0x00000004UL
@@ -649,7 +599,6 @@
 #define XINPUT__BELL                              0x00000100UL
 #define XINPUT__MOUSEMOTION                       0x00000200UL
 #define XINPUT__RELABELINPUT                      0x00000400UL
-
 #define XSERVER__SCREENSAVER                      0x00000001UL
 #define XSERVER__GETHOSTLIST                      0x00000002UL
 #define XSERVER__SETHOSTLIST                      0x00000004UL
@@ -658,17 +607,14 @@
 #define XSERVER__GETATTR                          0x00000020UL
 #define XSERVER__GRAB                             0x00000040UL
 #define XSERVER__UNGRAB                           0x00000080UL
-
 #define XEXTENSION__QUERY                         0x00000001UL
 #define XEXTENSION__USE                           0x00000002UL
-
 #define PAX__PAGEEXEC                             0x00000001UL
 #define PAX__EMUTRAMP                             0x00000002UL
 #define PAX__MPROTECT                             0x00000004UL
 #define PAX__RANDMMAP                             0x00000008UL
 #define PAX__RANDEXEC                             0x00000010UL
 #define PAX__SEGMEXEC                             0x00000020UL
-
 #define NETLINK_ROUTE_SOCKET__IOCTL               0x00000001UL
 #define NETLINK_ROUTE_SOCKET__READ                0x00000002UL
 #define NETLINK_ROUTE_SOCKET__WRITE               0x00000004UL
@@ -691,10 +637,8 @@
 #define NETLINK_ROUTE_SOCKET__RECV_MSG            0x00080000UL
 #define NETLINK_ROUTE_SOCKET__SEND_MSG            0x00100000UL
 #define NETLINK_ROUTE_SOCKET__NAME_BIND           0x00200000UL
-
 #define NETLINK_ROUTE_SOCKET__NLMSG_READ          0x00400000UL
 #define NETLINK_ROUTE_SOCKET__NLMSG_WRITE         0x00800000UL
-
 #define NETLINK_FIREWALL_SOCKET__IOCTL            0x00000001UL
 #define NETLINK_FIREWALL_SOCKET__READ             0x00000002UL
 #define NETLINK_FIREWALL_SOCKET__WRITE            0x00000004UL
@@ -717,10 +661,8 @@
 #define NETLINK_FIREWALL_SOCKET__RECV_MSG         0x00080000UL
 #define NETLINK_FIREWALL_SOCKET__SEND_MSG         0x00100000UL
 #define NETLINK_FIREWALL_SOCKET__NAME_BIND        0x00200000UL
-
 #define NETLINK_FIREWALL_SOCKET__NLMSG_READ       0x00400000UL
 #define NETLINK_FIREWALL_SOCKET__NLMSG_WRITE      0x00800000UL
-
 #define NETLINK_TCPDIAG_SOCKET__IOCTL             0x00000001UL
 #define NETLINK_TCPDIAG_SOCKET__READ              0x00000002UL
 #define NETLINK_TCPDIAG_SOCKET__WRITE             0x00000004UL
@@ -743,10 +685,8 @@
 #define NETLINK_TCPDIAG_SOCKET__RECV_MSG          0x00080000UL
 #define NETLINK_TCPDIAG_SOCKET__SEND_MSG          0x00100000UL
 #define NETLINK_TCPDIAG_SOCKET__NAME_BIND         0x00200000UL
-
 #define NETLINK_TCPDIAG_SOCKET__NLMSG_READ        0x00400000UL
 #define NETLINK_TCPDIAG_SOCKET__NLMSG_WRITE       0x00800000UL
-
 #define NETLINK_NFLOG_SOCKET__IOCTL               0x00000001UL
 #define NETLINK_NFLOG_SOCKET__READ                0x00000002UL
 #define NETLINK_NFLOG_SOCKET__WRITE               0x00000004UL
@@ -769,7 +709,6 @@
 #define NETLINK_NFLOG_SOCKET__RECV_MSG            0x00080000UL
 #define NETLINK_NFLOG_SOCKET__SEND_MSG            0x00100000UL
 #define NETLINK_NFLOG_SOCKET__NAME_BIND           0x00200000UL
-
 #define NETLINK_XFRM_SOCKET__IOCTL                0x00000001UL
 #define NETLINK_XFRM_SOCKET__READ                 0x00000002UL
 #define NETLINK_XFRM_SOCKET__WRITE                0x00000004UL
@@ -792,10 +731,8 @@
 #define NETLINK_XFRM_SOCKET__RECV_MSG             0x00080000UL
 #define NETLINK_XFRM_SOCKET__SEND_MSG             0x00100000UL
 #define NETLINK_XFRM_SOCKET__NAME_BIND            0x00200000UL
-
 #define NETLINK_XFRM_SOCKET__NLMSG_READ           0x00400000UL
 #define NETLINK_XFRM_SOCKET__NLMSG_WRITE          0x00800000UL
-
 #define NETLINK_SELINUX_SOCKET__IOCTL             0x00000001UL
 #define NETLINK_SELINUX_SOCKET__READ              0x00000002UL
 #define NETLINK_SELINUX_SOCKET__WRITE             0x00000004UL
@@ -818,7 +755,6 @@
 #define NETLINK_SELINUX_SOCKET__RECV_MSG          0x00080000UL
 #define NETLINK_SELINUX_SOCKET__SEND_MSG          0x00100000UL
 #define NETLINK_SELINUX_SOCKET__NAME_BIND         0x00200000UL
-
 #define NETLINK_AUDIT_SOCKET__IOCTL               0x00000001UL
 #define NETLINK_AUDIT_SOCKET__READ                0x00000002UL
 #define NETLINK_AUDIT_SOCKET__WRITE               0x00000004UL
@@ -841,12 +777,10 @@
 #define NETLINK_AUDIT_SOCKET__RECV_MSG            0x00080000UL
 #define NETLINK_AUDIT_SOCKET__SEND_MSG            0x00100000UL
 #define NETLINK_AUDIT_SOCKET__NAME_BIND           0x00200000UL
-
 #define NETLINK_AUDIT_SOCKET__NLMSG_READ          0x00400000UL
 #define NETLINK_AUDIT_SOCKET__NLMSG_WRITE         0x00800000UL
 #define NETLINK_AUDIT_SOCKET__NLMSG_RELAY         0x01000000UL
 #define NETLINK_AUDIT_SOCKET__NLMSG_READPRIV      0x02000000UL
-
 #define NETLINK_IP6FW_SOCKET__IOCTL               0x00000001UL
 #define NETLINK_IP6FW_SOCKET__READ                0x00000002UL
 #define NETLINK_IP6FW_SOCKET__WRITE               0x00000004UL
@@ -869,10 +803,8 @@
 #define NETLINK_IP6FW_SOCKET__RECV_MSG            0x00080000UL
 #define NETLINK_IP6FW_SOCKET__SEND_MSG            0x00100000UL
 #define NETLINK_IP6FW_SOCKET__NAME_BIND           0x00200000UL
-
 #define NETLINK_IP6FW_SOCKET__NLMSG_READ          0x00400000UL
 #define NETLINK_IP6FW_SOCKET__NLMSG_WRITE         0x00800000UL
-
 #define NETLINK_DNRT_SOCKET__IOCTL                0x00000001UL
 #define NETLINK_DNRT_SOCKET__READ                 0x00000002UL
 #define NETLINK_DNRT_SOCKET__WRITE                0x00000004UL
@@ -895,10 +827,8 @@
 #define NETLINK_DNRT_SOCKET__RECV_MSG             0x00080000UL
 #define NETLINK_DNRT_SOCKET__SEND_MSG             0x00100000UL
 #define NETLINK_DNRT_SOCKET__NAME_BIND            0x00200000UL
-
 #define DBUS__ACQUIRE_SVC                         0x00000001UL
 #define DBUS__SEND_MSG                            0x00000002UL
-
 #define NSCD__GETPWD                              0x00000001UL
 #define NSCD__GETGRP                              0x00000002UL
 #define NSCD__GETHOST                             0x00000004UL
@@ -907,12 +837,10 @@
 #define NSCD__SHMEMPWD                            0x00000020UL
 #define NSCD__SHMEMGRP                            0x00000040UL
 #define NSCD__SHMEMHOST                           0x00000080UL
-
 #define ASSOCIATION__SENDTO                       0x00000001UL
 #define ASSOCIATION__RECVFROM                     0x00000002UL
 #define ASSOCIATION__SETCONTEXT                   0x00000004UL
 #define ASSOCIATION__POLMATCH                     0x00000008UL
-
 #define NETLINK_KOBJECT_UEVENT_SOCKET__IOCTL      0x00000001UL
 #define NETLINK_KOBJECT_UEVENT_SOCKET__READ       0x00000002UL
 #define NETLINK_KOBJECT_UEVENT_SOCKET__WRITE      0x00000004UL
@@ -935,7 +863,6 @@
 #define NETLINK_KOBJECT_UEVENT_SOCKET__RECV_MSG   0x00080000UL
 #define NETLINK_KOBJECT_UEVENT_SOCKET__SEND_MSG   0x00100000UL
 #define NETLINK_KOBJECT_UEVENT_SOCKET__NAME_BIND  0x00200000UL
-
 #define APPLETALK_SOCKET__IOCTL                   0x00000001UL
 #define APPLETALK_SOCKET__READ                    0x00000002UL
 #define APPLETALK_SOCKET__WRITE                   0x00000004UL
@@ -958,11 +885,9 @@
 #define APPLETALK_SOCKET__RECV_MSG                0x00080000UL
 #define APPLETALK_SOCKET__SEND_MSG                0x00100000UL
 #define APPLETALK_SOCKET__NAME_BIND               0x00200000UL
-
 #define PACKET__SEND                              0x00000001UL
 #define PACKET__RECV                              0x00000002UL
 #define PACKET__RELABELTO                         0x00000004UL
-
 #define KEY__VIEW                                 0x00000001UL
 #define KEY__READ                                 0x00000002UL
 #define KEY__WRITE                                0x00000004UL
@@ -970,3 +895,18 @@
 #define KEY__LINK                                 0x00000010UL
 #define KEY__SETATTR                              0x00000020UL
 #define KEY__CREATE                               0x00000040UL
+#define MACH_PORT__RELABELFROM                    0x00000001UL
+#define MACH_PORT__RELABELTO                      0x00000002UL
+#define MACH_PORT__SEND                           0x00000004UL
+#define MACH_PORT__RECV                           0x00000008UL
+#define MACH_PORT__MAKE_SEND                      0x00000010UL
+#define MACH_PORT__MAKE_SEND_ONCE                 0x00000020UL
+#define MACH_PORT__COPY_SEND                      0x00000040UL
+#define MACH_PORT__MOVE_SEND                      0x00000080UL
+#define MACH_PORT__MOVE_SEND_ONCE                 0x00000100UL
+#define MACH_PORT__MOVE_RECV                      0x00000200UL
+#define MACH_PORT__HOLD_SEND                      0x00000400UL
+#define MACH_PORT__HOLD_SEND_ONCE                 0x00000800UL
+#define MACH_PORT__HOLD_RECV                      0x00001000UL
+#define MACH_TASK__TERMINATE                      0x00000001UL
+#define MACH_TASK__SET_SPECIAL_PORT               0x00000002UL

==== //depot/projects/trustedbsd/sedarwin8/policies/sedarwin/libselinux/include/selinux/flask.h#3 (text+ko) ====

@@ -63,6 +63,8 @@
 #define SECCLASS_APPLETALK_SOCKET                        56
 #define SECCLASS_PACKET                                  57
 #define SECCLASS_KEY                                     58
+#define SECCLASS_MACH_PORT                               59
+#define SECCLASS_MACH_TASK                               60
 
 /*
  * Security identifier indices for initial entities
@@ -94,7 +96,8 @@
 #define SECINITSID_POLICY                               25
 #define SECINITSID_SCMP_PACKET                          26
 #define SECINITSID_DEVNULL                              27
+#define SECINITSID_DEVFS                                28
 
-#define SECINITSID_NUM                                  27
+#define SECINITSID_NUM                                  28
 
 #endif

==== //depot/projects/trustedbsd/sedarwin8/policies/sedarwin/libselinux/src/av_inherit.h#3 (text+ko) ====

@@ -1,32 +1,32 @@
 /* This file is automatically generated.  Do not edit. */
-S_(SECCLASS_DIR, file, 0x00020000UL)
-    S_(SECCLASS_FILE, file, 0x00020000UL)
-    S_(SECCLASS_LNK_FILE, file, 0x00020000UL)
-    S_(SECCLASS_CHR_FILE, file, 0x00020000UL)
-    S_(SECCLASS_BLK_FILE, file, 0x00020000UL)
-    S_(SECCLASS_SOCK_FILE, file, 0x00020000UL)
-    S_(SECCLASS_FIFO_FILE, file, 0x00020000UL)
-    S_(SECCLASS_SOCKET, socket, 0x00400000UL)
-    S_(SECCLASS_TCP_SOCKET, socket, 0x00400000UL)
-    S_(SECCLASS_UDP_SOCKET, socket, 0x00400000UL)
-    S_(SECCLASS_RAWIP_SOCKET, socket, 0x00400000UL)
-    S_(SECCLASS_NETLINK_SOCKET, socket, 0x00400000UL)
-    S_(SECCLASS_PACKET_SOCKET, socket, 0x00400000UL)
-    S_(SECCLASS_KEY_SOCKET, socket, 0x00400000UL)
-    S_(SECCLASS_UNIX_STREAM_SOCKET, socket, 0x00400000UL)
-    S_(SECCLASS_UNIX_DGRAM_SOCKET, socket, 0x00400000UL)
-    S_(SECCLASS_IPC, ipc, 0x00000200UL)
-    S_(SECCLASS_SEM, ipc, 0x00000200UL)
-    S_(SECCLASS_MSGQ, ipc, 0x00000200UL)
-    S_(SECCLASS_SHM, ipc, 0x00000200UL)
-    S_(SECCLASS_NETLINK_ROUTE_SOCKET, socket, 0x00400000UL)
-    S_(SECCLASS_NETLINK_FIREWALL_SOCKET, socket, 0x00400000UL)
-    S_(SECCLASS_NETLINK_TCPDIAG_SOCKET, socket, 0x00400000UL)
-    S_(SECCLASS_NETLINK_NFLOG_SOCKET, socket, 0x00400000UL)
-    S_(SECCLASS_NETLINK_XFRM_SOCKET, socket, 0x00400000UL)
-    S_(SECCLASS_NETLINK_SELINUX_SOCKET, socket, 0x00400000UL)
-    S_(SECCLASS_NETLINK_AUDIT_SOCKET, socket, 0x00400000UL)
-    S_(SECCLASS_NETLINK_IP6FW_SOCKET, socket, 0x00400000UL)
-    S_(SECCLASS_NETLINK_DNRT_SOCKET, socket, 0x00400000UL)
-    S_(SECCLASS_NETLINK_KOBJECT_UEVENT_SOCKET, socket, 0x00400000UL)
-    S_(SECCLASS_APPLETALK_SOCKET, socket, 0x00400000UL)
+   S_(SECCLASS_DIR, file, 0x00020000UL)
+   S_(SECCLASS_FILE, file, 0x00020000UL)
+   S_(SECCLASS_LNK_FILE, file, 0x00020000UL)
+   S_(SECCLASS_CHR_FILE, file, 0x00020000UL)
+   S_(SECCLASS_BLK_FILE, file, 0x00020000UL)
+   S_(SECCLASS_SOCK_FILE, file, 0x00020000UL)
+   S_(SECCLASS_FIFO_FILE, file, 0x00020000UL)
+   S_(SECCLASS_SOCKET, socket, 0x00400000UL)
+   S_(SECCLASS_TCP_SOCKET, socket, 0x00400000UL)
+   S_(SECCLASS_UDP_SOCKET, socket, 0x00400000UL)
+   S_(SECCLASS_RAWIP_SOCKET, socket, 0x00400000UL)
+   S_(SECCLASS_NETLINK_SOCKET, socket, 0x00400000UL)
+   S_(SECCLASS_PACKET_SOCKET, socket, 0x00400000UL)
+   S_(SECCLASS_KEY_SOCKET, socket, 0x00400000UL)
+   S_(SECCLASS_UNIX_STREAM_SOCKET, socket, 0x00400000UL)
+   S_(SECCLASS_UNIX_DGRAM_SOCKET, socket, 0x00400000UL)
+   S_(SECCLASS_IPC, ipc, 0x00000200UL)
+   S_(SECCLASS_SEM, ipc, 0x00000200UL)
+   S_(SECCLASS_MSGQ, ipc, 0x00000200UL)
+   S_(SECCLASS_SHM, ipc, 0x00000200UL)
+   S_(SECCLASS_NETLINK_ROUTE_SOCKET, socket, 0x00400000UL)
+   S_(SECCLASS_NETLINK_FIREWALL_SOCKET, socket, 0x00400000UL)
+   S_(SECCLASS_NETLINK_TCPDIAG_SOCKET, socket, 0x00400000UL)
+   S_(SECCLASS_NETLINK_NFLOG_SOCKET, socket, 0x00400000UL)
+   S_(SECCLASS_NETLINK_XFRM_SOCKET, socket, 0x00400000UL)
+   S_(SECCLASS_NETLINK_SELINUX_SOCKET, socket, 0x00400000UL)
+   S_(SECCLASS_NETLINK_AUDIT_SOCKET, socket, 0x00400000UL)
+   S_(SECCLASS_NETLINK_IP6FW_SOCKET, socket, 0x00400000UL)
+   S_(SECCLASS_NETLINK_DNRT_SOCKET, socket, 0x00400000UL)
+   S_(SECCLASS_NETLINK_KOBJECT_UEVENT_SOCKET, socket, 0x00400000UL)
+   S_(SECCLASS_APPLETALK_SOCKET, socket, 0x00400000UL)

==== //depot/projects/trustedbsd/sedarwin8/policies/sedarwin/libselinux/src/av_perm_to_string.h#3 (text+ko) ====

@@ -1,265 +1,269 @@
 /* This file is automatically generated.  Do not edit. */
-S_(SECCLASS_FILESYSTEM, FILESYSTEM__MOUNT, "mount")
-    S_(SECCLASS_FILESYSTEM, FILESYSTEM__REMOUNT, "remount")
-    S_(SECCLASS_FILESYSTEM, FILESYSTEM__UNMOUNT, "unmount")
-    S_(SECCLASS_FILESYSTEM, FILESYSTEM__GETATTR, "getattr")
-    S_(SECCLASS_FILESYSTEM, FILESYSTEM__RELABELFROM, "relabelfrom")
-    S_(SECCLASS_FILESYSTEM, FILESYSTEM__RELABELTO, "relabelto")
-    S_(SECCLASS_FILESYSTEM, FILESYSTEM__TRANSITION, "transition")
-    S_(SECCLASS_FILESYSTEM, FILESYSTEM__ASSOCIATE, "associate")
-    S_(SECCLASS_FILESYSTEM, FILESYSTEM__QUOTAMOD, "quotamod")
-    S_(SECCLASS_FILESYSTEM, FILESYSTEM__QUOTAGET, "quotaget")
-    S_(SECCLASS_DIR, DIR__ADD_NAME, "add_name")
-    S_(SECCLASS_DIR, DIR__REMOVE_NAME, "remove_name")
-    S_(SECCLASS_DIR, DIR__REPARENT, "reparent")
-    S_(SECCLASS_DIR, DIR__SEARCH, "search")
-    S_(SECCLASS_DIR, DIR__RMDIR, "rmdir")
-    S_(SECCLASS_FILE, FILE__EXECUTE_NO_TRANS, "execute_no_trans")
-    S_(SECCLASS_FILE, FILE__ENTRYPOINT, "entrypoint")
-    S_(SECCLASS_FILE, FILE__EXECMOD, "execmod")
-    S_(SECCLASS_CHR_FILE, CHR_FILE__EXECUTE_NO_TRANS, "execute_no_trans")
-    S_(SECCLASS_CHR_FILE, CHR_FILE__ENTRYPOINT, "entrypoint")
-    S_(SECCLASS_CHR_FILE, CHR_FILE__EXECMOD, "execmod")
-    S_(SECCLASS_FD, FD__USE, "use")
-    S_(SECCLASS_TCP_SOCKET, TCP_SOCKET__CONNECTTO, "connectto")
-    S_(SECCLASS_TCP_SOCKET, TCP_SOCKET__NEWCONN, "newconn")
-    S_(SECCLASS_TCP_SOCKET, TCP_SOCKET__ACCEPTFROM, "acceptfrom")
-    S_(SECCLASS_TCP_SOCKET, TCP_SOCKET__NODE_BIND, "node_bind")
-    S_(SECCLASS_TCP_SOCKET, TCP_SOCKET__NAME_CONNECT, "name_connect")
-    S_(SECCLASS_UDP_SOCKET, UDP_SOCKET__NODE_BIND, "node_bind")
-    S_(SECCLASS_RAWIP_SOCKET, RAWIP_SOCKET__NODE_BIND, "node_bind")
-    S_(SECCLASS_NODE, NODE__TCP_RECV, "tcp_recv")
-    S_(SECCLASS_NODE, NODE__TCP_SEND, "tcp_send")
-    S_(SECCLASS_NODE, NODE__UDP_RECV, "udp_recv")
-    S_(SECCLASS_NODE, NODE__UDP_SEND, "udp_send")
-    S_(SECCLASS_NODE, NODE__RAWIP_RECV, "rawip_recv")
-    S_(SECCLASS_NODE, NODE__RAWIP_SEND, "rawip_send")
-    S_(SECCLASS_NODE, NODE__ENFORCE_DEST, "enforce_dest")
-    S_(SECCLASS_NETIF, NETIF__TCP_RECV, "tcp_recv")
-    S_(SECCLASS_NETIF, NETIF__TCP_SEND, "tcp_send")
-    S_(SECCLASS_NETIF, NETIF__UDP_RECV, "udp_recv")
-    S_(SECCLASS_NETIF, NETIF__UDP_SEND, "udp_send")
-    S_(SECCLASS_NETIF, NETIF__RAWIP_RECV, "rawip_recv")
-    S_(SECCLASS_NETIF, NETIF__RAWIP_SEND, "rawip_send")
-    S_(SECCLASS_UNIX_STREAM_SOCKET, UNIX_STREAM_SOCKET__CONNECTTO, "connectto")
-    S_(SECCLASS_UNIX_STREAM_SOCKET, UNIX_STREAM_SOCKET__NEWCONN, "newconn")
-    S_(SECCLASS_UNIX_STREAM_SOCKET, UNIX_STREAM_SOCKET__ACCEPTFROM, "acceptfrom")
-    S_(SECCLASS_PROCESS, PROCESS__FORK, "fork")
-    S_(SECCLASS_PROCESS, PROCESS__TRANSITION, "transition")
-    S_(SECCLASS_PROCESS, PROCESS__SIGCHLD, "sigchld")
-    S_(SECCLASS_PROCESS, PROCESS__SIGKILL, "sigkill")
-    S_(SECCLASS_PROCESS, PROCESS__SIGSTOP, "sigstop")
-    S_(SECCLASS_PROCESS, PROCESS__SIGNULL, "signull")
-    S_(SECCLASS_PROCESS, PROCESS__SIGNAL, "signal")
-    S_(SECCLASS_PROCESS, PROCESS__PTRACE, "ptrace")
-    S_(SECCLASS_PROCESS, PROCESS__GETSCHED, "getsched")
-    S_(SECCLASS_PROCESS, PROCESS__SETSCHED, "setsched")
-    S_(SECCLASS_PROCESS, PROCESS__GETSESSION, "getsession")
-    S_(SECCLASS_PROCESS, PROCESS__GETPGID, "getpgid")
-    S_(SECCLASS_PROCESS, PROCESS__SETPGID, "setpgid")
-    S_(SECCLASS_PROCESS, PROCESS__GETCAP, "getcap")
-    S_(SECCLASS_PROCESS, PROCESS__SETCAP, "setcap")
-    S_(SECCLASS_PROCESS, PROCESS__SHARE, "share")
-    S_(SECCLASS_PROCESS, PROCESS__GETATTR, "getattr")
-    S_(SECCLASS_PROCESS, PROCESS__SETEXEC, "setexec")
-    S_(SECCLASS_PROCESS, PROCESS__SETFSCREATE, "setfscreate")
-    S_(SECCLASS_PROCESS, PROCESS__NOATSECURE, "noatsecure")
-    S_(SECCLASS_PROCESS, PROCESS__SIGINH, "siginh")
-    S_(SECCLASS_PROCESS, PROCESS__SETRLIMIT, "setrlimit")
-    S_(SECCLASS_PROCESS, PROCESS__RLIMITINH, "rlimitinh")
-    S_(SECCLASS_PROCESS, PROCESS__DYNTRANSITION, "dyntransition")
-    S_(SECCLASS_PROCESS, PROCESS__SETCURRENT, "setcurrent")
-    S_(SECCLASS_PROCESS, PROCESS__EXECMEM, "execmem")
-    S_(SECCLASS_PROCESS, PROCESS__EXECSTACK, "execstack")
-    S_(SECCLASS_PROCESS, PROCESS__EXECHEAP, "execheap")
-    S_(SECCLASS_PROCESS, PROCESS__SETKEYCREATE, "setkeycreate")
-    S_(SECCLASS_MSGQ, MSGQ__ENQUEUE, "enqueue")
-    S_(SECCLASS_MSG, MSG__SEND, "send")
-    S_(SECCLASS_MSG, MSG__RECEIVE, "receive")
-    S_(SECCLASS_SHM, SHM__LOCK, "lock")
-    S_(SECCLASS_SECURITY, SECURITY__COMPUTE_AV, "compute_av")
-    S_(SECCLASS_SECURITY, SECURITY__COMPUTE_CREATE, "compute_create")
-    S_(SECCLASS_SECURITY, SECURITY__COMPUTE_MEMBER, "compute_member")
-    S_(SECCLASS_SECURITY, SECURITY__CHECK_CONTEXT, "check_context")
-    S_(SECCLASS_SECURITY, SECURITY__LOAD_POLICY, "load_policy")
-    S_(SECCLASS_SECURITY, SECURITY__COMPUTE_RELABEL, "compute_relabel")
-    S_(SECCLASS_SECURITY, SECURITY__COMPUTE_USER, "compute_user")
-    S_(SECCLASS_SECURITY, SECURITY__SETENFORCE, "setenforce")
-    S_(SECCLASS_SECURITY, SECURITY__SETBOOL, "setbool")
-    S_(SECCLASS_SECURITY, SECURITY__SETSECPARAM, "setsecparam")
-    S_(SECCLASS_SECURITY, SECURITY__SETCHECKREQPROT, "setcheckreqprot")
-    S_(SECCLASS_SYSTEM, SYSTEM__IPC_INFO, "ipc_info")
-    S_(SECCLASS_SYSTEM, SYSTEM__SYSLOG_READ, "syslog_read")
-    S_(SECCLASS_SYSTEM, SYSTEM__SYSLOG_MOD, "syslog_mod")
-    S_(SECCLASS_SYSTEM, SYSTEM__SYSLOG_CONSOLE, "syslog_console")
-    S_(SECCLASS_CAPABILITY, CAPABILITY__CHOWN, "chown")
-    S_(SECCLASS_CAPABILITY, CAPABILITY__DAC_OVERRIDE, "dac_override")
-    S_(SECCLASS_CAPABILITY, CAPABILITY__DAC_READ_SEARCH, "dac_read_search")
-    S_(SECCLASS_CAPABILITY, CAPABILITY__FOWNER, "fowner")
-    S_(SECCLASS_CAPABILITY, CAPABILITY__FSETID, "fsetid")
-    S_(SECCLASS_CAPABILITY, CAPABILITY__KILL, "kill")
-    S_(SECCLASS_CAPABILITY, CAPABILITY__SETGID, "setgid")
-    S_(SECCLASS_CAPABILITY, CAPABILITY__SETUID, "setuid")
-    S_(SECCLASS_CAPABILITY, CAPABILITY__SETPCAP, "setpcap")
-    S_(SECCLASS_CAPABILITY, CAPABILITY__LINUX_IMMUTABLE, "linux_immutable")
-    S_(SECCLASS_CAPABILITY, CAPABILITY__NET_BIND_SERVICE, "net_bind_service")
-    S_(SECCLASS_CAPABILITY, CAPABILITY__NET_BROADCAST, "net_broadcast")
-    S_(SECCLASS_CAPABILITY, CAPABILITY__NET_ADMIN, "net_admin")
-    S_(SECCLASS_CAPABILITY, CAPABILITY__NET_RAW, "net_raw")
-    S_(SECCLASS_CAPABILITY, CAPABILITY__IPC_LOCK, "ipc_lock")
-    S_(SECCLASS_CAPABILITY, CAPABILITY__IPC_OWNER, "ipc_owner")
-    S_(SECCLASS_CAPABILITY, CAPABILITY__SYS_MODULE, "sys_module")
-    S_(SECCLASS_CAPABILITY, CAPABILITY__SYS_RAWIO, "sys_rawio")
-    S_(SECCLASS_CAPABILITY, CAPABILITY__SYS_CHROOT, "sys_chroot")
-    S_(SECCLASS_CAPABILITY, CAPABILITY__SYS_PTRACE, "sys_ptrace")
-    S_(SECCLASS_CAPABILITY, CAPABILITY__SYS_PACCT, "sys_pacct")
-    S_(SECCLASS_CAPABILITY, CAPABILITY__SYS_ADMIN, "sys_admin")
-    S_(SECCLASS_CAPABILITY, CAPABILITY__SYS_BOOT, "sys_boot")
-    S_(SECCLASS_CAPABILITY, CAPABILITY__SYS_NICE, "sys_nice")
-    S_(SECCLASS_CAPABILITY, CAPABILITY__SYS_RESOURCE, "sys_resource")
-    S_(SECCLASS_CAPABILITY, CAPABILITY__SYS_TIME, "sys_time")
-    S_(SECCLASS_CAPABILITY, CAPABILITY__SYS_TTY_CONFIG, "sys_tty_config")
-    S_(SECCLASS_CAPABILITY, CAPABILITY__MKNOD, "mknod")
-    S_(SECCLASS_CAPABILITY, CAPABILITY__LEASE, "lease")
-    S_(SECCLASS_CAPABILITY, CAPABILITY__AUDIT_WRITE, "audit_write")
-    S_(SECCLASS_CAPABILITY, CAPABILITY__AUDIT_CONTROL, "audit_control")
-    S_(SECCLASS_PASSWD, PASSWD__PASSWD, "passwd")
-    S_(SECCLASS_PASSWD, PASSWD__CHFN, "chfn")
-    S_(SECCLASS_PASSWD, PASSWD__CHSH, "chsh")
-    S_(SECCLASS_PASSWD, PASSWD__ROOTOK, "rootok")
-    S_(SECCLASS_PASSWD, PASSWD__CRONTAB, "crontab")
-    S_(SECCLASS_DRAWABLE, DRAWABLE__CREATE, "create")
-    S_(SECCLASS_DRAWABLE, DRAWABLE__DESTROY, "destroy")
-    S_(SECCLASS_DRAWABLE, DRAWABLE__DRAW, "draw")
-    S_(SECCLASS_DRAWABLE, DRAWABLE__COPY, "copy")
-    S_(SECCLASS_DRAWABLE, DRAWABLE__GETATTR, "getattr")
-    S_(SECCLASS_GC, GC__CREATE, "create")
-    S_(SECCLASS_GC, GC__FREE, "free")
-    S_(SECCLASS_GC, GC__GETATTR, "getattr")
-    S_(SECCLASS_GC, GC__SETATTR, "setattr")
-    S_(SECCLASS_WINDOW, WINDOW__ADDCHILD, "addchild")
-    S_(SECCLASS_WINDOW, WINDOW__CREATE, "create")
-    S_(SECCLASS_WINDOW, WINDOW__DESTROY, "destroy")
-    S_(SECCLASS_WINDOW, WINDOW__MAP, "map")
-    S_(SECCLASS_WINDOW, WINDOW__UNMAP, "unmap")
-    S_(SECCLASS_WINDOW, WINDOW__CHSTACK, "chstack")
-    S_(SECCLASS_WINDOW, WINDOW__CHPROPLIST, "chproplist")
-    S_(SECCLASS_WINDOW, WINDOW__CHPROP, "chprop")
-    S_(SECCLASS_WINDOW, WINDOW__LISTPROP, "listprop")
-    S_(SECCLASS_WINDOW, WINDOW__GETATTR, "getattr")
-    S_(SECCLASS_WINDOW, WINDOW__SETATTR, "setattr")
-    S_(SECCLASS_WINDOW, WINDOW__SETFOCUS, "setfocus")
-    S_(SECCLASS_WINDOW, WINDOW__MOVE, "move")
-    S_(SECCLASS_WINDOW, WINDOW__CHSELECTION, "chselection")
-    S_(SECCLASS_WINDOW, WINDOW__CHPARENT, "chparent")
-    S_(SECCLASS_WINDOW, WINDOW__CTRLLIFE, "ctrllife")
-    S_(SECCLASS_WINDOW, WINDOW__ENUMERATE, "enumerate")
-    S_(SECCLASS_WINDOW, WINDOW__TRANSPARENT, "transparent")
-    S_(SECCLASS_WINDOW, WINDOW__MOUSEMOTION, "mousemotion")
-    S_(SECCLASS_WINDOW, WINDOW__CLIENTCOMEVENT, "clientcomevent")
-    S_(SECCLASS_WINDOW, WINDOW__INPUTEVENT, "inputevent")
-    S_(SECCLASS_WINDOW, WINDOW__DRAWEVENT, "drawevent")
-    S_(SECCLASS_WINDOW, WINDOW__WINDOWCHANGEEVENT, "windowchangeevent")
-    S_(SECCLASS_WINDOW, WINDOW__WINDOWCHANGEREQUEST, "windowchangerequest")
-    S_(SECCLASS_WINDOW, WINDOW__SERVERCHANGEEVENT, "serverchangeevent")
-    S_(SECCLASS_WINDOW, WINDOW__EXTENSIONEVENT, "extensionevent")
-    S_(SECCLASS_FONT, FONT__LOAD, "load")
-    S_(SECCLASS_FONT, FONT__FREE, "free")
-    S_(SECCLASS_FONT, FONT__GETATTR, "getattr")
-    S_(SECCLASS_FONT, FONT__USE, "use")
-    S_(SECCLASS_COLORMAP, COLORMAP__CREATE, "create")
-    S_(SECCLASS_COLORMAP, COLORMAP__FREE, "free")
-    S_(SECCLASS_COLORMAP, COLORMAP__INSTALL, "install")
-    S_(SECCLASS_COLORMAP, COLORMAP__UNINSTALL, "uninstall")
-    S_(SECCLASS_COLORMAP, COLORMAP__LIST, "list")
-    S_(SECCLASS_COLORMAP, COLORMAP__READ, "read")
-    S_(SECCLASS_COLORMAP, COLORMAP__STORE, "store")
-    S_(SECCLASS_COLORMAP, COLORMAP__GETATTR, "getattr")
-    S_(SECCLASS_COLORMAP, COLORMAP__SETATTR, "setattr")
-    S_(SECCLASS_PROPERTY, PROPERTY__CREATE, "create")
-    S_(SECCLASS_PROPERTY, PROPERTY__FREE, "free")
-    S_(SECCLASS_PROPERTY, PROPERTY__READ, "read")
-    S_(SECCLASS_PROPERTY, PROPERTY__WRITE, "write")
-    S_(SECCLASS_CURSOR, CURSOR__CREATE, "create")
-    S_(SECCLASS_CURSOR, CURSOR__CREATEGLYPH, "createglyph")
-    S_(SECCLASS_CURSOR, CURSOR__FREE, "free")
-    S_(SECCLASS_CURSOR, CURSOR__ASSIGN, "assign")
-    S_(SECCLASS_CURSOR, CURSOR__SETATTR, "setattr")
-    S_(SECCLASS_XCLIENT, XCLIENT__KILL, "kill")
-    S_(SECCLASS_XINPUT, XINPUT__LOOKUP, "lookup")
-    S_(SECCLASS_XINPUT, XINPUT__GETATTR, "getattr")
-    S_(SECCLASS_XINPUT, XINPUT__SETATTR, "setattr")
-    S_(SECCLASS_XINPUT, XINPUT__SETFOCUS, "setfocus")
-    S_(SECCLASS_XINPUT, XINPUT__WARPPOINTER, "warppointer")
-    S_(SECCLASS_XINPUT, XINPUT__ACTIVEGRAB, "activegrab")
-    S_(SECCLASS_XINPUT, XINPUT__PASSIVEGRAB, "passivegrab")
-    S_(SECCLASS_XINPUT, XINPUT__UNGRAB, "ungrab")
-    S_(SECCLASS_XINPUT, XINPUT__BELL, "bell")
-    S_(SECCLASS_XINPUT, XINPUT__MOUSEMOTION, "mousemotion")
-    S_(SECCLASS_XINPUT, XINPUT__RELABELINPUT, "relabelinput")
-    S_(SECCLASS_XSERVER, XSERVER__SCREENSAVER, "screensaver")
-    S_(SECCLASS_XSERVER, XSERVER__GETHOSTLIST, "gethostlist")
-    S_(SECCLASS_XSERVER, XSERVER__SETHOSTLIST, "sethostlist")
-    S_(SECCLASS_XSERVER, XSERVER__GETFONTPATH, "getfontpath")
-    S_(SECCLASS_XSERVER, XSERVER__SETFONTPATH, "setfontpath")
-    S_(SECCLASS_XSERVER, XSERVER__GETATTR, "getattr")
-    S_(SECCLASS_XSERVER, XSERVER__GRAB, "grab")
-    S_(SECCLASS_XSERVER, XSERVER__UNGRAB, "ungrab")
-    S_(SECCLASS_XEXTENSION, XEXTENSION__QUERY, "query")
-    S_(SECCLASS_XEXTENSION, XEXTENSION__USE, "use")
-    S_(SECCLASS_PAX, PAX__PAGEEXEC, "pageexec")
-    S_(SECCLASS_PAX, PAX__EMUTRAMP, "emutramp")
-    S_(SECCLASS_PAX, PAX__MPROTECT, "mprotect")
-    S_(SECCLASS_PAX, PAX__RANDMMAP, "randmmap")
-    S_(SECCLASS_PAX, PAX__RANDEXEC, "randexec")
-    S_(SECCLASS_PAX, PAX__SEGMEXEC, "segmexec")
-    S_(SECCLASS_NETLINK_ROUTE_SOCKET, NETLINK_ROUTE_SOCKET__NLMSG_READ,
-   "nlmsg_read")
-    S_(SECCLASS_NETLINK_ROUTE_SOCKET, NETLINK_ROUTE_SOCKET__NLMSG_WRITE,
-   "nlmsg_write")
-    S_(SECCLASS_NETLINK_FIREWALL_SOCKET, NETLINK_FIREWALL_SOCKET__NLMSG_READ,
-   "nlmsg_read")
-    S_(SECCLASS_NETLINK_FIREWALL_SOCKET, NETLINK_FIREWALL_SOCKET__NLMSG_WRITE,
-   "nlmsg_write")
-    S_(SECCLASS_NETLINK_TCPDIAG_SOCKET, NETLINK_TCPDIAG_SOCKET__NLMSG_READ,
-   "nlmsg_read")
-    S_(SECCLASS_NETLINK_TCPDIAG_SOCKET, NETLINK_TCPDIAG_SOCKET__NLMSG_WRITE,
-   "nlmsg_write")
-    S_(SECCLASS_NETLINK_XFRM_SOCKET, NETLINK_XFRM_SOCKET__NLMSG_READ, "nlmsg_read")
-    S_(SECCLASS_NETLINK_XFRM_SOCKET, NETLINK_XFRM_SOCKET__NLMSG_WRITE,
-   "nlmsg_write")
-    S_(SECCLASS_NETLINK_AUDIT_SOCKET, NETLINK_AUDIT_SOCKET__NLMSG_READ,
-   "nlmsg_read")
-    S_(SECCLASS_NETLINK_AUDIT_SOCKET, NETLINK_AUDIT_SOCKET__NLMSG_WRITE,
-   "nlmsg_write")
-    S_(SECCLASS_NETLINK_AUDIT_SOCKET, NETLINK_AUDIT_SOCKET__NLMSG_RELAY,
-   "nlmsg_relay")
-    S_(SECCLASS_NETLINK_AUDIT_SOCKET, NETLINK_AUDIT_SOCKET__NLMSG_READPRIV,
-   "nlmsg_readpriv")
-    S_(SECCLASS_NETLINK_IP6FW_SOCKET, NETLINK_IP6FW_SOCKET__NLMSG_READ,
-   "nlmsg_read")
-    S_(SECCLASS_NETLINK_IP6FW_SOCKET, NETLINK_IP6FW_SOCKET__NLMSG_WRITE,
-   "nlmsg_write")
-    S_(SECCLASS_DBUS, DBUS__ACQUIRE_SVC, "acquire_svc")
-    S_(SECCLASS_DBUS, DBUS__SEND_MSG, "send_msg")
-    S_(SECCLASS_NSCD, NSCD__GETPWD, "getpwd")
-    S_(SECCLASS_NSCD, NSCD__GETGRP, "getgrp")
-    S_(SECCLASS_NSCD, NSCD__GETHOST, "gethost")
-    S_(SECCLASS_NSCD, NSCD__GETSTAT, "getstat")
-    S_(SECCLASS_NSCD, NSCD__ADMIN, "admin")
-    S_(SECCLASS_NSCD, NSCD__SHMEMPWD, "shmempwd")
-    S_(SECCLASS_NSCD, NSCD__SHMEMGRP, "shmemgrp")
-    S_(SECCLASS_NSCD, NSCD__SHMEMHOST, "shmemhost")
-    S_(SECCLASS_ASSOCIATION, ASSOCIATION__SENDTO, "sendto")
-    S_(SECCLASS_ASSOCIATION, ASSOCIATION__RECVFROM, "recvfrom")
-    S_(SECCLASS_ASSOCIATION, ASSOCIATION__SETCONTEXT, "setcontext")
-    S_(SECCLASS_PACKET, PACKET__SEND, "send")
-    S_(SECCLASS_PACKET, PACKET__RECV, "recv")
-    S_(SECCLASS_PACKET, PACKET__RELABELTO, "relabelto")
-    S_(SECCLASS_KEY, KEY__VIEW, "view")
-    S_(SECCLASS_KEY, KEY__READ, "read")
-    S_(SECCLASS_KEY, KEY__WRITE, "write")
-    S_(SECCLASS_KEY, KEY__SEARCH, "search")
-    S_(SECCLASS_KEY, KEY__LINK, "link")
-    S_(SECCLASS_KEY, KEY__SETATTR, "setattr")
-    S_(SECCLASS_KEY, KEY__CREATE, "create")
+   S_(SECCLASS_FILESYSTEM, FILESYSTEM__MOUNT, "mount")
+   S_(SECCLASS_FILESYSTEM, FILESYSTEM__REMOUNT, "remount")
+   S_(SECCLASS_FILESYSTEM, FILESYSTEM__UNMOUNT, "unmount")
+   S_(SECCLASS_FILESYSTEM, FILESYSTEM__GETATTR, "getattr")
+   S_(SECCLASS_FILESYSTEM, FILESYSTEM__RELABELFROM, "relabelfrom")
+   S_(SECCLASS_FILESYSTEM, FILESYSTEM__RELABELTO, "relabelto")
+   S_(SECCLASS_FILESYSTEM, FILESYSTEM__TRANSITION, "transition")
+   S_(SECCLASS_FILESYSTEM, FILESYSTEM__ASSOCIATE, "associate")
+   S_(SECCLASS_FILESYSTEM, FILESYSTEM__QUOTAMOD, "quotamod")
+   S_(SECCLASS_FILESYSTEM, FILESYSTEM__QUOTAGET, "quotaget")
+   S_(SECCLASS_DIR, DIR__ADD_NAME, "add_name")
+   S_(SECCLASS_DIR, DIR__REMOVE_NAME, "remove_name")
+   S_(SECCLASS_DIR, DIR__REPARENT, "reparent")
+   S_(SECCLASS_DIR, DIR__SEARCH, "search")
+   S_(SECCLASS_DIR, DIR__RMDIR, "rmdir")
+   S_(SECCLASS_FILE, FILE__EXECUTE_NO_TRANS, "execute_no_trans")
+   S_(SECCLASS_FILE, FILE__ENTRYPOINT, "entrypoint")
+   S_(SECCLASS_FILE, FILE__EXECMOD, "execmod")
+   S_(SECCLASS_CHR_FILE, CHR_FILE__EXECUTE_NO_TRANS, "execute_no_trans")
+   S_(SECCLASS_CHR_FILE, CHR_FILE__ENTRYPOINT, "entrypoint")
+   S_(SECCLASS_CHR_FILE, CHR_FILE__EXECMOD, "execmod")
+   S_(SECCLASS_FD, FD__USE, "use")
+   S_(SECCLASS_TCP_SOCKET, TCP_SOCKET__CONNECTTO, "connectto")
+   S_(SECCLASS_TCP_SOCKET, TCP_SOCKET__NEWCONN, "newconn")
+   S_(SECCLASS_TCP_SOCKET, TCP_SOCKET__ACCEPTFROM, "acceptfrom")
+   S_(SECCLASS_TCP_SOCKET, TCP_SOCKET__NODE_BIND, "node_bind")
+   S_(SECCLASS_TCP_SOCKET, TCP_SOCKET__NAME_CONNECT, "name_connect")
+   S_(SECCLASS_UDP_SOCKET, UDP_SOCKET__NODE_BIND, "node_bind")
+   S_(SECCLASS_RAWIP_SOCKET, RAWIP_SOCKET__NODE_BIND, "node_bind")
+   S_(SECCLASS_NODE, NODE__TCP_RECV, "tcp_recv")
+   S_(SECCLASS_NODE, NODE__TCP_SEND, "tcp_send")
+   S_(SECCLASS_NODE, NODE__UDP_RECV, "udp_recv")
+   S_(SECCLASS_NODE, NODE__UDP_SEND, "udp_send")
+   S_(SECCLASS_NODE, NODE__RAWIP_RECV, "rawip_recv")
+   S_(SECCLASS_NODE, NODE__RAWIP_SEND, "rawip_send")
+   S_(SECCLASS_NODE, NODE__ENFORCE_DEST, "enforce_dest")
+   S_(SECCLASS_NETIF, NETIF__TCP_RECV, "tcp_recv")
+   S_(SECCLASS_NETIF, NETIF__TCP_SEND, "tcp_send")
+   S_(SECCLASS_NETIF, NETIF__UDP_RECV, "udp_recv")
+   S_(SECCLASS_NETIF, NETIF__UDP_SEND, "udp_send")
+   S_(SECCLASS_NETIF, NETIF__RAWIP_RECV, "rawip_recv")
+   S_(SECCLASS_NETIF, NETIF__RAWIP_SEND, "rawip_send")
+   S_(SECCLASS_UNIX_STREAM_SOCKET, UNIX_STREAM_SOCKET__CONNECTTO, "connectto")
+   S_(SECCLASS_UNIX_STREAM_SOCKET, UNIX_STREAM_SOCKET__NEWCONN, "newconn")
+   S_(SECCLASS_UNIX_STREAM_SOCKET, UNIX_STREAM_SOCKET__ACCEPTFROM, "acceptfrom")
+   S_(SECCLASS_PROCESS, PROCESS__FORK, "fork")
+   S_(SECCLASS_PROCESS, PROCESS__TRANSITION, "transition")
+   S_(SECCLASS_PROCESS, PROCESS__SIGCHLD, "sigchld")
+   S_(SECCLASS_PROCESS, PROCESS__SIGKILL, "sigkill")
+   S_(SECCLASS_PROCESS, PROCESS__SIGSTOP, "sigstop")
+   S_(SECCLASS_PROCESS, PROCESS__SIGNULL, "signull")
+   S_(SECCLASS_PROCESS, PROCESS__SIGNAL, "signal")
+   S_(SECCLASS_PROCESS, PROCESS__PTRACE, "ptrace")
+   S_(SECCLASS_PROCESS, PROCESS__GETSCHED, "getsched")
+   S_(SECCLASS_PROCESS, PROCESS__SETSCHED, "setsched")
+   S_(SECCLASS_PROCESS, PROCESS__GETSESSION, "getsession")
+   S_(SECCLASS_PROCESS, PROCESS__GETPGID, "getpgid")
+   S_(SECCLASS_PROCESS, PROCESS__SETPGID, "setpgid")
+   S_(SECCLASS_PROCESS, PROCESS__GETCAP, "getcap")
+   S_(SECCLASS_PROCESS, PROCESS__SETCAP, "setcap")
+   S_(SECCLASS_PROCESS, PROCESS__SHARE, "share")
+   S_(SECCLASS_PROCESS, PROCESS__GETATTR, "getattr")
+   S_(SECCLASS_PROCESS, PROCESS__SETEXEC, "setexec")
+   S_(SECCLASS_PROCESS, PROCESS__SETFSCREATE, "setfscreate")
+   S_(SECCLASS_PROCESS, PROCESS__NOATSECURE, "noatsecure")
+   S_(SECCLASS_PROCESS, PROCESS__SIGINH, "siginh")
+   S_(SECCLASS_PROCESS, PROCESS__SETRLIMIT, "setrlimit")
+   S_(SECCLASS_PROCESS, PROCESS__RLIMITINH, "rlimitinh")
+   S_(SECCLASS_PROCESS, PROCESS__DYNTRANSITION, "dyntransition")
+   S_(SECCLASS_PROCESS, PROCESS__SETCURRENT, "setcurrent")
+   S_(SECCLASS_PROCESS, PROCESS__EXECMEM, "execmem")
+   S_(SECCLASS_PROCESS, PROCESS__EXECSTACK, "execstack")
+   S_(SECCLASS_PROCESS, PROCESS__EXECHEAP, "execheap")
+   S_(SECCLASS_PROCESS, PROCESS__SETKEYCREATE, "setkeycreate")
+   S_(SECCLASS_PROCESS, PROCESS__TASKFORPID, "taskforpid")
+   S_(SECCLASS_MSGQ, MSGQ__ENQUEUE, "enqueue")
+   S_(SECCLASS_MSG, MSG__SEND, "send")
+   S_(SECCLASS_MSG, MSG__RECEIVE, "receive")
+   S_(SECCLASS_SHM, SHM__LOCK, "lock")
+   S_(SECCLASS_SECURITY, SECURITY__COMPUTE_AV, "compute_av")
+   S_(SECCLASS_SECURITY, SECURITY__COMPUTE_CREATE, "compute_create")
+   S_(SECCLASS_SECURITY, SECURITY__COMPUTE_MEMBER, "compute_member")
+   S_(SECCLASS_SECURITY, SECURITY__CHECK_CONTEXT, "check_context")
+   S_(SECCLASS_SECURITY, SECURITY__LOAD_POLICY, "load_policy")
+   S_(SECCLASS_SECURITY, SECURITY__COMPUTE_RELABEL, "compute_relabel")
+   S_(SECCLASS_SECURITY, SECURITY__COMPUTE_USER, "compute_user")
+   S_(SECCLASS_SECURITY, SECURITY__SETENFORCE, "setenforce")
+   S_(SECCLASS_SECURITY, SECURITY__SETBOOL, "setbool")
+   S_(SECCLASS_SECURITY, SECURITY__SETSECPARAM, "setsecparam")
+   S_(SECCLASS_SECURITY, SECURITY__SETCHECKREQPROT, "setcheckreqprot")
+   S_(SECCLASS_SYSTEM, SYSTEM__IPC_INFO, "ipc_info")
+   S_(SECCLASS_SYSTEM, SYSTEM__SYSLOG_READ, "syslog_read")
+   S_(SECCLASS_SYSTEM, SYSTEM__SYSLOG_MOD, "syslog_mod")
+   S_(SECCLASS_SYSTEM, SYSTEM__SYSLOG_CONSOLE, "syslog_console")
+   S_(SECCLASS_CAPABILITY, CAPABILITY__CHOWN, "chown")
+   S_(SECCLASS_CAPABILITY, CAPABILITY__DAC_OVERRIDE, "dac_override")
+   S_(SECCLASS_CAPABILITY, CAPABILITY__DAC_READ_SEARCH, "dac_read_search")
+   S_(SECCLASS_CAPABILITY, CAPABILITY__FOWNER, "fowner")
+   S_(SECCLASS_CAPABILITY, CAPABILITY__FSETID, "fsetid")
+   S_(SECCLASS_CAPABILITY, CAPABILITY__KILL, "kill")
+   S_(SECCLASS_CAPABILITY, CAPABILITY__SETGID, "setgid")
+   S_(SECCLASS_CAPABILITY, CAPABILITY__SETUID, "setuid")
+   S_(SECCLASS_CAPABILITY, CAPABILITY__SETPCAP, "setpcap")
+   S_(SECCLASS_CAPABILITY, CAPABILITY__LINUX_IMMUTABLE, "linux_immutable")
+   S_(SECCLASS_CAPABILITY, CAPABILITY__NET_BIND_SERVICE, "net_bind_service")
+   S_(SECCLASS_CAPABILITY, CAPABILITY__NET_BROADCAST, "net_broadcast")
+   S_(SECCLASS_CAPABILITY, CAPABILITY__NET_ADMIN, "net_admin")
+   S_(SECCLASS_CAPABILITY, CAPABILITY__NET_RAW, "net_raw")
+   S_(SECCLASS_CAPABILITY, CAPABILITY__IPC_LOCK, "ipc_lock")
+   S_(SECCLASS_CAPABILITY, CAPABILITY__IPC_OWNER, "ipc_owner")
+   S_(SECCLASS_CAPABILITY, CAPABILITY__SYS_MODULE, "sys_module")
+   S_(SECCLASS_CAPABILITY, CAPABILITY__SYS_RAWIO, "sys_rawio")
+   S_(SECCLASS_CAPABILITY, CAPABILITY__SYS_CHROOT, "sys_chroot")
+   S_(SECCLASS_CAPABILITY, CAPABILITY__SYS_PTRACE, "sys_ptrace")
+   S_(SECCLASS_CAPABILITY, CAPABILITY__SYS_PACCT, "sys_pacct")
+   S_(SECCLASS_CAPABILITY, CAPABILITY__SYS_ADMIN, "sys_admin")
+   S_(SECCLASS_CAPABILITY, CAPABILITY__SYS_BOOT, "sys_boot")
+   S_(SECCLASS_CAPABILITY, CAPABILITY__SYS_NICE, "sys_nice")
+   S_(SECCLASS_CAPABILITY, CAPABILITY__SYS_RESOURCE, "sys_resource")
+   S_(SECCLASS_CAPABILITY, CAPABILITY__SYS_TIME, "sys_time")
+   S_(SECCLASS_CAPABILITY, CAPABILITY__SYS_TTY_CONFIG, "sys_tty_config")
+   S_(SECCLASS_CAPABILITY, CAPABILITY__MKNOD, "mknod")
+   S_(SECCLASS_CAPABILITY, CAPABILITY__LEASE, "lease")
+   S_(SECCLASS_CAPABILITY, CAPABILITY__AUDIT_WRITE, "audit_write")

>>> TRUNCATED FOR MAIL (1000 lines) <<<


More information about the trustedbsd-cvs mailing list