blob: 9290e3ab36427e73a0ce8593de26f87551410a45 [file] [log] [blame]
Stephen Smalley2dd4e512012-01-04 12:33:27 -05001# Enable new networking controls.
2policycap network_peer_controls;
3
4# Enable open permission check.
5policycap open_perms;
Stephen Smalley431bdd92016-12-08 13:35:27 -05006
7# Enable separate security classes for
8# all network address families previously
9# mapped to the socket class and for
10# ICMP and SCTP sockets previously mapped
11# to the rawip_socket class.
12policycap extended_socket_class;
13
Nick Kralevich1b1d1332018-09-07 10:48:55 -070014# Enable NoNewPrivileges support. Requires libsepol 2.7+
15# and kernel 4.14 (estimated).
16#
17# Checks enabled;
18# process2: nnp_transition, nosuid_transition
19#
20policycap nnp_nosuid_transition;