blob: 6386101120eb9dc5f95894975ef50e500e93a12f [file] [log] [blame]
William Robertsdc107232012-07-11 16:46:38 -07001# Label inodes with the fs label.
2genfscon rootfs / u:object_r:rootfs:s0
3# proc labeling can be further refined (longest matching prefix).
4genfscon proc / u:object_r:proc:s0
Daniel Micay5423db62016-07-29 14:48:19 -04005genfscon proc /interrupts u:object_r:proc_interrupts:s0
dcashman26cd9122015-07-13 08:39:17 -07006genfscon proc /iomem u:object_r:proc_iomem:s0
dcashmanf25ea5f2016-02-23 17:09:48 -08007genfscon proc /meminfo u:object_r:proc_meminfo:s0
Robert Craig1bf61c42014-01-07 14:41:47 -05008genfscon proc /net u:object_r:proc_net:s0
hqjiang4c06d272012-07-19 11:07:04 -07009genfscon proc /net/xt_qtaguid/ctrl u:object_r:qtaguid_proc:s0
Nick Kralevich2de02872014-09-26 10:51:12 -070010genfscon proc /cpuinfo u:object_r:proc_cpuinfo:s0
Daniel Micay5423db62016-07-29 14:48:19 -040011genfscon proc /softirqs u:object_r:proc_timer:s0
12genfscon proc /stat u:object_r:proc_stat:s0
Stephen Smalley3dad7b62014-03-05 09:50:08 -050013genfscon proc /sysrq-trigger u:object_r:proc_sysrq:s0
Stephen Smalley7adb9992013-12-06 09:31:40 -050014genfscon proc /sys/fs/protected_hardlinks u:object_r:proc_security:s0
15genfscon proc /sys/fs/protected_symlinks u:object_r:proc_security:s0
16genfscon proc /sys/fs/suid_dumpable u:object_r:proc_security:s0
17genfscon proc /sys/kernel/core_pattern u:object_r:usermodehelper:s0
18genfscon proc /sys/kernel/dmesg_restrict u:object_r:proc_security:s0
19genfscon proc /sys/kernel/hotplug u:object_r:usermodehelper:s0
20genfscon proc /sys/kernel/kptr_restrict u:object_r:proc_security:s0
21genfscon proc /sys/kernel/modprobe u:object_r:usermodehelper:s0
22genfscon proc /sys/kernel/modules_disabled u:object_r:proc_security:s0
23genfscon proc /sys/kernel/poweroff_cmd u:object_r:usermodehelper:s0
24genfscon proc /sys/kernel/randomize_va_space u:object_r:proc_security:s0
25genfscon proc /sys/kernel/usermodehelper u:object_r:usermodehelper:s0
Robert Craig529fcbe2014-01-07 13:46:56 -050026genfscon proc /sys/net u:object_r:proc_net:s0
Stephen Smalleye6a7b372013-12-09 13:24:25 -050027genfscon proc /sys/vm/mmap_min_addr u:object_r:proc_security:s0
Jeff Sharkeyc9605962015-05-14 20:55:31 -070028genfscon proc /sys/vm/drop_caches u:object_r:proc_drop_caches:s0
Jeff Vander Stoepbc1986f2016-06-27 15:38:25 -070029genfscon proc /sys/vm/overcommit_memory u:object_r:proc_overcommit_memory:s0
Daniel Micay5423db62016-07-29 14:48:19 -040030genfscon proc /timer_list u:object_r:proc_timer:s0
31genfscon proc /timer_stats u:object_r:proc_timer:s0
Nick Kraleviche427a2b2017-01-04 08:43:09 -080032genfscon proc /tty/drivers u:object_r:proc_tty_drivers:s0
Adam Lesinski3526a662015-05-12 17:14:35 -070033genfscon proc /uid_cputime/show_uid_stat u:object_r:proc_uid_cputime_showstat:s0
34genfscon proc /uid_cputime/remove_uid_range u:object_r:proc_uid_cputime_removeuid:s0
Jeff Sharkey828433c2017-01-17 18:33:50 -070035genfscon proc /uid_procstat/set u:object_r:proc_uid_procstat_set:s0
Daniel Micay7078e8b2016-08-08 13:48:01 -040036genfscon proc /zoneinfo u:object_r:proc_zoneinfo:s0
Adam Lesinski3526a662015-05-12 17:14:35 -070037
William Robertsdc107232012-07-11 16:46:38 -070038# selinuxfs booleans can be individually labeled.
39genfscon selinuxfs / u:object_r:selinuxfs:s0
40genfscon cgroup / u:object_r:cgroup:s0
41# sysfs labels can be set by userspace.
42genfscon sysfs / u:object_r:sysfs:s0
43genfscon inotifyfs / u:object_r:inotify:s0
Stephen Smalley374b2a12014-07-08 14:45:09 -040044genfscon vfat / u:object_r:vfat:s0
William Robertsdc107232012-07-11 16:46:38 -070045genfscon debugfs / u:object_r:debugfs:s0
Christian Poetzsch4dafa722016-05-13 13:36:33 +010046genfscon tracefs / u:object_r:debugfs_tracing:s0
Stephen Smalley374b2a12014-07-08 14:45:09 -040047genfscon fuse / u:object_r:fuse:s0
Daniel Rosenbergc15090b2016-03-01 16:13:50 -080048genfscon configfs / u:object_r:configfs:s0
49genfscon sdcardfs / u:object_r:sdcardfs:s0
jaejyn.shin318e0c92014-04-10 13:32:54 +090050genfscon pstore / u:object_r:pstorefs:s0
Nick Kralevich77cc0552014-04-15 14:53:05 -070051genfscon functionfs / u:object_r:functionfs:s0
Nick Kralevich5a5fb852014-06-07 07:31:31 -070052genfscon usbfs / u:object_r:usbfs:s0
Nick Kralevichfdc56c52015-04-10 17:42:49 -070053genfscon binfmt_misc / u:object_r:binfmt_miscfs:s0