1#
2# Common neverallow permissions
3define(`no_w_file_perms', `{ append create link unlink relabelfrom rename setattr write }')
4define(`no_rw_file_perms', `{ no_w_file_perms open read ioctl lock watch watch_mount watch_sb watch_with_perm watch_reads }')
5define(`no_x_file_perms', `{ execute execute_no_trans }')
6define(`no_w_dir_perms',  `{ add_name create link relabelfrom remove_name rename reparent rmdir setattr write }')
7
8#####################################
9# neverallow_establish_socket_comms(src, dst)
10# neverallow src domain establishing socket connections to dst domain.
11#
12define(`neverallow_establish_socket_comms', `
13  neverallow $1 $2:socket_class_set { connect sendto };
14  neverallow $1 $2:unix_stream_socket connectto;
15')
16