diff -urN policy-1.13.3.o/flask/access_vectors policy-1.13.3.w/flask/access_vectors --- policy-1.13.3.o/flask/access_vectors 2004-06-02 15:04:57.000000000 -0400 +++ policy-1.13.3.w/flask/access_vectors 2004-06-08 23:51:26.000000000 -0400 @@ -495,3 +495,57 @@ randexec # Randomize ET_EXEC base segmexec # Segmentation based non-executable pages } + +# +# Extended Netlink classes +# +class netlink_route_socket +inherits socket +{ + nlmsg_read + nlmsg_write +} + +class netlink_firewall_socket +inherits socket +{ + nlmsg_read + nlmsg_write +} + +class netlink_tcpdiag_socket +inherits socket +{ + nlmsg_read + nlmsg_write +} + +class netlink_nflog_socket +inherits socket + +class netlink_xfrm_socket +inherits socket +{ + nlmsg_read + nlmsg_write +} + +class netlink_selinux_socket +inherits socket + +class netlink_audit_socket +inherits socket +{ + nlmsg_read + nlmsg_write +} + +class netlink_ip6fw_socket +inherits socket +{ + nlmsg_read + nlmsg_write +} + +class netlink_dnrt_socket +inherits socket diff -urN policy-1.13.3.o/flask/security_classes policy-1.13.3.w/flask/security_classes --- policy-1.13.3.o/flask/security_classes 2004-06-02 15:04:57.000000000 -0400 +++ policy-1.13.3.w/flask/security_classes 2004-06-08 23:44:04.000000000 -0400 @@ -63,4 +63,15 @@ # pax flags class pax +# extended netlink sockets +class netlink_route_socket +class netlink_firewall_socket +class netlink_tcpdiag_socket +class netlink_nflog_socket +class netlink_xfrm_socket +class netlink_selinux_socket +class netlink_audit_socket +class netlink_ip6fw_socket +class netlink_dnrt_socket + # FLASK