Blob Blame History Raw
policy_module(cpufreqselector, 1.3.1)

########################################
#
# Declarations
#

type cpufreqselector_t;
type cpufreqselector_exec_t;
init_daemon_domain(cpufreqselector_t, cpufreqselector_exec_t)

########################################
#
# Local policy
#

allow cpufreqselector_t self:capability sys_nice;
allow cpufreqselector_t self:process getsched;
allow cpufreqselector_t self:fifo_file rw_fifo_file_perms;
allow cpufreqselector_t self:process getsched;

kernel_read_system_state(cpufreqselector_t)

dev_rw_sysfs(cpufreqselector_t)

userdom_read_all_users_state(cpufreqselector_t)
userdom_dontaudit_search_admin_dir(cpufreqselector_t)

optional_policy(`
	dbus_system_domain(cpufreqselector_t, cpufreqselector_exec_t)

	optional_policy(`
		consolekit_dbus_chat(cpufreqselector_t)
	')

	optional_policy(`
		policykit_dbus_chat(cpufreqselector_t)
	')
')

optional_policy(`
	nscd_dontaudit_search_pid(cpufreqselector_t)
')

optional_policy(`
	policykit_domtrans_auth(cpufreqselector_t)
	policykit_read_lib(cpufreqselector_t)
	policykit_read_reload(cpufreqselector_t)
')

optional_policy(`
	xserver_dbus_chat_xdm(cpufreqselector_t)
')