1 This contains a basic and seemingly functional policy for Chromium. This policy
2 was written on FC12 and might not function on other distributions depending on
3 the version of the refpolicy installed.
5 When building Chromium with the GYP define selinux=1, the seccomp sandbox is
6 disabled and the zygote will perform a dynamic transition to chromium_renderer_t
7 after forking a renderer. The policy in this directory defines access vectors
8 for chromium_renderer_t.
11 % make -f /usr/share/selinux/devel/Makefile
12 % sudo /usr/sbin/semodule -i chromium-browser.pp