This is the flask-based XSM policy used in OpenXT to harden Xen security.
It was originally forked from the Xen source repository. When upgrading Xen in OpenXT, this policy should be updated as well. It could be rewritten as a patchqueue on top of Xen to enforce these updates.