|
Chris PeBenito |
31b7c0 |
#DESC Ftpd - Ftp daemon
|
|
Chris PeBenito |
31b7c0 |
#
|
|
Chris PeBenito |
31b7c0 |
# Authors: Stephen Smalley <sds@epoch.ncsc.mil> and Timothy Fraser
|
|
Chris PeBenito |
31b7c0 |
# Russell Coker <russell@coker.com.au>
|
|
Chris PeBenito |
31b7c0 |
# X-Debian-Packages: proftpd-common bsd-ftpd ftpd vsftpd
|
|
Chris PeBenito |
31b7c0 |
#
|
|
Chris PeBenito |
31b7c0 |
|
|
Chris PeBenito |
31b7c0 |
#################################
|
|
Chris PeBenito |
31b7c0 |
#
|
|
Chris PeBenito |
31b7c0 |
# Rules for the ftpd_t domain
|
|
Chris PeBenito |
31b7c0 |
#
|
|
Chris PeBenito |
31b7c0 |
daemon_domain(ftpd, `, auth_chkpwd, nscd_client_domain')
|
|
Chris PeBenito |
31b7c0 |
etc_domain(ftpd)
|
|
Chris PeBenito |
31b7c0 |
|
|
Chris PeBenito |
31b7c0 |
can_network(ftpd_t)
|
|
Chris PeBenito |
31b7c0 |
allow ftpd_t port_type:tcp_socket name_connect;
|
|
Chris PeBenito |
31b7c0 |
allow ftpd_t self:unix_dgram_socket { sendto create_socket_perms };
|
|
Chris PeBenito |
31b7c0 |
allow ftpd_t self:unix_stream_socket create_socket_perms;
|
|
Chris PeBenito |
31b7c0 |
allow ftpd_t self:process { getcap setcap setsched setrlimit };
|
|
Chris PeBenito |
31b7c0 |
allow ftpd_t self:fifo_file rw_file_perms;
|
|
Chris PeBenito |
31b7c0 |
|
|
Chris PeBenito |
31b7c0 |
allow ftpd_t bin_t:dir search;
|
|
Chris PeBenito |
31b7c0 |
can_exec(ftpd_t, bin_t)
|
|
Chris PeBenito |
31b7c0 |
allow ftpd_t bin_t:lnk_file read;
|
|
Chris PeBenito |
31b7c0 |
read_sysctl(ftpd_t)
|
|
Chris PeBenito |
31b7c0 |
|
|
Chris PeBenito |
31b7c0 |
allow ftpd_t urandom_device_t:chr_file { getattr read };
|
|
Chris PeBenito |
31b7c0 |
|
|
Chris PeBenito |
31b7c0 |
ifdef(`crond.te', `
|
|
Chris PeBenito |
31b7c0 |
system_crond_entry(ftpd_exec_t, ftpd_t)
|
|
Chris PeBenito |
31b7c0 |
allow system_crond_t xferlog_t:file r_file_perms;
|
|
Chris PeBenito |
31b7c0 |
can_exec(ftpd_t, { sbin_t shell_exec_t })
|
|
Chris PeBenito |
31b7c0 |
allow ftpd_t usr_t:file { getattr read };
|
|
Chris PeBenito |
31b7c0 |
ifdef(`logrotate.te', `
|
|
Chris PeBenito |
31b7c0 |
can_exec(ftpd_t, logrotate_exec_t)
|
|
Chris PeBenito |
31b7c0 |
')dnl end if logrotate.te
|
|
Chris PeBenito |
31b7c0 |
')dnl end if crond.te
|
|
Chris PeBenito |
31b7c0 |
|
|
Chris PeBenito |
31b7c0 |
allow ftpd_t ftp_data_port_t:tcp_socket name_bind;
|
|
Chris PeBenito |
31b7c0 |
allow ftpd_t port_t:tcp_socket name_bind;
|
|
Chris PeBenito |
31b7c0 |
|
|
Chris PeBenito |
31b7c0 |
# ftpd_lock_t is only needed when ftpd_is_daemon is true, but we cannot define types conditionally
|
|
Chris PeBenito |
31b7c0 |
type ftpd_lock_t, file_type, sysadmfile, lockfile;
|
|
Chris PeBenito |
31b7c0 |
|
|
Chris PeBenito |
31b7c0 |
# Allow ftpd to run directly without inetd.
|
|
Chris PeBenito |
31b7c0 |
bool ftpd_is_daemon false;
|
|
Chris PeBenito |
31b7c0 |
if (ftpd_is_daemon) {
|
|
Chris PeBenito |
31b7c0 |
file_type_auto_trans(ftpd_t, var_lock_t, ftpd_lock_t, file)
|
|
Chris PeBenito |
31b7c0 |
allow ftpd_t ftp_port_t:tcp_socket name_bind;
|
|
Chris PeBenito |
31b7c0 |
can_tcp_connect(userdomain, ftpd_t)
|
|
Chris PeBenito |
31b7c0 |
# Allows it to check exec privs on daemon
|
|
Chris PeBenito |
31b7c0 |
allow inetd_t ftpd_exec_t:file x_file_perms;
|
|
Chris PeBenito |
31b7c0 |
}
|
|
Chris PeBenito |
31b7c0 |
ifdef(`inetd.te', `
|
|
Chris PeBenito |
31b7c0 |
if (!ftpd_is_daemon) {
|
|
Chris PeBenito |
31b7c0 |
ifdef(`tcpd.te', `domain_auto_trans(tcpd_t, ftpd_exec_t, ftpd_t)')
|
|
Chris PeBenito |
31b7c0 |
domain_auto_trans(inetd_t, ftpd_exec_t, ftpd_t)
|
|
Chris PeBenito |
31b7c0 |
|
|
Chris PeBenito |
31b7c0 |
# Use sockets inherited from inetd.
|
|
Chris PeBenito |
31b7c0 |
allow ftpd_t inetd_t:fd use;
|
|
Chris PeBenito |
31b7c0 |
allow ftpd_t inetd_t:tcp_socket rw_stream_socket_perms;
|
|
Chris PeBenito |
31b7c0 |
|
|
Chris PeBenito |
31b7c0 |
# Send SIGCHLD to inetd on death.
|
|
Chris PeBenito |
31b7c0 |
allow ftpd_t inetd_t:process sigchld;
|
|
Chris PeBenito |
31b7c0 |
}
|
|
Chris PeBenito |
31b7c0 |
') dnl end inetd.te
|
|
Chris PeBenito |
31b7c0 |
|
|
Chris PeBenito |
31b7c0 |
# Access shared memory tmpfs instance.
|
|
Chris PeBenito |
31b7c0 |
tmpfs_domain(ftpd)
|
|
Chris PeBenito |
31b7c0 |
|
|
Chris PeBenito |
31b7c0 |
# Use capabilities.
|
|
Chris PeBenito |
31b7c0 |
allow ftpd_t self:capability { chown fowner fsetid setgid setuid net_bind_service sys_chroot sys_nice sys_resource };
|
|
Chris PeBenito |
31b7c0 |
|
|
Chris PeBenito |
31b7c0 |
# Append to /var/log/wtmp.
|
|
Chris PeBenito |
31b7c0 |
allow ftpd_t wtmp_t:file { getattr append };
|
|
Chris PeBenito |
31b7c0 |
#kerberized ftp requires the following
|
|
Chris PeBenito |
31b7c0 |
allow ftpd_t wtmp_t:file { write lock };
|
|
Chris PeBenito |
31b7c0 |
|
|
Chris PeBenito |
31b7c0 |
# Create and modify /var/log/xferlog.
|
|
Chris PeBenito |
31b7c0 |
type xferlog_t, file_type, sysadmfile, logfile;
|
|
Chris PeBenito |
31b7c0 |
file_type_auto_trans(ftpd_t, var_log_t, xferlog_t, file)
|
|
Chris PeBenito |
31b7c0 |
|
|
Chris PeBenito |
31b7c0 |
# Execute /bin/ls (can comment this out for proftpd)
|
|
Chris PeBenito |
31b7c0 |
# also may need rules to allow tar etc...
|
|
Chris PeBenito |
31b7c0 |
can_exec(ftpd_t, ls_exec_t)
|
|
Chris PeBenito |
31b7c0 |
|
|
Chris PeBenito |
31b7c0 |
allow initrc_t ftpd_etc_t:file { getattr read };
|
|
Chris PeBenito |
31b7c0 |
allow ftpd_t { etc_t etc_runtime_t }:file { getattr read };
|
|
Chris PeBenito |
31b7c0 |
allow ftpd_t proc_t:file { getattr read };
|
|
Chris PeBenito |
31b7c0 |
|
|
Chris PeBenito |
31b7c0 |
dontaudit ftpd_t sysadm_home_dir_t:dir getattr;
|
|
Chris PeBenito |
31b7c0 |
dontaudit ftpd_t selinux_config_t:dir search;
|
|
Chris PeBenito |
31b7c0 |
allow ftpd_t autofs_t:dir search;
|
|
Chris PeBenito |
31b7c0 |
allow ftpd_t self:file { getattr read };
|
|
Chris PeBenito |
31b7c0 |
tmp_domain(ftpd)
|
|
Chris PeBenito |
31b7c0 |
|
|
Chris PeBenito |
31b7c0 |
# Allow ftp to read/write files in the user home directories.
|
|
Chris PeBenito |
31b7c0 |
bool ftp_home_dir false;
|
|
Chris PeBenito |
31b7c0 |
|
|
Chris PeBenito |
31b7c0 |
if (ftp_home_dir) {
|
|
Chris PeBenito |
31b7c0 |
# allow access to /home
|
|
Chris PeBenito |
31b7c0 |
allow ftpd_t home_root_t:dir r_dir_perms;
|
|
Chris PeBenito |
31b7c0 |
create_dir_file(ftpd_t, home_type)
|
|
Chris PeBenito |
31b7c0 |
ifdef(`targeted_policy', `
|
|
Chris PeBenito |
31b7c0 |
file_type_auto_trans(ftpd_t, user_home_dir_t, user_home_t)
|
|
Chris PeBenito |
31b7c0 |
')
|
|
Chris PeBenito |
31b7c0 |
}
|
|
Chris PeBenito |
31b7c0 |
if (use_nfs_home_dirs && ftp_home_dir) {
|
|
Chris PeBenito |
31b7c0 |
r_dir_file(ftpd_t, nfs_t)
|
|
Chris PeBenito |
31b7c0 |
}
|
|
Chris PeBenito |
31b7c0 |
if (use_samba_home_dirs && ftp_home_dir) {
|
|
Chris PeBenito |
31b7c0 |
r_dir_file(ftpd_t, cifs_t)
|
|
Chris PeBenito |
31b7c0 |
}
|
|
Chris PeBenito |
31b7c0 |
dontaudit ftpd_t selinux_config_t:dir search;
|
|
Chris PeBenito |
31b7c0 |
anonymous_domain(ftpd)
|
|
Chris PeBenito |
31b7c0 |
|