|
Dan Walsh |
3eaa99 |
policy_module(git, 1.0.3)
|
|
Dan Walsh |
3eaa99 |
|
|
Dan Walsh |
3eaa99 |
## <desc>
|
|
Dominick Grift |
68ac47 |
##
|
|
Dominick Grift |
68ac47 |
## Allow Git daemon system to search home directories.
|
|
Dominick Grift |
68ac47 |
##
|
|
Dan Walsh |
3eaa99 |
## </desc>
|
|
Dan Walsh |
3eaa99 |
gen_tunable(git_system_enable_homedirs, false)
|
|
Dan Walsh |
3eaa99 |
|
|
Dan Walsh |
3eaa99 |
## <desc>
|
|
Dominick Grift |
68ac47 |
##
|
|
Dominick Grift |
68ac47 |
## Allow Git daemon system to access cifs file systems.
|
|
Dominick Grift |
68ac47 |
##
|
|
Dan Walsh |
3eaa99 |
## </desc>
|
|
Dan Walsh |
3eaa99 |
gen_tunable(git_system_use_cifs, false)
|
|
Dan Walsh |
3eaa99 |
|
|
Dan Walsh |
3eaa99 |
## <desc>
|
|
Dominick Grift |
68ac47 |
##
|
|
Dominick Grift |
68ac47 |
## Allow Git daemon system to access nfs file systems.
|
|
Dominick Grift |
68ac47 |
##
|
|
Dan Walsh |
3eaa99 |
## </desc>
|
|
Dan Walsh |
3eaa99 |
gen_tunable(git_system_use_nfs, false)
|
|
Dan Walsh |
3eaa99 |
|
|
Dan Walsh |
3eaa99 |
########################################
|
|
Dan Walsh |
3eaa99 |
#
|
|
Dan Walsh |
3eaa99 |
# Git daemon global private declarations.
|
|
Dan Walsh |
3eaa99 |
#
|
|
Dan Walsh |
3eaa99 |
|
|
Dan Walsh |
3eaa99 |
attribute git_domains;
|
|
Dan Walsh |
3eaa99 |
attribute git_system_content;
|
|
Dan Walsh |
3eaa99 |
attribute git_content;
|
|
Dan Walsh |
3eaa99 |
|
|
Dan Walsh |
3eaa99 |
type gitd_exec_t;
|
|
Dominick Grift |
96d3c0 |
application_executable_file(gitd_exec_t)
|
|
Dan Walsh |
3eaa99 |
|
|
Dan Walsh |
3eaa99 |
########################################
|
|
Dan Walsh |
3eaa99 |
#
|
|
Dan Walsh |
3eaa99 |
# Git daemon system private declarations.
|
|
Dan Walsh |
3eaa99 |
#
|
|
Dan Walsh |
3eaa99 |
|
|
Dan Walsh |
3eaa99 |
type git_system_t, git_domains;
|
|
Dan Walsh |
3eaa99 |
inetd_service_domain(git_system_t, gitd_exec_t)
|
|
Dan Walsh |
3eaa99 |
role system_r types git_system_t;
|
|
Dan Walsh |
3eaa99 |
|
|
Dan Walsh |
3eaa99 |
type git_system_content_t, git_system_content, git_content;
|
|
Dan Walsh |
3eaa99 |
files_type(git_system_content_t)
|
|
Dan Walsh |
3eaa99 |
typealias git_system_content_t alias git_data_t;
|
|
Dan Walsh |
3eaa99 |
|
|
Dan Walsh |
3eaa99 |
########################################
|
|
Dan Walsh |
3eaa99 |
#
|
|
Dan Walsh |
3eaa99 |
# Git daemon session private declarations.
|
|
Dan Walsh |
3eaa99 |
#
|
|
Dan Walsh |
3eaa99 |
|
|
Dan Walsh |
3eaa99 |
## <desc>
|
|
Dominick Grift |
68ac47 |
##
|
|
Dominick Grift |
68ac47 |
## Allow Git daemon session to bind
|
|
Dominick Grift |
68ac47 |
## tcp sockets to all unreserved ports.
|
|
Dominick Grift |
68ac47 |
##
|
|
Dan Walsh |
3eaa99 |
## </desc>
|
|
Dan Walsh |
3eaa99 |
gen_tunable(git_session_bind_all_unreserved_ports, false)
|
|
Dan Walsh |
3eaa99 |
|
|
Dan Walsh |
3eaa99 |
type git_session_t, git_domains;
|
|
Dan Walsh |
3eaa99 |
application_domain(git_session_t, gitd_exec_t)
|
|
Dan Walsh |
3eaa99 |
ubac_constrained(git_session_t)
|
|
Dan Walsh |
3eaa99 |
|
|
Dan Walsh |
3eaa99 |
type git_session_content_t, git_content;
|
|
Dan Walsh |
3eaa99 |
userdom_user_home_content(git_session_content_t)
|
|
Dan Walsh |
3eaa99 |
|
|
Dan Walsh |
3eaa99 |
########################################
|
|
Dan Walsh |
3eaa99 |
#
|
|
Dan Walsh |
3eaa99 |
# Git daemon global private policy.
|
|
Dan Walsh |
3eaa99 |
#
|
|
Dan Walsh |
3eaa99 |
|
|
Dan Walsh |
3eaa99 |
allow git_domains self:fifo_file rw_fifo_file_perms;
|
|
Dan Walsh |
3eaa99 |
allow git_domains self:netlink_route_socket create_netlink_socket_perms;
|
|
Dan Walsh |
3eaa99 |
allow git_domains self:tcp_socket create_socket_perms;
|
|
Dan Walsh |
3eaa99 |
allow git_domains self:udp_socket create_socket_perms;
|
|
Dan Walsh |
3eaa99 |
allow git_domains self:unix_dgram_socket create_socket_perms;
|
|
Dan Walsh |
3eaa99 |
|
|
Dan Walsh |
3eaa99 |
corenet_all_recvfrom_netlabel(git_domains)
|
|
Dan Walsh |
3eaa99 |
corenet_all_recvfrom_unlabeled(git_domains)
|
|
Dan Walsh |
3eaa99 |
corenet_tcp_bind_generic_node(git_domains)
|
|
Dan Walsh |
3eaa99 |
corenet_tcp_sendrecv_generic_if(git_domains)
|
|
Dan Walsh |
3eaa99 |
corenet_tcp_sendrecv_generic_node(git_domains)
|
|
Dan Walsh |
3eaa99 |
corenet_tcp_sendrecv_generic_port(git_domains)
|
|
Dan Walsh |
3eaa99 |
corenet_tcp_bind_git_port(git_domains)
|
|
Dan Walsh |
3eaa99 |
corenet_sendrecv_git_server_packets(git_domains)
|
|
Dan Walsh |
3eaa99 |
|
|
Dan Walsh |
3eaa99 |
corecmd_exec_bin(git_domains)
|
|
Dan Walsh |
3eaa99 |
|
|
Dan Walsh |
3eaa99 |
files_read_etc_files(git_domains)
|
|
Dan Walsh |
3eaa99 |
files_read_usr_files(git_domains)
|
|
Dan Walsh |
3eaa99 |
|
|
Dan Walsh |
3eaa99 |
fs_search_auto_mountpoints(git_domains)
|
|
Dan Walsh |
3eaa99 |
|
|
Dan Walsh |
3eaa99 |
kernel_read_system_state(git_domains)
|
|
Dan Walsh |
3eaa99 |
|
|
Dan Walsh |
3eaa99 |
auth_use_nsswitch(git_domains)
|
|
Dan Walsh |
3eaa99 |
|
|
Dan Walsh |
3eaa99 |
logging_send_syslog_msg(git_domains)
|
|
Dan Walsh |
3eaa99 |
|
|
Dan Walsh |
3eaa99 |
miscfiles_read_localization(git_domains)
|
|
Dan Walsh |
3eaa99 |
|
|
Dan Walsh |
3eaa99 |
sysnet_read_config(git_domains)
|
|
Dan Walsh |
3eaa99 |
|
|
Dan Walsh |
3eaa99 |
optional_policy(`
|
|
Dan Walsh |
3eaa99 |
automount_dontaudit_getattr_tmp_dirs(git_domains)
|
|
Dan Walsh |
3eaa99 |
')
|
|
Dan Walsh |
3eaa99 |
|
|
Dan Walsh |
3eaa99 |
optional_policy(`
|
|
Dan Walsh |
3eaa99 |
nis_use_ypbind(git_domains)
|
|
Dan Walsh |
3eaa99 |
')
|
|
Dan Walsh |
3eaa99 |
|
|
Dan Walsh |
3eaa99 |
########################################
|
|
Dan Walsh |
3eaa99 |
#
|
|
Dan Walsh |
3eaa99 |
# Git daemon system repository private policy.
|
|
Dan Walsh |
3eaa99 |
#
|
|
Dan Walsh |
3eaa99 |
|
|
Dan Walsh |
3eaa99 |
list_dirs_pattern(git_system_t, git_content, git_content)
|
|
Dan Walsh |
3eaa99 |
read_files_pattern(git_system_t, git_content, git_content)
|
|
Dan Walsh |
3eaa99 |
files_search_var_lib(git_system_t)
|
|
Dan Walsh |
3eaa99 |
|
|
Dominick Grift |
68ac47 |
tunable_policy(`git_system_enable_homedirs',`
|
|
Dan Walsh |
3eaa99 |
userdom_search_user_home_dirs(git_system_t)
|
|
Dan Walsh |
3eaa99 |
')
|
|
Dan Walsh |
3eaa99 |
|
|
Dominick Grift |
68ac47 |
tunable_policy(`git_system_enable_homedirs && use_nfs_home_dirs',`
|
|
Dan Walsh |
3eaa99 |
fs_list_nfs(git_system_t)
|
|
Dan Walsh |
3eaa99 |
fs_read_nfs_files(git_system_t)
|
|
Dan Walsh |
3eaa99 |
')
|
|
Dan Walsh |
3eaa99 |
|
|
Dominick Grift |
68ac47 |
tunable_policy(`git_system_enable_homedirs && use_samba_home_dirs',`
|
|
Dan Walsh |
3eaa99 |
fs_list_cifs(git_system_t)
|
|
Dan Walsh |
3eaa99 |
fs_read_cifs_files(git_system_t)
|
|
Dan Walsh |
3eaa99 |
')
|
|
Dan Walsh |
3eaa99 |
|
|
Dominick Grift |
68ac47 |
tunable_policy(`git_system_use_cifs',`
|
|
Dan Walsh |
3eaa99 |
fs_list_cifs(git_system_t)
|
|
Dan Walsh |
3eaa99 |
fs_read_cifs_files(git_system_t)
|
|
Dan Walsh |
3eaa99 |
')
|
|
Dan Walsh |
3eaa99 |
|
|
Dominick Grift |
68ac47 |
tunable_policy(`git_system_use_nfs',`
|
|
Dan Walsh |
3eaa99 |
fs_list_nfs(git_system_t)
|
|
Dan Walsh |
3eaa99 |
fs_read_nfs_files(git_system_t)
|
|
Dan Walsh |
3eaa99 |
')
|
|
Chris PeBenito |
153fe2 |
|
|
Chris PeBenito |
153fe2 |
########################################
|
|
Chris PeBenito |
153fe2 |
#
|
|
Dan Walsh |
3eaa99 |
# Git daemon session repository private policy.
|
|
Chris PeBenito |
153fe2 |
#
|
|
Chris PeBenito |
153fe2 |
|
|
Dan Walsh |
3eaa99 |
allow git_session_t self:tcp_socket { accept listen };
|
|
Dan Walsh |
3eaa99 |
|
|
Dan Walsh |
3eaa99 |
list_dirs_pattern(git_session_t, git_session_content_t, git_session_content_t)
|
|
Dan Walsh |
3eaa99 |
read_files_pattern(git_session_t, git_session_content_t, git_session_content_t)
|
|
Dan Walsh |
3eaa99 |
userdom_search_user_home_dirs(git_session_t)
|
|
Dan Walsh |
3eaa99 |
|
|
Dan Walsh |
3eaa99 |
userdom_use_user_terminals(git_session_t)
|
|
Dan Walsh |
3eaa99 |
|
|
Dominick Grift |
68ac47 |
tunable_policy(`git_session_bind_all_unreserved_ports',`
|
|
Dan Walsh |
3eaa99 |
corenet_tcp_bind_all_unreserved_ports(git_session_t)
|
|
Dan Walsh |
3eaa99 |
corenet_sendrecv_generic_server_packets(git_session_t)
|
|
Dan Walsh |
3eaa99 |
')
|
|
Dan Walsh |
3eaa99 |
|
|
Dominick Grift |
68ac47 |
tunable_policy(`use_nfs_home_dirs',`
|
|
Dan Walsh |
3eaa99 |
fs_list_nfs(git_session_t)
|
|
Dan Walsh |
3eaa99 |
fs_read_nfs_files(git_session_t)
|
|
Dan Walsh |
3eaa99 |
')
|
|
Dan Walsh |
3eaa99 |
|
|
Dominick Grift |
68ac47 |
tunable_policy(`use_samba_home_dirs',`
|
|
Dan Walsh |
3eaa99 |
fs_list_cifs(git_session_t)
|
|
Dan Walsh |
3eaa99 |
fs_read_cifs_files(git_session_t)
|
|
Dan Walsh |
3eaa99 |
')
|
|
Dan Walsh |
3eaa99 |
|
|
Dan Walsh |
3eaa99 |
########################################
|
|
Dan Walsh |
3eaa99 |
#
|
|
Dan Walsh |
3eaa99 |
# cgi git Declarations
|
|
Dan Walsh |
3eaa99 |
#
|
|
Dan Walsh |
3eaa99 |
|
|
Dan Walsh |
3eaa99 |
optional_policy(`
|
|
Dan Walsh |
3eaa99 |
apache_content_template(git)
|
|
Dan Walsh |
3eaa99 |
git_read_all_content_files(httpd_git_script_t)
|
|
Dan Walsh |
3eaa99 |
files_dontaudit_getattr_tmp_dirs(httpd_git_script_t)
|
|
Dan Walsh |
3eaa99 |
')
|
|
Dan Walsh |
3eaa99 |
|
|
Dan Walsh |
3eaa99 |
########################################
|
|
Dan Walsh |
3eaa99 |
#
|
|
Dan Walsh |
3eaa99 |
# Git-shell private policy.
|
|
Dan Walsh |
3eaa99 |
#
|
|
Dan Walsh |
3eaa99 |
|
|
Dan Walsh |
3eaa99 |
git_role_template(git_shell)
|
|
Dan Walsh |
3eaa99 |
gen_user(git_shell_u, user, git_shell_r, s0, s0)
|