|
Chris PeBenito |
ff7bc1 |
## <summary>
|
|
Chris PeBenito |
414e41 |
## Policy for kernel security interface, in particular, selinuxfs.
|
|
Chris PeBenito |
ff7bc1 |
## </summary>
|
|
Chris PeBenito |
274547 |
## <required val="true">
|
|
Chris PeBenito |
274547 |
## Contains the policy for the kernel SELinux security interface.
|
|
Chris PeBenito |
274547 |
## </required>
|
|
Chris PeBenito |
ff7bc1 |
|
|
Chris PeBenito |
ff7bc1 |
########################################
|
|
Chris PeBenito |
414e41 |
## <desc>
|
|
Chris PeBenito |
414e41 |
## Gets the caller the mountpoint of the selinuxfs filesystem.
|
|
Chris PeBenito |
414e41 |
## </desc>
|
|
Chris PeBenito |
414e41 |
## <param name="domain">
|
|
Chris PeBenito |
414e41 |
## The process type requesting the selinuxfs mountpoint.
|
|
Chris PeBenito |
414e41 |
## </param>
|
|
Chris PeBenito |
ff7bc1 |
#
|
|
Chris PeBenito |
199895 |
interface(`selinux_get_fs_mount',`
|
|
Chris PeBenito |
ff7bc1 |
# read /proc/filesystems to see if selinuxfs is supported
|
|
Chris PeBenito |
ff7bc1 |
# then read /proc/self/mount to see where selinuxfs is mounted
|
|
Chris PeBenito |
ff7bc1 |
kernel_read_system_state($1)
|
|
Chris PeBenito |
ff7bc1 |
')
|
|
Chris PeBenito |
ff7bc1 |
|
|
Chris PeBenito |
ff7bc1 |
########################################
|
|
Chris PeBenito |
414e41 |
## <desc>
|
|
Chris PeBenito |
414e41 |
## Allows the caller to get the mode of policy enforcement
|
|
Chris PeBenito |
414e41 |
## (enforcing or permissive mode).
|
|
Chris PeBenito |
414e41 |
## </desc>
|
|
Chris PeBenito |
414e41 |
## <param name="domain">
|
|
Chris PeBenito |
414e41 |
## The process type to allow to get the enforcing mode.
|
|
Chris PeBenito |
414e41 |
## </param>
|
|
Chris PeBenito |
ff7bc1 |
#
|
|
Chris PeBenito |
199895 |
interface(`selinux_get_enforce_mode',`
|
|
Chris PeBenito |
cbc9d6 |
gen_require(`
|
|
Chris PeBenito |
cbc9d6 |
type security_t;
|
|
Chris PeBenito |
cbc9d6 |
class dir { read search getattr };
|
|
Chris PeBenito |
cbc9d6 |
class file { getattr read };
|
|
Chris PeBenito |
cbc9d6 |
')
|
|
Chris PeBenito |
ff7bc1 |
|
|
Chris PeBenito |
ff7bc1 |
allow $1 security_t:dir { read search getattr };
|
|
Chris PeBenito |
ff7bc1 |
allow $1 security_t:file { getattr read };
|
|
Chris PeBenito |
ff7bc1 |
')
|
|
Chris PeBenito |
ff7bc1 |
|
|
Chris PeBenito |
ff7bc1 |
########################################
|
|
Chris PeBenito |
414e41 |
## <desc>
|
|
Chris PeBenito |
414e41 |
## Allow caller to set the mode of policy enforcement
|
|
Chris PeBenito |
414e41 |
## (enforcing or permissive mode).
|
|
Chris PeBenito |
414e41 |
## </desc>
|
|
Chris PeBenito |
414e41 |
## <param name="domain">
|
|
Chris PeBenito |
414e41 |
## The process type to allow to set the enforcement mode.
|
|
Chris PeBenito |
414e41 |
## </param>
|
|
Chris PeBenito |
ff7bc1 |
#
|
|
Chris PeBenito |
199895 |
interface(`selinux_set_enforce_mode',`
|
|
Chris PeBenito |
cbc9d6 |
gen_require(`
|
|
Chris PeBenito |
cbc9d6 |
type security_t;
|
|
Chris PeBenito |
cbc9d6 |
attribute can_setenforce;
|
|
Chris PeBenito |
cbc9d6 |
class dir { read search getattr };
|
|
Chris PeBenito |
cbc9d6 |
class file { getattr read write };
|
|
Chris PeBenito |
cbc9d6 |
class security setenforce;
|
|
Chris PeBenito |
cbc9d6 |
')
|
|
Chris PeBenito |
ff7bc1 |
|
|
Chris PeBenito |
ff7bc1 |
allow $1 security_t:dir { read search getattr };
|
|
Chris PeBenito |
ff7bc1 |
allow $1 security_t:file { getattr read write };
|
|
Chris PeBenito |
ff7bc1 |
allow $1 security_t:security setenforce;
|
|
Chris PeBenito |
ff7bc1 |
auditallow $1 security_t:security setenforce;
|
|
Chris PeBenito |
ff7bc1 |
typeattribute $1 can_setenforce;
|
|
Chris PeBenito |
ff7bc1 |
')
|
|
Chris PeBenito |
ff7bc1 |
|
|
Chris PeBenito |
ff7bc1 |
########################################
|
|
Chris PeBenito |
414e41 |
## <desc>
|
|
Chris PeBenito |
414e41 |
## Allow caller to load the policy into the kernel.
|
|
Chris PeBenito |
414e41 |
## </desc>
|
|
Chris PeBenito |
414e41 |
## <param name="domain">
|
|
Chris PeBenito |
414e41 |
## The process type that will load the policy.
|
|
Chris PeBenito |
414e41 |
## </param>
|
|
Chris PeBenito |
ff7bc1 |
#
|
|
Chris PeBenito |
199895 |
interface(`selinux_load_policy',`
|
|
Chris PeBenito |
cbc9d6 |
gen_require(`
|
|
Chris PeBenito |
cbc9d6 |
type security_t;
|
|
Chris PeBenito |
cbc9d6 |
attribute can_load_policy;
|
|
Chris PeBenito |
cbc9d6 |
class dir { read search getattr };
|
|
Chris PeBenito |
cbc9d6 |
class file { getattr read write };
|
|
Chris PeBenito |
cbc9d6 |
class security load_policy;
|
|
Chris PeBenito |
cbc9d6 |
')
|
|
Chris PeBenito |
ff7bc1 |
|
|
Chris PeBenito |
ff7bc1 |
allow $1 security_t:dir { read search getattr };
|
|
Chris PeBenito |
ff7bc1 |
allow $1 security_t:file { getattr read write };
|
|
Chris PeBenito |
ff7bc1 |
allow $1 security_t:security load_policy;
|
|
Chris PeBenito |
ff7bc1 |
auditallow $1 security_t:security load_policy;
|
|
Chris PeBenito |
ff7bc1 |
typeattribute $1 can_load_policy;
|
|
Chris PeBenito |
ff7bc1 |
')
|
|
Chris PeBenito |
ff7bc1 |
|
|
Chris PeBenito |
ff7bc1 |
########################################
|
|
Chris PeBenito |
414e41 |
## <desc>
|
|
Chris PeBenito |
414e41 |
## Allow caller to set the state of Booleans to
|
|
Chris PeBenito |
414e41 |
## enable or disable conditional portions of the policy.
|
|
Chris PeBenito |
414e41 |
## </desc>
|
|
Chris PeBenito |
414e41 |
## <param name="domain">
|
|
Chris PeBenito |
414e41 |
## The process type allowed to set the Boolean.
|
|
Chris PeBenito |
414e41 |
## </param>
|
|
Chris PeBenito |
414e41 |
## <param name="booltype" optional="true">
|
|
Chris PeBenito |
414e41 |
## The type of Booleans the caller is allowed to set.
|
|
Chris PeBenito |
414e41 |
## </param>
|
|
Chris PeBenito |
ff7bc1 |
#
|
|
Chris PeBenito |
199895 |
interface(`selinux_set_boolean',`
|
|
Chris PeBenito |
cbc9d6 |
gen_require(`
|
|
Chris PeBenito |
cbc9d6 |
type security_t;
|
|
Chris PeBenito |
cbc9d6 |
class dir { read search getattr };
|
|
Chris PeBenito |
cbc9d6 |
class file { getattr read write };
|
|
Chris PeBenito |
cbc9d6 |
class security setbool;
|
|
Chris PeBenito |
cbc9d6 |
')
|
|
Chris PeBenito |
ff7bc1 |
|
|
Chris PeBenito |
ff7bc1 |
ifelse(`$2',`',`
|
|
Chris PeBenito |
ff7bc1 |
allow $1 security_t:dir { getattr search read };
|
|
Chris PeBenito |
ff7bc1 |
allow $1 security_t:file { getattr read write };
|
|
Chris PeBenito |
ff7bc1 |
',`
|
|
Chris PeBenito |
ff7bc1 |
allow $1 $2:dir { getattr search read };
|
|
Chris PeBenito |
ff7bc1 |
allow $1 $2:file { getattr read write };
|
|
Chris PeBenito |
ff7bc1 |
')
|
|
Chris PeBenito |
ff7bc1 |
|
|
Chris PeBenito |
ff7bc1 |
allow $1 security_t:dir search;
|
|
Chris PeBenito |
ff7bc1 |
allow $1 security_t:security setbool;
|
|
Chris PeBenito |
ff7bc1 |
auditallow $1 security_t:security setbool;
|
|
Chris PeBenito |
ff7bc1 |
')
|
|
Chris PeBenito |
ff7bc1 |
|
|
Chris PeBenito |
ff7bc1 |
########################################
|
|
Chris PeBenito |
414e41 |
## <desc>
|
|
Chris PeBenito |
414e41 |
## Allow caller to set selinux security parameters.
|
|
Chris PeBenito |
414e41 |
## </desc>
|
|
Chris PeBenito |
414e41 |
## <param name="domain">
|
|
Chris PeBenito |
414e41 |
## The process type to allow to set security parameters.
|
|
Chris PeBenito |
414e41 |
## </param>
|
|
Chris PeBenito |
ff7bc1 |
#
|
|
Chris PeBenito |
199895 |
interface(`selinux_set_parameters',`
|
|
Chris PeBenito |
cbc9d6 |
gen_require(`
|
|
Chris PeBenito |
cbc9d6 |
type security_t;
|
|
Chris PeBenito |
cbc9d6 |
attribute can_setsecparam;
|
|
Chris PeBenito |
cbc9d6 |
class dir { read search getattr };
|
|
Chris PeBenito |
cbc9d6 |
class file { getattr read write };
|
|
Chris PeBenito |
cbc9d6 |
class security setsecparam;
|
|
Chris PeBenito |
cbc9d6 |
')
|
|
Chris PeBenito |
ff7bc1 |
|
|
Chris PeBenito |
ff7bc1 |
allow $1 security_t:dir { read search getattr };
|
|
Chris PeBenito |
ff7bc1 |
allow $1 security_t:file { getattr read write };
|
|
Chris PeBenito |
ff7bc1 |
allow $1 security_t:security setsecparam;
|
|
Chris PeBenito |
ff7bc1 |
auditallow $1 security_t:security setsecparam;
|
|
Chris PeBenito |
ff7bc1 |
typeattribute $1 can_setsecparam;
|
|
Chris PeBenito |
ff7bc1 |
')
|
|
Chris PeBenito |
ff7bc1 |
|
|
Chris PeBenito |
ff7bc1 |
########################################
|
|
Chris PeBenito |
414e41 |
## <desc>
|
|
Chris PeBenito |
414e41 |
## Allows caller to validate security contexts.
|
|
Chris PeBenito |
414e41 |
## </desc>
|
|
Chris PeBenito |
414e41 |
## <param name="domain">
|
|
Chris PeBenito |
414e41 |
## The process type permitted to validate contexts.
|
|
Chris PeBenito |
414e41 |
## </param>
|
|
Chris PeBenito |
ff7bc1 |
#
|
|
Chris PeBenito |
199895 |
interface(`selinux_validate_context',`
|
|
Chris PeBenito |
cbc9d6 |
gen_require(`
|
|
Chris PeBenito |
cbc9d6 |
type security_t;
|
|
Chris PeBenito |
cbc9d6 |
class dir { read search getattr };
|
|
Chris PeBenito |
cbc9d6 |
class file { getattr read write };
|
|
Chris PeBenito |
cbc9d6 |
class security check_context;
|
|
Chris PeBenito |
cbc9d6 |
')
|
|
Chris PeBenito |
ff7bc1 |
|
|
Chris PeBenito |
ff7bc1 |
allow $1 security_t:dir { read search getattr };
|
|
Chris PeBenito |
ff7bc1 |
allow $1 security_t:file { getattr read write };
|
|
Chris PeBenito |
ff7bc1 |
allow $1 security_t:security check_context;
|
|
Chris PeBenito |
ff7bc1 |
')
|
|
Chris PeBenito |
ff7bc1 |
|
|
Chris PeBenito |
ff7bc1 |
########################################
|
|
Chris PeBenito |
414e41 |
## <desc>
|
|
Chris PeBenito |
414e41 |
## Allows caller to compute an access vector.
|
|
Chris PeBenito |
414e41 |
## </desc>
|
|
Chris PeBenito |
414e41 |
## <param name="domain">
|
|
Chris PeBenito |
414e41 |
## The process type allowed to compute an access vector.
|
|
Chris PeBenito |
414e41 |
## </param>
|
|
Chris PeBenito |
ff7bc1 |
#
|
|
Chris PeBenito |
199895 |
interface(`selinux_compute_access_vector',`
|
|
Chris PeBenito |
cbc9d6 |
gen_require(`
|
|
Chris PeBenito |
cbc9d6 |
type security_t;
|
|
Chris PeBenito |
cbc9d6 |
class dir { read search getattr };
|
|
Chris PeBenito |
cbc9d6 |
class file { getattr read write };
|
|
Chris PeBenito |
cbc9d6 |
class security compute_av;
|
|
Chris PeBenito |
cbc9d6 |
')
|
|
Chris PeBenito |
ff7bc1 |
|
|
Chris PeBenito |
ff7bc1 |
allow $1 security_t:dir { read search getattr };
|
|
Chris PeBenito |
ff7bc1 |
allow $1 security_t:file { getattr read write };
|
|
Chris PeBenito |
ff7bc1 |
allow $1 security_t:security compute_av;
|
|
Chris PeBenito |
ff7bc1 |
')
|
|
Chris PeBenito |
ff7bc1 |
|
|
Chris PeBenito |
ff7bc1 |
########################################
|
|
Chris PeBenito |
414e41 |
## <desc>
|
|
Chris PeBenito |
414e41 |
##
|
|
Chris PeBenito |
414e41 |
## </desc>
|
|
Chris PeBenito |
414e41 |
## <param name="domain">
|
|
Chris PeBenito |
414e41 |
##
|
|
Chris PeBenito |
414e41 |
## </param>
|
|
Chris PeBenito |
ff7bc1 |
#
|
|
Chris PeBenito |
199895 |
interface(`selinux_compute_create_context',`
|
|
Chris PeBenito |
cbc9d6 |
gen_require(`
|
|
Chris PeBenito |
cbc9d6 |
type security_t;
|
|
Chris PeBenito |
cbc9d6 |
class dir { read search getattr };
|
|
Chris PeBenito |
cbc9d6 |
class file { getattr read write };
|
|
Chris PeBenito |
cbc9d6 |
class security compute_create;
|
|
Chris PeBenito |
cbc9d6 |
')
|
|
Chris PeBenito |
ff7bc1 |
|
|
Chris PeBenito |
ff7bc1 |
allow $1 security_t:dir { read search getattr };
|
|
Chris PeBenito |
ff7bc1 |
allow $1 security_t:file { getattr read write };
|
|
Chris PeBenito |
ff7bc1 |
allow $1 security_t:security compute_create;
|
|
Chris PeBenito |
ff7bc1 |
')
|
|
Chris PeBenito |
ff7bc1 |
|
|
Chris PeBenito |
ff7bc1 |
########################################
|
|
Chris PeBenito |
414e41 |
## <desc>
|
|
Chris PeBenito |
414e41 |
##
|
|
Chris PeBenito |
414e41 |
## </desc>
|
|
Chris PeBenito |
414e41 |
## <param name="domain">
|
|
Chris PeBenito |
414e41 |
## The process type to
|
|
Chris PeBenito |
414e41 |
## </param>
|
|
Chris PeBenito |
ff7bc1 |
#
|
|
Chris PeBenito |
199895 |
interface(`selinux_compute_relabel_context',`
|
|
Chris PeBenito |
cbc9d6 |
gen_require(`
|
|
Chris PeBenito |
cbc9d6 |
type security_t;
|
|
Chris PeBenito |
cbc9d6 |
class dir { read search getattr };
|
|
Chris PeBenito |
cbc9d6 |
class file { getattr read write };
|
|
Chris PeBenito |
cbc9d6 |
class security compute_relabel;
|
|
Chris PeBenito |
cbc9d6 |
')
|
|
Chris PeBenito |
ff7bc1 |
|
|
Chris PeBenito |
ff7bc1 |
allow $1 security_t:dir { read search getattr };
|
|
Chris PeBenito |
ff7bc1 |
allow $1 security_t:file { getattr read write };
|
|
Chris PeBenito |
ff7bc1 |
allow $1 security_t:security compute_relabel;
|
|
Chris PeBenito |
ff7bc1 |
')
|
|
Chris PeBenito |
ff7bc1 |
|
|
Chris PeBenito |
ff7bc1 |
########################################
|
|
Chris PeBenito |
414e41 |
## <desc>
|
|
Chris PeBenito |
414e41 |
## Allows caller to compute possible contexts for a user.
|
|
Chris PeBenito |
414e41 |
## </desc>
|
|
Chris PeBenito |
414e41 |
## <param name="domain">
|
|
Chris PeBenito |
414e41 |
## The process type allowed to compute user contexts.
|
|
Chris PeBenito |
414e41 |
## </param>
|
|
Chris PeBenito |
ff7bc1 |
#
|
|
Chris PeBenito |
199895 |
interface(`selinux_compute_user_contexts',`
|
|
Chris PeBenito |
cbc9d6 |
gen_require(`
|
|
Chris PeBenito |
cbc9d6 |
type security_t;
|
|
Chris PeBenito |
cbc9d6 |
class dir { read search getattr };
|
|
Chris PeBenito |
cbc9d6 |
class file { getattr read write };
|
|
Chris PeBenito |
cbc9d6 |
class security compute_user;
|
|
Chris PeBenito |
cbc9d6 |
')
|
|
Chris PeBenito |
ff7bc1 |
|
|
Chris PeBenito |
ff7bc1 |
allow $1 security_t:dir { read search getattr };
|
|
Chris PeBenito |
ff7bc1 |
allow $1 security_t:file { getattr read write };
|
|
Chris PeBenito |
ff7bc1 |
allow $1 security_t:security compute_user;
|
|
Chris PeBenito |
ff7bc1 |
')
|
|
Chris PeBenito |
ff7bc1 |
|
|
Chris PeBenito |
9726b3 |
########################################
|
|
Chris PeBenito |
9726b3 |
## <desc>
|
|
Chris PeBenito |
9726b3 |
## Unconfined access to the SELinux security server.
|
|
Chris PeBenito |
9726b3 |
## </desc>
|
|
Chris PeBenito |
9726b3 |
## <param name="domain">
|
|
Chris PeBenito |
9726b3 |
## Domain allowed access.
|
|
Chris PeBenito |
9726b3 |
## </param>
|
|
Chris PeBenito |
9726b3 |
#
|
|
Chris PeBenito |
9726b3 |
interface(`selinux_unconfined',`
|
|
Chris PeBenito |
9726b3 |
gen_require(`
|
|
Chris PeBenito |
9726b3 |
attribute can_load_policy, can_setenforce, can_setsecparam;
|
|
Chris PeBenito |
9726b3 |
type security_t;
|
|
Chris PeBenito |
9726b3 |
class security { load_policy setenforce setbool };
|
|
Chris PeBenito |
9726b3 |
')
|
|
Chris PeBenito |
9726b3 |
|
|
Chris PeBenito |
9726b3 |
# Access the security API.
|
|
Chris PeBenito |
9726b3 |
allow $1 security_t:security *;
|
|
Chris PeBenito |
9726b3 |
auditallow $1 security_t:security { load_policy setenforce setbool };
|
|
Chris PeBenito |
9726b3 |
|
|
Chris PeBenito |
9726b3 |
typeattribute $1 can_load_policy, can_setenforce, can_setsecparam;
|
|
Chris PeBenito |
9726b3 |
')
|