Chris PeBenito e181fe
# Copyright (C) 2005 Tresys Technology, LLC
Chris PeBenito e181fe
Chris PeBenito b4cd15
#######################################
Chris PeBenito b4cd15
#
Chris PeBenito 3ce6cb
# logging_make_log_file(domain)
Chris PeBenito b4cd15
#
Chris PeBenito b4cd15
define(`logging_make_log_file',`
Chris PeBenito bd202f
requires_block_template(`$0'_depend)
Chris PeBenito 3ce6cb
files_make_file($1)
Chris PeBenito b4cd15
typeattribute $1 logfile;
Chris PeBenito b4cd15
')
Chris PeBenito b4cd15
Chris PeBenito b4cd15
define(`logging_make_log_file_depend',`
Chris PeBenito b4cd15
attribute logfile;
Chris PeBenito b4cd15
')
Chris PeBenito b4cd15
Chris PeBenito fb1aee
########################################
Chris PeBenito fb1aee
#
Chris PeBenito fb1aee
# logging_create_private_log(domain,privatetype,[class(es)])
Chris PeBenito fb1aee
#
Chris PeBenito fb1aee
define(`logging_create_private_log',`
Chris PeBenito fb1aee
requires_block_template(`$0'_depend)
Chris PeBenito fb1aee
allow $1 var_log_t:dir { getattr search read write add_name remove_name };
Chris PeBenito fb1aee
ifelse(`$3',`',`
Chris PeBenito fb1aee
type_transition $1 var_log_t:file $2;
Chris PeBenito fb1aee
',`
Chris PeBenito fb1aee
type_transition $1 var_log_t:$3 $2;
Chris PeBenito fb1aee
') dnl end ifelse
Chris PeBenito fb1aee
')
Chris PeBenito fb1aee
Chris PeBenito fb1aee
define(`logging_create_private_log_depend',`
Chris PeBenito fb1aee
type var_log_t;
Chris PeBenito fb1aee
class dir { getattr search read write add_name remove_name };
Chris PeBenito fb1aee
')
Chris PeBenito fb1aee
Chris PeBenito b4cd15
#######################################
Chris PeBenito b4cd15
#
Chris PeBenito 3ce6cb
# logging_send_system_log_message(domain)
Chris PeBenito 8c7717
#
Chris PeBenito 8c7717
define(`logging_send_system_log_message',`
Chris PeBenito bd202f
requires_block_template(`$0'_depend)
Chris PeBenito 5a9522
allow $1 devlog_t:lnk_file read;
Chris PeBenito 8c7717
allow $1 devlog_t:sock_file { ioctl read getattr lock write append };
Chris PeBenito 8c7717
# the type of socket depends on the syslog daemon
Chris PeBenito 8c7717
allow $1 syslogd_t:unix_dgram_socket sendto;
Chris PeBenito 8c7717
allow $1 syslogd_t:unix_stream_socket connectto;
Chris PeBenito 8c7717
allow $1 self:unix_dgram_socket { create read getattr write setattr append bind connect getopt setopt shutdown };
Chris PeBenito 8c7717
allow $1 self:unix_stream_socket { create read getattr write setattr append bind connect getopt setopt shutdown };
Chris PeBenito f1470e
# cjp: this should most likely be removed:
Chris PeBenito f1470e
terminal_use_console($1)
Chris PeBenito 8c7717
')
Chris PeBenito 8c7717
Chris PeBenito 8c7717
define(`logging_send_system_log_message_depend',`
Chris PeBenito 8c7717
type syslogd_t, devlog_t;
Chris PeBenito 8c7717
class sock_file { ioctl read getattr lock write append };
Chris PeBenito 8c7717
class unix_dgram_socket { create read getattr write setattr append bind connect getopt setopt shutdown sendto };
Chris PeBenito 8c7717
class unix_stream_socket { create read getattr write setattr append bind connect getopt setopt shutdown connectto };
Chris PeBenito 8c7717
')
Chris PeBenito 8c7717
Chris PeBenito daa0e0
########################################
Chris PeBenito daa0e0
## <interface name="logging_search_system_log_directory">
Chris PeBenito daa0e0
##	<description>
Chris PeBenito daa0e0
##		Allows the domain to open a file in the
Chris PeBenito daa0e0
##		log directory, but does not allow the listing
Chris PeBenito daa0e0
##		of the contents of the log directory.
Chris PeBenito daa0e0
##	</description>
Chris PeBenito daa0e0
##	<parameter name="domain">
Chris PeBenito daa0e0
##		The type of the process performing this action.
Chris PeBenito daa0e0
##	</parameter>
Chris PeBenito daa0e0
##	<infoflow type="read" weight="3"/>
Chris PeBenito daa0e0
## </interface>
Chris PeBenito 3ce6cb
#
Chris PeBenito 3ce6cb
define(`logging_search_system_log_directory',`
Chris PeBenito bd202f
requires_block_template(`$0'_depend)
Chris PeBenito 3ce6cb
files_search_system_state_data_directory($1)
Chris PeBenito 3ce6cb
allow $1 var_log_t:dir search;
Chris PeBenito 3ce6cb
')
Chris PeBenito 3ce6cb
Chris PeBenito 3ce6cb
define(`logging_search_system_log_directory_depend',`
Chris PeBenito 3ce6cb
type var_log_t;
Chris PeBenito 3ce6cb
class dir search;
Chris PeBenito 3ce6cb
')
Chris PeBenito 3ce6cb
Chris PeBenito 3ce6cb
#######################################
Chris PeBenito 3ce6cb
#
Chris PeBenito b16c6b
# logging_ignore_get_all_logs_attributes(domain)
Chris PeBenito b16c6b
#
Chris PeBenito b16c6b
define(`logging_ignore_get_all_logs_attributes',`
Chris PeBenito b16c6b
requires_block_template(`$0'_depend)
Chris PeBenito b16c6b
dontaudit $1 logfile:file getattr;
Chris PeBenito b16c6b
')
Chris PeBenito b16c6b
Chris PeBenito b16c6b
define(`logging_ignore_get_all_logs_attributes_depend',`
Chris PeBenito b16c6b
attribute logfile;
Chris PeBenito b16c6b
class file getattr;
Chris PeBenito b16c6b
')
Chris PeBenito b16c6b
Chris PeBenito b16c6b
#######################################
Chris PeBenito b16c6b
#
Chris PeBenito 3ce6cb
# logging_append_all_logs(domain)
Chris PeBenito b4cd15
#
Chris PeBenito b4cd15
define(`logging_append_all_logs',`
Chris PeBenito bd202f
requires_block_template(`$0'_depend)
Chris PeBenito 3ce6cb
files_search_system_state_data_directory($1)
Chris PeBenito b4cd15
allow $1 var_log_t:dir { getattr search read };
Chris PeBenito b4cd15
allow $1 logfile:file { getattr append };
Chris PeBenito b4cd15
')
Chris PeBenito b4cd15
Chris PeBenito b4cd15
define(`logging_append_all_logs_depend',`
Chris PeBenito b4cd15
attribute logfile;
Chris PeBenito b4cd15
type var_log_t;
Chris PeBenito b4cd15
class dir { getattr search read };
Chris PeBenito b4cd15
class file { getattr append };
Chris PeBenito b4cd15
')
Chris PeBenito b4cd15
Chris PeBenito b4cd15
#######################################
Chris PeBenito b4cd15
#
Chris PeBenito 3ce6cb
# logging_read_all_logs(domain)
Chris PeBenito b4cd15
#
Chris PeBenito b4cd15
define(`logging_read_all_logs',`
Chris PeBenito bd202f
requires_block_template(`$0'_depend)
Chris PeBenito 3ce6cb
files_search_system_state_data_directory($1)
Chris PeBenito b4cd15
allow $1 var_log_t:dir { getattr search read };
Chris PeBenito b4cd15
allow $1 logfile:file { getattr read };
Chris PeBenito b4cd15
')
Chris PeBenito b4cd15
Chris PeBenito b4cd15
define(`logging_read_all_logs_depend',`
Chris PeBenito b4cd15
attribute logfile;
Chris PeBenito b4cd15
type var_log_t;
Chris PeBenito b4cd15
class dir { getattr search read };
Chris PeBenito b4cd15
class file { getattr read };
Chris PeBenito b4cd15
')
Chris PeBenito b4cd15
Chris PeBenito b4cd15
#######################################
Chris PeBenito b4cd15
#
Chris PeBenito 24280a
# logging_read_system_logs(domain)
Chris PeBenito 24280a
#
Chris PeBenito 24280a
define(`logging_read_system_logs',`
Chris PeBenito 24280a
requires_block_template(`$0'_depend)
Chris PeBenito 24280a
files_search_system_state_data_directory($1)
Chris PeBenito 24280a
allow $1 var_log_t:dir { getattr search read };
Chris PeBenito 24280a
allow $1 var_log_t:file { getattr read };
Chris PeBenito 24280a
')
Chris PeBenito 24280a
Chris PeBenito 24280a
define(`logging_read_system_logs_depend',`
Chris PeBenito 24280a
type var_log_t;
Chris PeBenito 24280a
class dir { getattr search read };
Chris PeBenito 24280a
class file { getattr read };
Chris PeBenito 24280a
')
Chris PeBenito 24280a
Chris PeBenito 24280a
#######################################
Chris PeBenito 24280a
#
Chris PeBenito d490eb
# logging_write_system_logs(domain)
Chris PeBenito d490eb
#
Chris PeBenito d490eb
define(`logging_write_system_logs',`
Chris PeBenito d490eb
requires_block_template(`$0'_depend)
Chris PeBenito d490eb
files_search_system_state_data_directory($1)
Chris PeBenito d490eb
allow $1 var_log_t:dir { getattr search read };
Chris PeBenito d490eb
allow $1 var_log_t:file { getattr write };
Chris PeBenito d490eb
')
Chris PeBenito d490eb
Chris PeBenito d490eb
define(`logging_write_system_logs_depend',`
Chris PeBenito d490eb
type var_log_t;
Chris PeBenito d490eb
class dir { getattr search read };
Chris PeBenito d490eb
class file { getattr write };
Chris PeBenito d490eb
')
Chris PeBenito d490eb
Chris PeBenito d490eb
#######################################
Chris PeBenito d490eb
#
Chris PeBenito 3ce6cb
# logging_modify_system_logs(domain)
Chris PeBenito b4cd15
#
Chris PeBenito b4cd15
define(`logging_modify_system_logs',`
Chris PeBenito bd202f
requires_block_template(`$0'_depend)
Chris PeBenito 3ce6cb
files_search_system_state_data_directory($1)
Chris PeBenito b4cd15
allow $1 var_log_t:dir { getattr search read };
Chris PeBenito b4cd15
allow $1 var_log_t:file { getattr read write append };
Chris PeBenito b4cd15
')
Chris PeBenito b4cd15
Chris PeBenito b4cd15
define(`logging_modify_system_logs_depend',`
Chris PeBenito b4cd15
type var_log_t;
Chris PeBenito b4cd15
class dir { getattr search read };
Chris PeBenito b4cd15
class file { getattr read write append };
Chris PeBenito b4cd15
')