|
Chris PeBenito |
0fbfa5 |
#DESC PPPD - PPP daemon
|
|
Chris PeBenito |
0fbfa5 |
#
|
|
Chris PeBenito |
0fbfa5 |
# Author: Russell Coker
|
|
Chris PeBenito |
0fbfa5 |
# X-Debian-Packages: ppp
|
|
Chris PeBenito |
0fbfa5 |
#
|
|
Chris PeBenito |
0fbfa5 |
|
|
Chris PeBenito |
0fbfa5 |
#################################
|
|
Chris PeBenito |
0fbfa5 |
#
|
|
Chris PeBenito |
0fbfa5 |
# Rules for the pppd_t domain, et al.
|
|
Chris PeBenito |
0fbfa5 |
#
|
|
Chris PeBenito |
0fbfa5 |
# pppd_t is the domain for the pppd program.
|
|
Chris PeBenito |
0fbfa5 |
# pppd_exec_t is the type of the pppd executable.
|
|
Chris PeBenito |
0fbfa5 |
# pppd_secret_t is the type of the pap and chap password files
|
|
Chris PeBenito |
0fbfa5 |
#
|
|
Chris PeBenito |
0fbfa5 |
bool pppd_for_user false;
|
|
Chris PeBenito |
0fbfa5 |
|
|
Chris PeBenito |
0fbfa5 |
daemon_domain(pppd, `, privmail')
|
|
Chris PeBenito |
0fbfa5 |
type pppd_secret_t, file_type, sysadmfile;
|
|
Chris PeBenito |
0fbfa5 |
|
|
Chris PeBenito |
0fbfa5 |
# Define a separate type for /etc/ppp
|
|
Chris PeBenito |
0fbfa5 |
etcdir_domain(pppd)
|
|
Chris PeBenito |
0fbfa5 |
# Define a separate type for writable files under /etc/ppp
|
|
Chris PeBenito |
0fbfa5 |
type pppd_etc_rw_t, file_type, sysadmfile;
|
|
Chris PeBenito |
0fbfa5 |
# Automatically label newly created files under /etc/ppp with this type
|
|
Chris PeBenito |
0fbfa5 |
file_type_auto_trans(pppd_t, pppd_etc_t, pppd_etc_rw_t, file)
|
|
Chris PeBenito |
0fbfa5 |
|
|
Chris PeBenito |
0fbfa5 |
# for SSP
|
|
Chris PeBenito |
0fbfa5 |
allow pppd_t urandom_device_t:chr_file read;
|
|
Chris PeBenito |
0fbfa5 |
|
|
Chris PeBenito |
0fbfa5 |
allow pppd_t sysfs_t:dir search;
|
|
Chris PeBenito |
0fbfa5 |
|
|
Chris PeBenito |
0fbfa5 |
log_domain(pppd)
|
|
Chris PeBenito |
0fbfa5 |
|
|
Chris PeBenito |
0fbfa5 |
# Use the network.
|
|
Chris PeBenito |
0fbfa5 |
can_network_server(pppd_t)
|
|
Chris PeBenito |
0fbfa5 |
can_ypbind(pppd_t)
|
|
Chris PeBenito |
0fbfa5 |
|
|
Chris PeBenito |
0fbfa5 |
# Use capabilities.
|
|
Chris PeBenito |
0fbfa5 |
allow pppd_t self:capability { net_admin setuid setgid fsetid };
|
|
Chris PeBenito |
0fbfa5 |
|
|
Chris PeBenito |
0fbfa5 |
allow pppd_t var_lock_t:dir rw_dir_perms;
|
|
Chris PeBenito |
0fbfa5 |
allow pppd_t var_lock_t:file create_file_perms;
|
|
Chris PeBenito |
0fbfa5 |
|
|
Chris PeBenito |
0fbfa5 |
# Access secret files
|
|
Chris PeBenito |
0fbfa5 |
allow pppd_t pppd_secret_t:file r_file_perms;
|
|
Chris PeBenito |
0fbfa5 |
|
|
Chris PeBenito |
0fbfa5 |
ifdef(`postfix.te', `
|
|
Chris PeBenito |
0fbfa5 |
allow pppd_t postfix_etc_t:dir search;
|
|
Chris PeBenito |
0fbfa5 |
allow pppd_t postfix_etc_t:file r_file_perms;
|
|
Chris PeBenito |
0fbfa5 |
allow pppd_t postfix_master_exec_t:file read;
|
|
Chris PeBenito |
0fbfa5 |
allow postfix_postqueue_t pppd_t:fd use;
|
|
Chris PeBenito |
0fbfa5 |
allow postfix_postqueue_t pppd_t:process sigchld;
|
|
Chris PeBenito |
0fbfa5 |
')
|
|
Chris PeBenito |
0fbfa5 |
|
|
Chris PeBenito |
0fbfa5 |
# allow running ip-up and ip-down scripts and running chat.
|
|
Chris PeBenito |
0fbfa5 |
can_exec(pppd_t, { shell_exec_t bin_t sbin_t etc_t ifconfig_exec_t })
|
|
Chris PeBenito |
0fbfa5 |
allow pppd_t { bin_t sbin_t }:dir search;
|
|
Chris PeBenito |
0fbfa5 |
allow pppd_t bin_t:lnk_file read;
|
|
Chris PeBenito |
0fbfa5 |
|
|
Chris PeBenito |
0fbfa5 |
# Access /dev/ppp.
|
|
Chris PeBenito |
0fbfa5 |
allow pppd_t ppp_device_t:chr_file rw_file_perms;
|
|
Chris PeBenito |
0fbfa5 |
allow pppd_t devtty_t:chr_file { read write };
|
|
Chris PeBenito |
0fbfa5 |
|
|
Chris PeBenito |
0fbfa5 |
allow pppd_t self:unix_dgram_socket create_socket_perms;
|
|
Chris PeBenito |
0fbfa5 |
allow pppd_t self:unix_stream_socket create_socket_perms;
|
|
Chris PeBenito |
0fbfa5 |
|
|
Chris PeBenito |
0fbfa5 |
allow pppd_t proc_t:dir search;
|
|
Chris PeBenito |
0fbfa5 |
allow pppd_t proc_t:{ file lnk_file } r_file_perms;
|
|
Chris PeBenito |
0fbfa5 |
|
|
Chris PeBenito |
0fbfa5 |
allow pppd_t etc_runtime_t:file r_file_perms;
|
|
Chris PeBenito |
0fbfa5 |
|
|
Chris PeBenito |
0fbfa5 |
allow pppd_t self:socket create_socket_perms;
|
|
Chris PeBenito |
0fbfa5 |
|
|
Chris PeBenito |
0fbfa5 |
allow pppd_t tty_device_t:chr_file { setattr rw_file_perms };
|
|
Chris PeBenito |
0fbfa5 |
|
|
Chris PeBenito |
0fbfa5 |
allow pppd_t devpts_t:dir search;
|
|
Chris PeBenito |
0fbfa5 |
|
|
Chris PeBenito |
0fbfa5 |
# for scripts
|
|
Chris PeBenito |
0fbfa5 |
allow pppd_t self:fifo_file rw_file_perms;
|
|
Chris PeBenito |
0fbfa5 |
allow pppd_t etc_t:lnk_file read;
|
|
Chris PeBenito |
0fbfa5 |
|
|
Chris PeBenito |
0fbfa5 |
# for ~/.ppprc - if it actually exists then you need some policy to read it
|
|
Chris PeBenito |
0fbfa5 |
allow pppd_t { sysadm_home_dir_t home_root_t user_home_dir_type }:dir search;
|
|
Chris PeBenito |
0fbfa5 |
|
|
Chris PeBenito |
0fbfa5 |
in_user_role(pppd_t)
|
|
Chris PeBenito |
0fbfa5 |
if (pppd_for_user) {
|
|
Chris PeBenito |
0fbfa5 |
# Run pppd in pppd_t by default for user
|
|
Chris PeBenito |
0fbfa5 |
domain_auto_trans(unpriv_userdomain, pppd_exec_t, pppd_t)
|
|
Chris PeBenito |
0fbfa5 |
allow unpriv_userdomain pppd_t:process signal;
|
|
Chris PeBenito |
0fbfa5 |
}
|
|
Chris PeBenito |
0fbfa5 |
|
|
Chris PeBenito |
0fbfa5 |
# for pppoe
|
|
Chris PeBenito |
0fbfa5 |
can_create_pty(pppd)
|
|
Chris PeBenito |
0fbfa5 |
allow pppd_t self:file { read getattr };
|
|
Chris PeBenito |
0fbfa5 |
allow pppd_t self:capability { fowner net_raw };
|
|
Chris PeBenito |
0fbfa5 |
allow pppd_t self:packet_socket create_socket_perms;
|
|
Chris PeBenito |
0fbfa5 |
|
|
Chris PeBenito |
0fbfa5 |
file_type_auto_trans(pppd_t, etc_t, net_conf_t, file)
|
|
Chris PeBenito |
0fbfa5 |
tmp_domain(pppd)
|