##
## Policy for kernel security interface, in particular, selinuxfs.
##
##
## Contains the policy for the kernel SELinux security interface.
##
########################################
##
## Gets the caller the mountpoint of the selinuxfs filesystem.
##
##
## The process type requesting the selinuxfs mountpoint.
##
#
interface(`selinux_get_fs_mount',`
# read /proc/filesystems to see if selinuxfs is supported
# then read /proc/self/mount to see where selinuxfs is mounted
kernel_read_system_state($1)
')
########################################
##
## Do not audit attempts to get the
## attributes of the selinuxfs directory.
##
##
## Domain to not audit.
##
#
interface(`selinux_dontaudit_getattr_dir',`
gen_require(`
type security_t;
')
dontaudit $1 security_t:dir getattr;
')
########################################
##
## Search selinuxfs.
##
##
## Domain allowed access.
##
#
interface(`selinux_search_fs',`
gen_require(`
type security_t;
')
allow $1 security_t:dir search;
')
########################################
##
## Do not audit attempts to search selinuxfs.
##
##
## Domain to not audit.
##
#
interface(`selinux_dontaudit_search_fs',`
gen_require(`
type security_t;
')
dontaudit $1 security_t:dir search;
')
########################################
##
## Do not audit attempts to read
## generic selinuxfs entries
##
##
## Domain to not audit.
##
#
interface(`selinux_dontaudit_read_fs',`
gen_require(`
type security_t;
')
dontaudit $1 security_t:dir search;
dontaudit $1 security_t:file { getattr read };
')
########################################
##
## Allows the caller to get the mode of policy enforcement
## (enforcing or permissive mode).
##
##
## The process type to allow to get the enforcing mode.
##
#
interface(`selinux_get_enforce_mode',`
gen_require(`
type security_t;
')
allow $1 security_t:dir { read search getattr };
allow $1 security_t:file { getattr read };
')
########################################
##
## Allow caller to set the mode of policy enforcement
## (enforcing or permissive mode).
##
##
##
## Allow caller to set the mode of policy enforcement
## (enforcing or permissive mode).
##
##
## Since this is a security event, this action is
## always audited.
##
##
##
## The process type to allow to set the enforcement mode.
##
#
interface(`selinux_set_enforce_mode',`
gen_require(`
type security_t;
attribute can_setenforce;
bool secure_mode_policyload;
')
allow $1 security_t:dir { read search getattr };
allow $1 security_t:file { getattr read write };
typeattribute $1 can_setenforce;
if(!secure_mode_policyload) {
allow $1 security_t:security setenforce;
auditallow $1 security_t:security setenforce;
}
')
########################################
##
## Allow caller to load the policy into the kernel.
##
##
## The process type that will load the policy.
##
#
interface(`selinux_load_policy',`
gen_require(`
type security_t;
attribute can_load_policy;
bool secure_mode_policyload;
')
allow $1 security_t:dir { read search getattr };
allow $1 security_t:file { getattr read write };
typeattribute $1 can_load_policy;
if(!secure_mode_policyload) {
allow $1 security_t:security load_policy;
auditallow $1 security_t:security load_policy;
}
')
########################################
##
## Allow caller to set the state of Booleans to
## enable or disable conditional portions of the policy.
##
##
##
## Allow caller to set the state of Booleans to
## enable or disable conditional portions of the policy.
##
##
## Since this is a security event, this action is
## always audited.
##
##
##
## The process type allowed to set the Boolean.
##
#
interface(`selinux_set_boolean',`
gen_require(`
type security_t;
')
allow $1 security_t:dir search;
allow $1 security_t:dir { getattr search read };
allow $1 security_t:file { getattr read write };
if(!secure_mode_policyload) {
allow $1 security_t:security setbool;
auditallow $1 security_t:security setbool;
}
')
########################################
##
## Allow caller to set SELinux access vector cache parameters.
##
##
##
## Allow caller to set SELinux access vector cache parameters.
## The allows the domain to set performance related parameters
## of the AVC, such as cache threshold.
##
##
## Since this is a security event, this action is
## always audited.
##
##
##
## The process type to allow to set security parameters.
##
#
interface(`selinux_set_parameters',`
gen_require(`
type security_t;
attribute can_setsecparam;
')
allow $1 security_t:dir { read search getattr };
allow $1 security_t:file { getattr read write };
allow $1 security_t:security setsecparam;
auditallow $1 security_t:security setsecparam;
typeattribute $1 can_setsecparam;
')
########################################
##
## Allows caller to validate security contexts.
##
##
## The process type permitted to validate contexts.
##
#
interface(`selinux_validate_context',`
gen_require(`
type security_t;
')
allow $1 security_t:dir { read search getattr };
allow $1 security_t:file { getattr read write };
allow $1 security_t:security check_context;
')
########################################
##
## Allows caller to compute an access vector.
##
##
## The process type allowed to compute an access vector.
##
#
interface(`selinux_compute_access_vector',`
gen_require(`
type security_t;
')
allow $1 security_t:dir { read search getattr };
allow $1 security_t:file { getattr read write };
allow $1 security_t:security compute_av;
')
########################################
##
## Calculate the default type for object creation.
##
##
## Domain allowed access.
##
#
interface(`selinux_compute_create_context',`
gen_require(`
type security_t;
')
allow $1 security_t:dir { read search getattr };
allow $1 security_t:file { getattr read write };
allow $1 security_t:security compute_create;
')
########################################
##
## Allows caller to compute polyinstatntiated
## directory members.
##
##
## Domain allowed access.
##
#
interface(`selinux_compute_member',`
gen_require(`
type security_t;
')
allow $1 security_t:dir { read search getattr };
allow $1 security_t:file { getattr read write };
allow $1 security_t:security compute_member;
')
########################################
##
## Calculate the context for relabeling objects.
##
##
##
## Calculate the context for relabeling objects.
## This is determined by using the type_change
## rules in the policy, and is generally used
## for determining the context for relabeling
## a terminal when a user logs in.
##
##
##
## Domain allowed access.
##
#
interface(`selinux_compute_relabel_context',`
gen_require(`
type security_t;
')
allow $1 security_t:dir { read search getattr };
allow $1 security_t:file { getattr read write };
allow $1 security_t:security compute_relabel;
')
########################################
##
## Allows caller to compute possible contexts for a user.
##
##
## The process type allowed to compute user contexts.
##
#
interface(`selinux_compute_user_contexts',`
gen_require(`
type security_t;
')
allow $1 security_t:dir { read search getattr };
allow $1 security_t:file { getattr read write };
allow $1 security_t:security compute_user;
')
########################################
##
## Unconfined access to the SELinux kernel security server.
##
##
## Domain allowed access.
##
#
interface(`selinux_unconfined',`
gen_require(`
attribute can_load_policy, can_setenforce, can_setsecparam;
bool secure_mode_policyload;
type security_t;
')
# use SELinuxfs
allow $1 security_t:dir { getattr search read };
allow $1 security_t:file { getattr read write };
typeattribute $1 can_load_policy, can_setenforce, can_setsecparam;
if(!secure_mode_policyload) {
# Access the security API.
allow $1 security_t:security *;
auditallow $1 security_t:security { load_policy setenforce setbool };
}
')