2174 lines
47 KiB
Plaintext
2174 lines
47 KiB
Plaintext
## <summary>
|
|
## Device nodes and interfaces for many basic system devices.
|
|
## </summary>
|
|
## <desc>
|
|
## <p>
|
|
## This module creates the device node concept and provides
|
|
## the policy for many of the device files. Notable exceptions are
|
|
## the mass storage and terminal devices that are covered by other
|
|
## modules.
|
|
## </p>
|
|
## <p>
|
|
## This module creates the concept of a device node. That is a
|
|
## char or block device file, usually in /dev. All types that
|
|
## are used to label device nodes should use the dev_node macro.
|
|
## </p>
|
|
## <p>
|
|
## Additionally, this module controls access to three things:
|
|
## <ul>
|
|
## <li>the device directories containing device nodes</li>
|
|
## <li>device nodes as a group</li>
|
|
## <li>individual access to specific device nodes covered by
|
|
## this module.</li>
|
|
## </ul>
|
|
## </p>
|
|
## </desc>
|
|
|
|
########################################
|
|
## <summary>
|
|
## Make the passed in type a type appropriate for
|
|
## use on device nodes (usually files in /dev).
|
|
## </summary>
|
|
## <param name="object_type">
|
|
## The object type that will be used on device nodes.
|
|
## </param>
|
|
#
|
|
interface(`dev_node',`
|
|
gen_require(`
|
|
attribute device_node;
|
|
')
|
|
|
|
typeattribute $1 device_node;
|
|
|
|
fs_associate($1)
|
|
|
|
optional_policy(`distro_redhat',`
|
|
fs_associate_tmpfs($1)
|
|
')
|
|
')
|
|
|
|
########################################
|
|
## <summary>
|
|
## Allow full relabeling (to and from) of all device nodes.
|
|
## </summary>
|
|
## <param name="domain">
|
|
## Domain allowed to relabel.
|
|
## </param>
|
|
#
|
|
interface(`dev_relabel_all_dev_nodes',`
|
|
gen_require(`
|
|
attribute device_node;
|
|
type device_t;
|
|
class dir { getattr relabelfrom };
|
|
class file { getattr relabelfrom };
|
|
class lnk_file { getattr relabelfrom };
|
|
class fifo_file { getattr relabelfrom };
|
|
class sock_file { getattr relabelfrom };
|
|
class blk_file { getattr relabelfrom relabelto };
|
|
class chr_file { getattr relabelfrom relabelto };
|
|
')
|
|
|
|
allow $1 device_node:dir { getattr relabelfrom };
|
|
allow $1 device_node:file { getattr relabelfrom };
|
|
allow $1 device_node:lnk_file { getattr relabelfrom };
|
|
allow $1 device_node:fifo_file { getattr relabelfrom };
|
|
allow $1 device_node:sock_file { getattr relabelfrom };
|
|
allow $1 { device_t device_node }:blk_file { getattr relabelfrom relabelto };
|
|
allow $1 { device_t device_node }:chr_file { getattr relabelfrom relabelto };
|
|
')
|
|
|
|
########################################
|
|
## <summary>
|
|
## List all of the device nodes in a device directory.
|
|
## </summary>
|
|
## <param name="domain">
|
|
## Domain allowed to list device nodes.
|
|
## </param>
|
|
#
|
|
interface(`dev_list_all_dev_nodes',`
|
|
gen_require(`
|
|
type device_t;
|
|
class dir r_dir_perms;
|
|
class lnk_file { getattr read };
|
|
')
|
|
|
|
allow $1 device_t:dir r_dir_perms;
|
|
allow $1 device_t:lnk_file { getattr read };
|
|
')
|
|
|
|
########################################
|
|
## <summary>
|
|
## Set the attributes of /dev directories.
|
|
## </summary>
|
|
## <param name="domain">
|
|
## Domain allowed access.
|
|
## </param>
|
|
#
|
|
interface(`dev_setattr_dev_dir',`
|
|
gen_require(`
|
|
type device_t;
|
|
class dir setattr;
|
|
')
|
|
|
|
allow $1 device_t:dir setattr;
|
|
')
|
|
|
|
########################################
|
|
## <summary>
|
|
## Dontaudit attempts to list all device nodes.
|
|
## </summary>
|
|
## <param name="domain">
|
|
## Domain to dontaudit listing of device nodes.
|
|
## </param>
|
|
#
|
|
interface(`dev_dontaudit_list_all_dev_nodes',`
|
|
gen_require(`
|
|
type device_t;
|
|
class dir r_dir_perms;
|
|
')
|
|
|
|
dontaudit $1 device_t:dir r_dir_perms;
|
|
')
|
|
|
|
########################################
|
|
## <summary>
|
|
## Create a directory in the device directory.
|
|
## </summary>
|
|
## <param name="domain">
|
|
## Domain allowed to create the directory.
|
|
## </param>
|
|
#
|
|
interface(`dev_create_dir',`
|
|
gen_require(`
|
|
type device_t;
|
|
class dir { ra_dir_perms create };
|
|
')
|
|
|
|
allow $1 device_t:dir { ra_dir_perms create };
|
|
')
|
|
|
|
########################################
|
|
## <summary>
|
|
## Allow full relabeling (to and from) of directories in /dev.
|
|
## </summary>
|
|
## <param name="domain">
|
|
## Domain allowed to relabel.
|
|
## </param>
|
|
#
|
|
interface(`dev_relabel_dev_dirs',`
|
|
gen_require(`
|
|
type device_t;
|
|
class dir { r_dir_perms relabelfrom relabelto };
|
|
')
|
|
|
|
allow $1 device_t:dir { r_dir_perms relabelfrom relabelto };
|
|
')
|
|
|
|
########################################
|
|
## <summary>
|
|
## Read and write generic files in /dev.
|
|
## </summary>
|
|
## <param name="domain">
|
|
## Domain allowed access.
|
|
## </param>
|
|
#
|
|
interface(`dev_rw_generic_file',`
|
|
gen_require(`
|
|
type device_t;
|
|
class dir search;
|
|
class file rw_file_perms;
|
|
')
|
|
|
|
allow $1 device_t:dir search;
|
|
allow $1 device_t:file rw_file_perms;
|
|
')
|
|
|
|
########################################
|
|
## <summary>
|
|
## Dontaudit getattr on generic pipes.
|
|
## </summary>
|
|
## <param name="domain">
|
|
## Domain to dontaudit.
|
|
## </param>
|
|
#
|
|
interface(`dev_dontaudit_getattr_generic_pipe',`
|
|
gen_require(`
|
|
type device_t;
|
|
class fifo_file getattr;
|
|
')
|
|
|
|
dontaudit $1 device_t:fifo_file getattr;
|
|
')
|
|
|
|
########################################
|
|
## <summary>
|
|
## Allow getattr on generic block devices.
|
|
## </summary>
|
|
## <param name="domain">
|
|
## Domain allowed access.
|
|
## </param>
|
|
#
|
|
interface(`dev_getattr_generic_blk_file',`
|
|
gen_require(`
|
|
type device_t;
|
|
class dir r_dir_perms;
|
|
class blk_file getattr;
|
|
')
|
|
|
|
allow $1 device_t:dir r_dir_perms;
|
|
allow $1 device_t:blk_file getattr;
|
|
')
|
|
|
|
########################################
|
|
## <summary>
|
|
## Dontaudit getattr on generic block devices.
|
|
## </summary>
|
|
## <param name="domain">
|
|
## Domain to dontaudit access.
|
|
## </param>
|
|
#
|
|
interface(`dev_dontaudit_getattr_generic_blk_file',`
|
|
gen_require(`
|
|
type device_t;
|
|
class blk_file getattr;
|
|
')
|
|
|
|
dontaudit $1 device_t:blk_file getattr;
|
|
')
|
|
|
|
########################################
|
|
## <summary>
|
|
## Dontaudit setattr on generic block devices.
|
|
## </summary>
|
|
## <param name="domain">
|
|
## Domain to dontaudit access.
|
|
## </param>
|
|
#
|
|
interface(`dev_dontaudit_setattr_generic_blk_file',`
|
|
gen_require(`
|
|
type device_t;
|
|
class blk_file setattr;
|
|
')
|
|
|
|
dontaudit $1 device_t:blk_file setattr;
|
|
')
|
|
|
|
########################################
|
|
## <summary>
|
|
## Allow read, write, create, and delete for generic
|
|
## block files.
|
|
## </summary>
|
|
## <param name="domain">
|
|
## Domain allowed access.
|
|
## </param>
|
|
#
|
|
interface(`dev_manage_generic_blk_file',`
|
|
gen_require(`
|
|
type device_t;
|
|
class blk_file create_file_perms;
|
|
')
|
|
|
|
allow $1 device_t:dir rw_dir_perms;
|
|
allow $1 device_t:blk_file create_file_perms;
|
|
')
|
|
|
|
########################################
|
|
## <summary>
|
|
## Allow read, write, and create for generic character device files.
|
|
## </summary>
|
|
## <param name="domain">
|
|
## Domain allowed access.
|
|
## </param>
|
|
#
|
|
interface(`dev_create_generic_chr_file',`
|
|
gen_require(`
|
|
type device_t;
|
|
class dir ra_dir_perms;
|
|
class chr_file create;
|
|
class capability mknod;
|
|
')
|
|
|
|
allow $1 device_t:dir ra_dir_perms;
|
|
allow $1 device_t:chr_file create;
|
|
|
|
allow $1 self:capability mknod;
|
|
')
|
|
|
|
########################################
|
|
## <summary>
|
|
## Allow getattr for generic character device files.
|
|
## </summary>
|
|
## <param name="domain">
|
|
## Domain allowed access.
|
|
## </param>
|
|
#
|
|
interface(`dev_getattr_generic_chr_file',`
|
|
gen_require(`
|
|
type device_t;
|
|
class dir r_dir_perms;
|
|
class chr_file getattr;
|
|
')
|
|
|
|
allow $1 device_t:dir r_dir_perms;
|
|
allow $1 device_t:chr_file getattr;
|
|
')
|
|
|
|
########################################
|
|
## <summary>
|
|
## Dontaudit getattr for generic character device files.
|
|
## </summary>
|
|
## <param name="domain">
|
|
## Domain to dontaudit access.
|
|
## </param>
|
|
#
|
|
interface(`dev_dontaudit_getattr_generic_chr_file',`
|
|
gen_require(`
|
|
type device_t;
|
|
class chr_file getattr;
|
|
')
|
|
|
|
dontaudit $1 device_t:chr_file getattr;
|
|
')
|
|
|
|
########################################
|
|
## <summary>
|
|
## Dontaudit setattr for generic character device files.
|
|
## </summary>
|
|
## <param name="domain">
|
|
## Domain to dontaudit access.
|
|
## </param>
|
|
#
|
|
interface(`dev_dontaudit_setattr_generic_chr_file',`
|
|
gen_require(`
|
|
type device_t;
|
|
class chr_file setattr;
|
|
')
|
|
|
|
dontaudit $1 device_t:chr_file setattr;
|
|
')
|
|
|
|
########################################
|
|
## <summary>
|
|
## Do not audit attempts to set the attributes
|
|
## of symbolic links in device directories (/dev).
|
|
## </summary>
|
|
## <param name="domain">
|
|
## Domain to not audit.
|
|
## </param>
|
|
#
|
|
interface(`dev_dontaudit_setattr_generic_symlink',`
|
|
gen_require(`
|
|
type device_t;
|
|
class lnk_file setattr;
|
|
')
|
|
|
|
dontaudit $1 device_t:lnk_file setattr;
|
|
')
|
|
|
|
########################################
|
|
## <summary>
|
|
## Delete symbolic links in device directories.
|
|
## </summary>
|
|
## <param name="domain">
|
|
## Domain allowed access.
|
|
## </param>
|
|
#
|
|
interface(`dev_del_generic_symlinks',`
|
|
gen_require(`
|
|
type device_t;
|
|
class dir { getattr read write remove_name };
|
|
class lnk_file unlink;
|
|
')
|
|
|
|
allow $1 device_t:dir { getattr read write remove_name };
|
|
allow $1 device_t:lnk_file unlink;
|
|
')
|
|
|
|
########################################
|
|
## <summary>
|
|
## Create, delete, read, and write symbolic links in device directories.
|
|
## </summary>
|
|
## <param name="domain">
|
|
## Domain allowed access.
|
|
## </param>
|
|
#
|
|
interface(`dev_manage_generic_symlinks',`
|
|
gen_require(`
|
|
type device_t;
|
|
class dir { create read getattr lock setattr ioctl link unlink rename search add_name remove_name reparent write rmdir relabelfrom relabelto };
|
|
class lnk_file { create read getattr setattr link unlink rename };
|
|
')
|
|
|
|
allow $1 device_t:dir { create read getattr lock setattr ioctl link unlink rename search add_name remove_name reparent write rmdir relabelfrom relabelto };
|
|
allow $1 device_t:lnk_file { create read getattr setattr link unlink rename };
|
|
')
|
|
|
|
########################################
|
|
## <summary>
|
|
## Relabel symbolic links in device directories.
|
|
## </summary>
|
|
## <param name="domain">
|
|
## Domain allowed access.
|
|
## </param>
|
|
#
|
|
interface(`dev_relabel_generic_symlinks',`
|
|
gen_require(`
|
|
type device_t;
|
|
class dir r_dir_perms;
|
|
class lnk_file { relabelfrom relabelto };
|
|
')
|
|
|
|
allow $1 device_t:dir r_dir_perms;
|
|
allow $1 device_t:lnk_file { relabelfrom relabelto };
|
|
')
|
|
|
|
########################################
|
|
## <summary>
|
|
## Create, delete, read, and write device nodes in device directories.
|
|
## </summary>
|
|
## <param name="domain">
|
|
## Domain allowed access.
|
|
## </param>
|
|
#
|
|
interface(`dev_manage_dev_nodes',`
|
|
gen_require(`
|
|
attribute device_node, memory_raw_read, memory_raw_write;
|
|
type device_t;
|
|
class dir { create read getattr lock setattr ioctl link unlink rename search add_name remove_name reparent write rmdir relabelfrom relabelto };
|
|
class sock_file { create ioctl read getattr lock write setattr append link unlink rename };
|
|
class lnk_file { create read getattr setattr link unlink rename };
|
|
class chr_file { create ioctl read getattr lock write setattr append link unlink rename relabelfrom relabelto };
|
|
class blk_file { create ioctl read getattr lock write setattr append link unlink rename relabelfrom relabelto };
|
|
')
|
|
|
|
allow $1 device_t:dir { create read getattr lock setattr ioctl link unlink rename search add_name remove_name reparent write rmdir relabelfrom relabelto };
|
|
allow $1 device_t:sock_file { create ioctl read getattr lock write setattr append link unlink rename };
|
|
allow $1 device_t:lnk_file { create read getattr setattr link unlink rename };
|
|
allow $1 device_t:{ chr_file blk_file } { create ioctl read getattr lock write setattr append link unlink rename relabelfrom relabelto };
|
|
allow $1 device_node:{ chr_file blk_file } { create ioctl read getattr lock write setattr append link unlink rename relabelfrom relabelto };
|
|
|
|
# these next rules are to satisfy assertions broken by the above lines.
|
|
# the permissions hopefully can be cut back a lot
|
|
storage_raw_read_fixed_disk($1)
|
|
storage_raw_write_fixed_disk($1)
|
|
storage_read_scsi_generic($1)
|
|
storage_write_scsi_generic($1)
|
|
|
|
typeattribute $1 memory_raw_read;
|
|
typeattribute $1 memory_raw_write;
|
|
')
|
|
|
|
########################################
|
|
## <summary>
|
|
## Dontaudit getattr for generic device files.
|
|
## </summary>
|
|
## <param name="domain">
|
|
## Domain to dontaudit access.
|
|
## </param>
|
|
#
|
|
interface(`dev_dontaudit_rw_generic_dev_nodes',`
|
|
gen_require(`
|
|
type device_t;
|
|
class chr_file { getattr read write ioctl };
|
|
class blk_file { getattr read write ioctl };
|
|
')
|
|
|
|
dontaudit $1 device_t:{ chr_file blk_file } { getattr read write ioctl };
|
|
')
|
|
|
|
########################################
|
|
## <summary>
|
|
## Create, delete, read, and write block device files.
|
|
## </summary>
|
|
## <param name="domain">
|
|
## Domain allowed access.
|
|
## </param>
|
|
#
|
|
interface(`dev_manage_generic_blk_file',`
|
|
gen_require(`
|
|
type device_t;
|
|
class dir rw_dir_perms;
|
|
class blk_file create_file_perms;
|
|
')
|
|
|
|
allow $1 device_t:dir rw_dir_perms;
|
|
allow $1 device_t:blk_file create_file_perms;
|
|
')
|
|
|
|
########################################
|
|
## <summary>
|
|
## Create, delete, read, and write character device files.
|
|
## </summary>
|
|
## <param name="domain">
|
|
## Domain allowed access.
|
|
## </param>
|
|
#
|
|
interface(`dev_manage_generic_chr_file',`
|
|
gen_require(`
|
|
type device_t;
|
|
class dir rw_dir_perms;
|
|
class chr_file create_file_perms;
|
|
')
|
|
|
|
allow $1 device_t:dir rw_dir_perms;
|
|
allow $1 device_t:chr_file create_file_perms;
|
|
')
|
|
|
|
########################################
|
|
## <summary>
|
|
## Create, read, and write device nodes. The node
|
|
## will be transitioned to the type provided.
|
|
## </summary>
|
|
## <param name="domain">
|
|
## Domain allowed access.
|
|
## </param>
|
|
## <param name="file">
|
|
## Type to which the created node will be transitioned.
|
|
## </param>
|
|
## <param name="objectclass(es)">
|
|
## Object class(es) (single or set including {}) for which this
|
|
## the transition will occur.
|
|
## </param>
|
|
#
|
|
interface(`dev_create_dev_node',`
|
|
gen_require(`
|
|
type device_t;
|
|
class dir rw_dir_perms;
|
|
')
|
|
|
|
allow $1 device_t:dir rw_dir_perms;
|
|
type_transition $1 device_t:$3 $2;
|
|
|
|
optional_policy(`distro_redhat',`
|
|
fs_associate_tmpfs($2)
|
|
')
|
|
')
|
|
|
|
########################################
|
|
## <summary>
|
|
## Getattr on all block file device nodes.
|
|
## </summary>
|
|
## <param name="domain">
|
|
## Domain allowed access.
|
|
## </param>
|
|
#
|
|
interface(`dev_getattr_all_blk_files',`
|
|
gen_require(`
|
|
attribute device_node;
|
|
class blk_file getattr;
|
|
class dir r_dir_perms;
|
|
')
|
|
|
|
allow $1 device_t:dir r_dir_perms;
|
|
allow $1 device_node:blk_file getattr;
|
|
')
|
|
|
|
########################################
|
|
## <summary>
|
|
## Dontaudit getattr on all block file device nodes.
|
|
## </summary>
|
|
## <param name="domain">
|
|
## Domain to dontaudit access.
|
|
## </param>
|
|
#
|
|
interface(`dev_dontaudit_getattr_all_blk_files',`
|
|
gen_require(`
|
|
attribute device_node;
|
|
class blk_file getattr;
|
|
')
|
|
|
|
allow $1 device_node:blk_file getattr;
|
|
')
|
|
|
|
########################################
|
|
## <summary>
|
|
## Getattr on all character file device nodes.
|
|
## </summary>
|
|
## <param name="domain">
|
|
## Domain allowed access.
|
|
## </param>
|
|
#
|
|
interface(`dev_getattr_all_chr_files',`
|
|
gen_require(`
|
|
attribute device_node;
|
|
class chr_file getattr;
|
|
class dir r_dir_perms;
|
|
')
|
|
|
|
allow $1 device_t:dir r_dir_perms;
|
|
allow $1 device_node:chr_file getattr;
|
|
')
|
|
|
|
########################################
|
|
## <summary>
|
|
## Dontaudit getattr on all character file device nodes.
|
|
## </summary>
|
|
## <param name="domain">
|
|
## Domain to dontaudit access.
|
|
## </param>
|
|
#
|
|
interface(`dev_dontaudit_getattr_all_chr_files',`
|
|
gen_require(`
|
|
attribute device_node;
|
|
class chr_file getattr;
|
|
')
|
|
|
|
dontaudit $1 device_node:chr_file getattr;
|
|
')
|
|
|
|
########################################
|
|
## <summary>
|
|
## Setattr on all block file device nodes.
|
|
## </summary>
|
|
## <param name="domain">
|
|
## Domain allowed access.
|
|
## </param>
|
|
#
|
|
interface(`dev_setattr_all_blk_files',`
|
|
gen_require(`
|
|
attribute device_node;
|
|
class dir r_dir_perms;
|
|
class blk_file setattr;
|
|
')
|
|
|
|
allow $1 device_t:dir r_dir_perms;
|
|
allow $1 device_node:blk_file setattr;
|
|
')
|
|
|
|
########################################
|
|
## <summary>
|
|
## Setattr on all character file device nodes.
|
|
## </summary>
|
|
## <param name="domain">
|
|
## Domain allowed access.
|
|
## </param>
|
|
#
|
|
interface(`dev_setattr_all_chr_files',`
|
|
gen_require(`
|
|
attribute device_node;
|
|
class dir r_dir_perms;
|
|
class chr_file setattr;
|
|
')
|
|
|
|
allow $1 device_t:dir r_dir_perms;
|
|
allow $1 device_node:chr_file setattr;
|
|
')
|
|
|
|
########################################
|
|
## <summary>
|
|
## Read, write, create, and delete all block device files.
|
|
## </summary>
|
|
## <param name="domain">
|
|
## Domain allowed access.
|
|
## </param>
|
|
#
|
|
interface(`dev_manage_all_blk_files',`
|
|
gen_require(`
|
|
attribute device_node;
|
|
class dir rw_dir_perms;
|
|
class blk_file create_file_perms;
|
|
')
|
|
|
|
allow $1 device_t:dir rw_dir_perms;
|
|
allow $1 device_node:blk_file create_file_perms;
|
|
|
|
# these next rules are to satisfy assertions broken by the above lines.
|
|
storage_raw_read_fixed_disk($1)
|
|
storage_raw_write_fixed_disk($1)
|
|
storage_read_scsi_generic($1)
|
|
storage_write_scsi_generic($1)
|
|
')
|
|
|
|
########################################
|
|
## <summary>
|
|
## Read, write, create, and delete all character device files.
|
|
## </summary>
|
|
## <param name="domain">
|
|
## Domain allowed access.
|
|
## </param>
|
|
#
|
|
interface(`dev_manage_all_chr_files',`
|
|
gen_require(`
|
|
attribute device_node, memory_raw_read, memory_raw_write;
|
|
class dir rw_dir_perms;
|
|
class chr_file create_file_perms;
|
|
')
|
|
|
|
allow $1 device_t:dir rw_dir_perms;
|
|
allow $1 device_node:chr_file create_file_perms;
|
|
|
|
typeattribute $1 memory_raw_read, memory_raw_write;
|
|
')
|
|
|
|
########################################
|
|
## <summary>
|
|
## Get the attributes of the apm bios device node.
|
|
## </summary>
|
|
## <param name="domain">
|
|
## Domain allowed access.
|
|
## </param>
|
|
#
|
|
interface(`dev_getattr_apm_bios',`
|
|
gen_require(`
|
|
type device_t, apm_bios_t;
|
|
class dir r_dir_perms;
|
|
class chr_file getattr;
|
|
')
|
|
|
|
allow $1 device_t:dir r_dir_perms;
|
|
allow $1 apm_bios_t:chr_file getattr;
|
|
')
|
|
|
|
########################################
|
|
## <summary>
|
|
## Do not audit attempts to get the attributes of
|
|
## the apm bios device node.
|
|
## </summary>
|
|
## <param name="domain">
|
|
## Domain to not audit.
|
|
## </param>
|
|
#
|
|
interface(`dev_dontaudit_getattr_apm_bios',`
|
|
gen_require(`
|
|
type apm_bios_t;
|
|
class chr_file getattr;
|
|
')
|
|
|
|
dontaudit $1 apm_bios_t:chr_file getattr;
|
|
')
|
|
|
|
########################################
|
|
## <summary>
|
|
## Set the attributes of the apm bios device node.
|
|
## </summary>
|
|
## <param name="domain">
|
|
## Domain allowed access.
|
|
## </param>
|
|
#
|
|
interface(`dev_setattr_apm_bios',`
|
|
gen_require(`
|
|
type device_t, apm_bios_t;
|
|
class dir r_dir_perms;
|
|
class chr_file setattr;
|
|
')
|
|
|
|
allow $1 device_t:dir r_dir_perms;
|
|
allow $1 apm_bios_t:chr_file setattr;
|
|
')
|
|
|
|
########################################
|
|
## <summary>
|
|
## Do not audit attempts to set the attributes of
|
|
## the apm bios device node.
|
|
## </summary>
|
|
## <param name="domain">
|
|
## Domain to not audit.
|
|
## </param>
|
|
#
|
|
interface(`dev_dontaudit_setattr_apm_bios',`
|
|
gen_require(`
|
|
type apm_bios_t;
|
|
class chr_file setattr;
|
|
')
|
|
|
|
dontaudit $1 apm_bios_t:chr_file setattr;
|
|
')
|
|
|
|
########################################
|
|
## <summary>
|
|
## Read and write the apm bios.
|
|
## </summary>
|
|
## <param name="domain">
|
|
## Domain allowed access.
|
|
## </param>
|
|
#
|
|
interface(`dev_rw_apm_bios',`
|
|
gen_require(`
|
|
type device_t, apm_bios_t;
|
|
class dir r_dir_perms;
|
|
class chr_file rw_file_perms;
|
|
')
|
|
|
|
allow $1 device_t:dir r_dir_perms;
|
|
allow $1 apm_bios_t:chr_file rw_file_perms;
|
|
')
|
|
|
|
########################################
|
|
## <summary>
|
|
## Read raw memory devices (e.g. /dev/mem).
|
|
## </summary>
|
|
## <param name="domain">
|
|
## Domain allowed access.
|
|
## </param>
|
|
#
|
|
interface(`dev_read_raw_memory',`
|
|
gen_require(`
|
|
type device_t, memory_device_t;
|
|
attribute memory_raw_read;
|
|
class dir r_dir_perms;
|
|
class chr_file r_file_perms;
|
|
class capability sys_rawio;
|
|
')
|
|
|
|
allow $1 device_t:dir r_dir_perms;
|
|
allow $1 memory_device_t:chr_file r_file_perms;
|
|
|
|
allow $1 self:capability sys_rawio;
|
|
typeattribute $1 memory_raw_read;
|
|
')
|
|
|
|
########################################
|
|
## <summary>
|
|
## Write raw memory devices (e.g. /dev/mem).
|
|
## </summary>
|
|
## <param name="domain">
|
|
## Domain allowed access.
|
|
## </param>
|
|
#
|
|
interface(`dev_write_raw_memory',`
|
|
gen_require(`
|
|
type device_t, memory_device_t;
|
|
attribute memory_raw_write;
|
|
class dir r_dir_perms;
|
|
class chr_file write;
|
|
class capability sys_rawio;
|
|
')
|
|
|
|
allow $1 device_t:dir r_dir_perms;
|
|
allow $1 memory_device_t:chr_file write;
|
|
|
|
allow $1 self:capability sys_rawio;
|
|
typeattribute $1 memory_raw_write;
|
|
')
|
|
|
|
########################################
|
|
## <summary>
|
|
## Read and execute raw memory devices (e.g. /dev/mem).
|
|
## </summary>
|
|
## <param name="domain">
|
|
## Domain allowed access.
|
|
## </param>
|
|
#
|
|
interface(`dev_rx_raw_memory',`
|
|
gen_require(`
|
|
type device_t, memory_device_t;
|
|
class chr_file execute;
|
|
')
|
|
|
|
dev_read_raw_memory($1)
|
|
allow $1 memory_device_t:chr_file execute;
|
|
')
|
|
|
|
########################################
|
|
## <summary>
|
|
## Write and execute raw memory devices (e.g. /dev/mem).
|
|
## </summary>
|
|
## <param name="domain">
|
|
## Domain allowed access.
|
|
## </param>
|
|
#
|
|
interface(`dev_wx_raw_memory',`
|
|
gen_require(`
|
|
type device_t, memory_device_t;
|
|
class chr_file execute;
|
|
')
|
|
|
|
dev_write_raw_memory($1)
|
|
allow $1 memory_device_t:chr_file execute;
|
|
')
|
|
|
|
########################################
|
|
## <summary>
|
|
## Read from random devices (e.g., /dev/random)
|
|
## </summary>
|
|
## <param name="domain">
|
|
## Domain allowed access.
|
|
## </param>
|
|
#
|
|
interface(`dev_read_rand',`
|
|
gen_require(`
|
|
type device_t, random_device_t;
|
|
class dir r_dir_perms;
|
|
class chr_file r_file_perms;
|
|
')
|
|
|
|
allow $1 device_t:dir r_dir_perms;
|
|
allow $1 random_device_t:chr_file r_file_perms;
|
|
')
|
|
|
|
########################################
|
|
## <summary>
|
|
## Read from pseudo random devices (e.g., /dev/urandom)
|
|
## </summary>
|
|
## <param name="domain">
|
|
## Domain allowed access.
|
|
## </param>
|
|
#
|
|
interface(`dev_read_urand',`
|
|
gen_require(`
|
|
type device_t, urandom_device_t;
|
|
class dir r_dir_perms;
|
|
class chr_file r_file_perms;
|
|
')
|
|
|
|
allow $1 device_t:dir r_dir_perms;
|
|
allow $1 urandom_device_t:chr_file r_file_perms;
|
|
')
|
|
|
|
########################################
|
|
## <summary>
|
|
## Write to the random device (e.g., /dev/random). This adds
|
|
## entropy used to generate the random data read from the
|
|
## random device.
|
|
## </summary>
|
|
## <param name="domain">
|
|
## Domain allowed access.
|
|
## </param>
|
|
#
|
|
interface(`dev_write_rand',`
|
|
gen_require(`
|
|
type device_t, random_device_t;
|
|
class dir r_dir_perms;
|
|
class chr_file { getattr write ioctl };
|
|
')
|
|
|
|
allow $1 device_t:dir r_dir_perms;
|
|
allow $1 random_device_t:chr_file { getattr write ioctl };
|
|
')
|
|
|
|
########################################
|
|
## <summary>
|
|
## Write to the pseudo random device (e.g., /dev/urandom). This
|
|
## sets the random number generator seed.
|
|
## </summary>
|
|
## <param name="domain">
|
|
## Domain allowed access.
|
|
## </param>
|
|
#
|
|
interface(`dev_write_urand',`
|
|
gen_require(`
|
|
type device_t, urandom_device_t;
|
|
class dir r_dir_perms;
|
|
class chr_file { getattr write ioctl };
|
|
')
|
|
|
|
allow $1 device_t:dir r_dir_perms;
|
|
allow $1 urandom_device_t:chr_file { getattr write ioctl };
|
|
')
|
|
|
|
########################################
|
|
## <summary>
|
|
## Read and write to the null device (/dev/null).
|
|
## </summary>
|
|
## <param name="domain">
|
|
## Domain allowed access.
|
|
## </param>
|
|
#
|
|
interface(`dev_rw_null_dev',`
|
|
gen_require(`
|
|
type device_t, null_device_t;
|
|
class device_t:dir r_dir_perms;
|
|
class chr_file rw_file_perms;
|
|
')
|
|
|
|
allow $1 device_t:dir r_dir_perms;
|
|
allow $1 null_device_t:chr_file rw_file_perms;
|
|
')
|
|
|
|
########################################
|
|
## <summary>
|
|
## Read and write to the zero device (/dev/zero).
|
|
## </summary>
|
|
## <param name="domain">
|
|
## Domain allowed access.
|
|
## </param>
|
|
#
|
|
interface(`dev_rw_zero_dev',`
|
|
gen_require(`
|
|
type device_t, zero_device_t;
|
|
class device_t:dir r_dir_perms;
|
|
class chr_file r_file_perms;
|
|
')
|
|
|
|
allow $1 device_t:dir r_dir_perms;
|
|
allow $1 zero_device_t:chr_file rw_file_perms;
|
|
')
|
|
|
|
########################################
|
|
## <summary>
|
|
## Read, write, and execute the zero device (/dev/zero).
|
|
## </summary>
|
|
## <param name="domain">
|
|
## Domain allowed access.
|
|
## </param>
|
|
#
|
|
interface(`dev_rwx_zero_dev',`
|
|
gen_require(`
|
|
type zero_device_t;
|
|
class chr_file execute;
|
|
')
|
|
|
|
dev_rw_zero_dev($1)
|
|
allow $1 zero_device_t:chr_file execute;
|
|
')
|
|
|
|
########################################
|
|
## <summary>
|
|
## Read the realtime clock (/dev/rtc).
|
|
## </summary>
|
|
## <param name="domain">
|
|
## Domain allowed access.
|
|
## </param>
|
|
#
|
|
interface(`dev_read_realtime_clock',`
|
|
gen_require(`
|
|
type device_t, clock_device_t;
|
|
class dir r_dir_perms;
|
|
class chr_file r_file_perms;
|
|
')
|
|
|
|
allow $1 device_t:dir r_dir_perms;
|
|
allow $1 clock_device_t:chr_file r_file_perms;
|
|
')
|
|
|
|
########################################
|
|
## <summary>
|
|
## Read the realtime clock (/dev/rtc).
|
|
## </summary>
|
|
## <param name="domain">
|
|
## Domain allowed access.
|
|
## </param>
|
|
#
|
|
interface(`dev_write_realtime_clock',`
|
|
gen_require(`
|
|
type device_t, clock_device_t;
|
|
class dir r_dir_perms;
|
|
class chr_file { setattr lock write append ioctl };
|
|
')
|
|
|
|
allow $1 device_t:dir r_dir_perms;
|
|
allow $1 clock_device_t:chr_file { setattr lock write append ioctl };
|
|
')
|
|
|
|
########################################
|
|
## <summary>
|
|
## Read the realtime clock (/dev/rtc).
|
|
## </summary>
|
|
## <param name="domain">
|
|
## Domain allowed access.
|
|
## </param>
|
|
#
|
|
interface(`dev_rw_realtime_clock',`
|
|
dev_read_realtime_clock($1)
|
|
dev_write_realtime_clock($1)
|
|
')
|
|
|
|
########################################
|
|
## <summary>
|
|
## Get the attributes of the sound devices.
|
|
## </summary>
|
|
## <param name="domain">
|
|
## Domain allowed access.
|
|
## </param>
|
|
#
|
|
interface(`dev_getattr_snd_dev',`
|
|
gen_require(`
|
|
type device_t, sound_device_t;
|
|
class dir r_dir_perms;
|
|
class chr_file getattr;
|
|
')
|
|
|
|
allow $1 device_t:dir r_dir_perms;
|
|
allow $1 sound_device_t:chr_file getattr;
|
|
')
|
|
|
|
########################################
|
|
## <summary>
|
|
## Set the attributes of the sound devices.
|
|
## </summary>
|
|
## <param name="domain">
|
|
## Domain allowed access.
|
|
## </param>
|
|
#
|
|
interface(`dev_setattr_snd_dev',`
|
|
gen_require(`
|
|
type device_t, sound_device_t;
|
|
class dir r_dir_perms;
|
|
class chr_file setattr;
|
|
')
|
|
|
|
allow $1 device_t:dir r_dir_perms;
|
|
allow $1 sound_device_t:chr_file setattr;
|
|
')
|
|
|
|
########################################
|
|
## <summary>
|
|
## Read the sound devices.
|
|
## </summary>
|
|
## <param name="domain">
|
|
## Domain allowed access.
|
|
## </param>
|
|
#
|
|
interface(`dev_read_snd_dev',`
|
|
gen_require(`
|
|
type device_t, sound_device_t;
|
|
class dir r_dir_perms;
|
|
class chr_file r_file_perms;
|
|
')
|
|
|
|
allow $1 device_t:dir r_dir_perms;
|
|
allow $1 sound_device_t:chr_file r_file_perms;
|
|
')
|
|
|
|
########################################
|
|
## <summary>
|
|
## Write the sound devices.
|
|
## </summary>
|
|
## <param name="domain">
|
|
## Domain allowed access.
|
|
## </param>
|
|
#
|
|
interface(`dev_write_snd_dev',`
|
|
gen_require(`
|
|
type device_t, sound_device_t;
|
|
class dir r_dir_perms;
|
|
class chr_file { getattr write ioctl };
|
|
')
|
|
|
|
allow $1 device_t:dir r_dir_perms;
|
|
allow $1 sound_device_t:chr_file { getattr write ioctl };
|
|
')
|
|
|
|
########################################
|
|
## <summary>
|
|
## Read the sound mixer devices.
|
|
## </summary>
|
|
## <param name="domain">
|
|
## Domain allowed access.
|
|
## </param>
|
|
#
|
|
interface(`dev_read_snd_mixer_dev',`
|
|
gen_require(`
|
|
type device_t, sound_device_t;
|
|
class dir r_dir_perms;
|
|
class chr_file { getattr read ioctl };
|
|
')
|
|
|
|
allow $1 device_t:dir r_dir_perms;
|
|
allow $1 sound_device_t:chr_file { getattr read ioctl };
|
|
')
|
|
|
|
########################################
|
|
## <summary>
|
|
## Write the sound mixer devices.
|
|
## </summary>
|
|
## <param name="domain">
|
|
## Domain allowed access.
|
|
## </param>
|
|
#
|
|
interface(`dev_write_snd_mixer_dev',`
|
|
gen_require(`
|
|
type device_t, sound_device_t;
|
|
class dir r_dir_perms;
|
|
class chr_file { getattr write ioctl };
|
|
')
|
|
|
|
allow $1 device_t:dir r_dir_perms;
|
|
allow $1 sound_device_t:chr_file { getattr write ioctl };
|
|
')
|
|
|
|
########################################
|
|
## <summary>
|
|
## Read and write the agp devices.
|
|
## </summary>
|
|
## <param name="domain">
|
|
## Domain allowed access.
|
|
## </param>
|
|
#
|
|
interface(`dev_rw_agp_dev',`
|
|
gen_require(`
|
|
type device_t, agp_device_t;
|
|
class dir r_dir_perms;
|
|
class chr_file rw_file_perms;
|
|
')
|
|
|
|
allow $1 device_t:dir r_dir_perms;
|
|
allow $1 agp_device_t:chr_file rw_file_perms;
|
|
')
|
|
|
|
########################################
|
|
## <summary>
|
|
## Getattr the agp devices.
|
|
## </summary>
|
|
## <param name="domain">
|
|
## Domain allowed access.
|
|
## </param>
|
|
#
|
|
interface(`dev_getattr_agp_dev',`
|
|
gen_require(`
|
|
type device_t, dri_device_t;
|
|
class dir r_dir_perms;
|
|
class chr_file getattr;
|
|
')
|
|
|
|
allow $1 device_t:dir r_dir_perms;
|
|
allow $1 dri_device_t:chr_file getattr;
|
|
')
|
|
|
|
########################################
|
|
## <summary>
|
|
## Read and write the dri devices.
|
|
## </summary>
|
|
## <param name="domain">
|
|
## Domain allowed access.
|
|
## </param>
|
|
#
|
|
interface(`dev_rw_dri_dev',`
|
|
gen_require(`
|
|
type device_t, dri_device_t;
|
|
class dir r_dir_perms;
|
|
class chr_file rw_file_perms;
|
|
')
|
|
|
|
allow $1 device_t:dir r_dir_perms;
|
|
allow $1 dri_device_t:chr_file rw_file_perms;
|
|
')
|
|
|
|
########################################
|
|
## <summary>
|
|
## Dontaudit read and write on the dri devices.
|
|
## </summary>
|
|
## <param name="domain">
|
|
## Domain to dontaudit access.
|
|
## </param>
|
|
#
|
|
interface(`dev_dontaudit_rw_dri_dev',`
|
|
gen_require(`
|
|
type dri_device_t;
|
|
class chr_file { getattr read write ioctl };
|
|
')
|
|
|
|
dontaudit $1 dri_device_t:chr_file { getattr read write ioctl };
|
|
')
|
|
|
|
########################################
|
|
## <summary>
|
|
## Read the mtrr device.
|
|
## </summary>
|
|
## <param name="domain">
|
|
## Domain allowed access.
|
|
## </param>
|
|
#
|
|
interface(`dev_read_mtrr',`
|
|
gen_require(`
|
|
type device_t, mtrr_device_t;
|
|
class dir r_dir_perms;
|
|
class chr_file r_file_perms;
|
|
')
|
|
|
|
allow $1 device_t:dir r_dir_perms;
|
|
allow $1 mtrr_device_t:chr_file r_file_perms;
|
|
')
|
|
|
|
########################################
|
|
## <summary>
|
|
## Write the mtrr device.
|
|
## </summary>
|
|
## <param name="domain">
|
|
## Domain allowed access.
|
|
## </param>
|
|
#
|
|
interface(`dev_write_mtrr',`
|
|
gen_require(`
|
|
type device_t, mtrr_device_t;
|
|
class dir r_dir_perms;
|
|
class chr_file { getattr write ioctl };
|
|
')
|
|
|
|
allow $1 device_t:dir r_dir_perms;
|
|
allow $1 mtrr_device_t:chr_file { getattr write ioctl };
|
|
')
|
|
|
|
########################################
|
|
## <summary>
|
|
## Get the attributes of the framebuffer device node.
|
|
## </summary>
|
|
## <param name="domain">
|
|
## Domain allowed access.
|
|
## </param>
|
|
#
|
|
interface(`dev_getattr_framebuffer',`
|
|
gen_require(`
|
|
type device_t, framebuf_device_t;
|
|
class dir r_dir_perms;
|
|
class chr_file getattr;
|
|
')
|
|
|
|
allow $1 device_t:dir r_dir_perms;
|
|
allow $1 framebuf_device_t:chr_file getattr;
|
|
')
|
|
|
|
########################################
|
|
## <summary>
|
|
## Set the attributes of the framebuffer device node.
|
|
## </summary>
|
|
## <param name="domain">
|
|
## Domain allowed access.
|
|
## </param>
|
|
#
|
|
interface(`dev_setattr_framebuffer',`
|
|
gen_require(`
|
|
type device_t, framebuf_device_t;
|
|
class dir r_dir_perms;
|
|
class chr_file setattr;
|
|
')
|
|
|
|
allow $1 device_t:dir r_dir_perms;
|
|
allow $1 framebuf_device_t:chr_file setattr;
|
|
')
|
|
|
|
########################################
|
|
## <summary>
|
|
## Dot not audit attempts to set the attributes
|
|
## of the framebuffer device node.
|
|
## </summary>
|
|
## <param name="domain">
|
|
## Domain to not audit.
|
|
## </param>
|
|
#
|
|
interface(`dev_dontaudit_setattr_framebuffer',`
|
|
gen_require(`
|
|
type framebuf_device_t;
|
|
class chr_file setattr;
|
|
')
|
|
|
|
dontaudit $1 framebuf_device_t:chr_file setattr;
|
|
')
|
|
|
|
########################################
|
|
## <summary>
|
|
## Read the framebuffer.
|
|
## </summary>
|
|
## <param name="domain">
|
|
## Domain allowed access.
|
|
## </param>
|
|
#
|
|
interface(`dev_read_framebuffer',`
|
|
gen_require(`
|
|
type framebuf_device_t;
|
|
class dir r_dir_perms;
|
|
class chr_file r_file_perms;
|
|
')
|
|
|
|
allow $1 device_t:dir r_dir_perms;
|
|
allow $1 framebuf_device_t:chr_file r_file_perms;
|
|
')
|
|
|
|
########################################
|
|
## <summary>
|
|
## Do not audit attempts to read the framebuffer.
|
|
## </summary>
|
|
## <param name="domain">
|
|
## Domain allowed access.
|
|
## </param>
|
|
#
|
|
interface(`dev_dontaudit_read_framebuffer',`
|
|
gen_require(`
|
|
type framebuf_device_t;
|
|
class chr_file r_file_perms;
|
|
')
|
|
|
|
dontaudit $1 framebuf_device_t:chr_file { getattr read };
|
|
')
|
|
|
|
########################################
|
|
## <summary>
|
|
## Write the framebuffer.
|
|
## </summary>
|
|
## <param name="domain">
|
|
## Domain allowed access.
|
|
## </param>
|
|
#
|
|
interface(`dev_write_framebuffer',`
|
|
gen_require(`
|
|
type device_t, framebuf_device_t;
|
|
class dir r_dir_perms;
|
|
class chr_file { getattr write ioctl };
|
|
')
|
|
|
|
allow $1 device_t:dir r_dir_perms;
|
|
allow $1 framebuf_device_t:chr_file { getattr write ioctl };
|
|
')
|
|
|
|
########################################
|
|
## <summary>
|
|
## Read the lvm comtrol device.
|
|
## </summary>
|
|
## <param name="domain">
|
|
## Domain allowed access.
|
|
## </param>
|
|
#
|
|
interface(`dev_read_lvm_control',`
|
|
gen_require(`
|
|
type device_t, lvm_control_t;
|
|
class dir r_dir_perms;
|
|
class chr_file r_file_perms;
|
|
')
|
|
|
|
allow $1 device_t:dir r_dir_perms;
|
|
allow $1 lvm_control_t:chr_file r_file_perms;
|
|
')
|
|
|
|
########################################
|
|
## <summary>
|
|
## Read and write the lvm control device.
|
|
## </summary>
|
|
## <param name="domain">
|
|
## Domain allowed access.
|
|
## </param>
|
|
#
|
|
interface(`dev_rw_lvm_control',`
|
|
gen_require(`
|
|
type device_t, lvm_control_t;
|
|
class dir r_dir_perms;
|
|
class chr_file rw_file_perms;
|
|
')
|
|
|
|
allow $1 device_t:dir r_dir_perms;
|
|
allow $1 lvm_control_t:chr_file rw_file_perms;
|
|
')
|
|
|
|
########################################
|
|
## <summary>
|
|
## Delete the lvm control device.
|
|
## </summary>
|
|
## <param name="domain">
|
|
## Domain allowed access.
|
|
## </param>
|
|
#
|
|
interface(`dev_delete_lvm_control',`
|
|
gen_require(`
|
|
type device_t, lvm_control_t;
|
|
class dir { getattr search read write remove_name };
|
|
class chr_file unlink;
|
|
')
|
|
|
|
allow $1 device_t:dir { getattr search read write remove_name };
|
|
allow $1 lvm_control_t:chr_file unlink;
|
|
')
|
|
|
|
########################################
|
|
## <summary>
|
|
## Get the attributes of miscellaneous devices.
|
|
## </summary>
|
|
## <param name="domain">
|
|
## Domain allowed access.
|
|
## </param>
|
|
#
|
|
interface(`dev_getattr_misc',`
|
|
gen_require(`
|
|
type device_t, misc_device_t;
|
|
class dir r_dir_perms;
|
|
class chr_file getattr;
|
|
')
|
|
|
|
allow $1 device_t:dir r_dir_perms;
|
|
allow $1 misc_device_t:chr_file getattr;
|
|
')
|
|
|
|
########################################
|
|
## <summary>
|
|
## Do not audit attempts to get the attributes
|
|
## of miscellaneous devices.
|
|
## </summary>
|
|
## <param name="domain">
|
|
## Domain allowed access.
|
|
## </param>
|
|
#
|
|
interface(`dev_dontaudit_getattr_misc',`
|
|
gen_require(`
|
|
type misc_device_t;
|
|
class chr_file getattr;
|
|
')
|
|
|
|
dontaudit $1 misc_device_t:chr_file getattr;
|
|
')
|
|
|
|
########################################
|
|
## <summary>
|
|
## Set the attributes of miscellaneous devices.
|
|
## </summary>
|
|
## <param name="domain">
|
|
## Domain allowed access.
|
|
## </param>
|
|
#
|
|
interface(`dev_setattr_misc',`
|
|
gen_require(`
|
|
type device_t, misc_device_t;
|
|
class dir r_dir_perms;
|
|
class chr_file setattr;
|
|
')
|
|
|
|
allow $1 device_t:dir r_dir_perms;
|
|
allow $1 misc_device_t:chr_file setattr;
|
|
')
|
|
|
|
########################################
|
|
## <summary>
|
|
## Do not audit attempts to set the attributes
|
|
## of miscellaneous devices.
|
|
## </summary>
|
|
## <param name="domain">
|
|
## Domain allowed access.
|
|
## </param>
|
|
#
|
|
interface(`dev_dontaudit_setattr_misc',`
|
|
gen_require(`
|
|
type misc_device_t;
|
|
class chr_file setattr;
|
|
')
|
|
|
|
dontaudit $1 misc_device_t:chr_file setattr;
|
|
')
|
|
|
|
########################################
|
|
## <summary>
|
|
## Read miscellaneous devices.
|
|
## </summary>
|
|
## <param name="domain">
|
|
## Domain allowed access.
|
|
## </param>
|
|
#
|
|
interface(`dev_read_misc',`
|
|
gen_require(`
|
|
type device_t, misc_device_t;
|
|
class dir r_dir_perms;
|
|
class chr_file r_file_perms;
|
|
')
|
|
|
|
allow $1 device_t:dir r_dir_perms;
|
|
allow $1 misc_device_t:chr_file r_file_perms;
|
|
')
|
|
|
|
########################################
|
|
## <summary>
|
|
## Write miscellaneous devices.
|
|
## </summary>
|
|
## <param name="domain">
|
|
## Domain allowed access.
|
|
## </param>
|
|
#
|
|
interface(`dev_write_misc',`
|
|
gen_require(`
|
|
type device_t, misc_device_t;
|
|
class dir r_dir_perms;
|
|
class chr_file { getattr write ioctl };
|
|
')
|
|
|
|
allow $1 device_t:dir r_dir_perms;
|
|
allow $1 misc_device_t:chr_file { getattr write ioctl };
|
|
')
|
|
|
|
########################################
|
|
## <summary>
|
|
## Get the attributes of the mouse devices.
|
|
## </summary>
|
|
## <param name="domain">
|
|
## Domain allowed access.
|
|
## </param>
|
|
#
|
|
interface(`dev_getattr_mouse',`
|
|
gen_require(`
|
|
type device_t, mouse_device_t;
|
|
class dir r_dir_perms;
|
|
class chr_file getattr;
|
|
')
|
|
|
|
allow $1 device_t:dir r_dir_perms;
|
|
allow $1 mouse_device_t:chr_file getattr;
|
|
')
|
|
|
|
########################################
|
|
## <summary>
|
|
## Set the attributes of the mouse devices.
|
|
## </summary>
|
|
## <param name="domain">
|
|
## Domain allowed access.
|
|
## </param>
|
|
#
|
|
interface(`dev_setattr_mouse',`
|
|
gen_require(`
|
|
type device_t, mouse_device_t;
|
|
class dir r_dir_perms;
|
|
class chr_file setattr;
|
|
')
|
|
|
|
allow $1 device_t:dir r_dir_perms;
|
|
allow $1 mouse_device_t:chr_file setattr;
|
|
')
|
|
|
|
########################################
|
|
## <summary>
|
|
## Read the mouse devices.
|
|
## </summary>
|
|
## <param name="domain">
|
|
## Domain allowed access.
|
|
## </param>
|
|
#
|
|
interface(`dev_read_mouse',`
|
|
gen_require(`
|
|
type device_t, mouse_device_t;
|
|
class dir r_dir_perms;
|
|
class chr_file r_file_perms;
|
|
')
|
|
|
|
allow $1 device_t:dir r_dir_perms;
|
|
allow $1 mouse_device_t:chr_file r_file_perms;
|
|
')
|
|
|
|
########################################
|
|
## <summary>
|
|
## Set the attributes of the printer device nodes.
|
|
## </summary>
|
|
## <param name="domain">
|
|
## Domain allowed access.
|
|
## </param>
|
|
#
|
|
interface(`dev_setattr_printer',`
|
|
gen_require(`
|
|
type device_t, printer_device_t;
|
|
class dir search;
|
|
class chr_file setattr;
|
|
')
|
|
|
|
allow $1 device_t:dir search;
|
|
allow $1 printer_device_t:chr_file setattr;
|
|
')
|
|
|
|
########################################
|
|
## <summary>
|
|
## Read input event devices (/dev/input).
|
|
## </summary>
|
|
## <param name="domain">
|
|
## Domain allowed access.
|
|
## </param>
|
|
#
|
|
interface(`dev_read_input',`
|
|
gen_require(`
|
|
type device_t, event_device_t;
|
|
class dir r_dir_perms;
|
|
class chr_file r_file_perms;
|
|
')
|
|
|
|
allow $1 device_t:dir r_dir_perms;
|
|
allow $1 event_device_t:chr_file r_file_perms;
|
|
')
|
|
|
|
########################################
|
|
## <summary>
|
|
## Read the multiplexed input device (/dev/input).
|
|
## </summary>
|
|
## <param name="domain">
|
|
## Domain allowed access.
|
|
## </param>
|
|
#
|
|
interface(`dev_read_cpuid',`
|
|
gen_require(`
|
|
type device_t, cpu_device_t;
|
|
class dir r_dir_perms;
|
|
class chr_file r_file_perms;
|
|
')
|
|
|
|
allow $1 device_t:dir r_dir_perms;
|
|
allow $1 cpu_device_t:chr_file r_file_perms;
|
|
')
|
|
|
|
########################################
|
|
## <summary>
|
|
## Read and write the the cpu microcode device. This
|
|
## is required to load cpu microcode.
|
|
## </summary>
|
|
## <param name="domain">
|
|
## Domain allowed access.
|
|
## </param>
|
|
#
|
|
interface(`dev_rw_cpu_microcode',`
|
|
gen_require(`
|
|
type device_t, cpu_device_t;
|
|
class dir r_dir_perms;
|
|
class chr_file rw_file_perms;
|
|
')
|
|
|
|
allow $1 device_t:dir r_dir_perms;
|
|
allow $1 cpu_device_t:chr_file rw_file_perms;
|
|
')
|
|
|
|
########################################
|
|
## <summary>
|
|
## Get the attributes of the scanner device.
|
|
## </summary>
|
|
## <param name="domain">
|
|
## Domain allowed access.
|
|
## </param>
|
|
#
|
|
interface(`dev_getattr_scanner',`
|
|
gen_require(`
|
|
type device_t, scanner_device_t;
|
|
class dir r_dir_perms;
|
|
class chr_file getattr;
|
|
')
|
|
|
|
allow $1 device_t:dir r_dir_perms;
|
|
allow $1 scanner_device_t:chr_file getattr;
|
|
')
|
|
|
|
########################################
|
|
## <summary>
|
|
## Do not audit attempts to get the attributes of
|
|
## the scanner device.
|
|
## </summary>
|
|
## <param name="domain">
|
|
## Domain to not audit.
|
|
## </param>
|
|
#
|
|
interface(`dev_dontaudit_getattr_scanner',`
|
|
gen_require(`
|
|
type scanner_device_t;
|
|
class chr_file getattr;
|
|
')
|
|
|
|
dontaudit $1 scanner_device_t:chr_file getattr;
|
|
')
|
|
|
|
########################################
|
|
## <summary>
|
|
## Set the attributes of the scanner device.
|
|
## </summary>
|
|
## <param name="domain">
|
|
## Domain allowed access.
|
|
## </param>
|
|
#
|
|
interface(`dev_setattr_scanner',`
|
|
gen_require(`
|
|
type device_t, scanner_device_t;
|
|
class dir r_dir_perms;
|
|
class chr_file getattr;
|
|
')
|
|
|
|
allow $1 device_t:dir r_dir_perms;
|
|
allow $1 scanner_device_t:chr_file setattr;
|
|
')
|
|
|
|
########################################
|
|
## <summary>
|
|
## Do not audit attempts to set the attributes of
|
|
## the scanner device.
|
|
## </summary>
|
|
## <param name="domain">
|
|
## Domain to not audit.
|
|
## </param>
|
|
#
|
|
interface(`dev_dontaudit_setattr_scanner',`
|
|
gen_require(`
|
|
type scanner_device_t;
|
|
class chr_file getattr;
|
|
')
|
|
|
|
dontaudit $1 scanner_device_t:chr_file setattr;
|
|
')
|
|
|
|
########################################
|
|
## <summary>
|
|
## Read and write the scanner device.
|
|
## </summary>
|
|
## <param name="domain">
|
|
## Domain allowed access.
|
|
## </param>
|
|
#
|
|
interface(`dev_rw_scanner',`
|
|
gen_require(`
|
|
type device_t, scanner_device_t;
|
|
class dir r_dir_perms;
|
|
class chr_file rw_file_perms;
|
|
')
|
|
|
|
allow $1 device_t:dir r_dir_perms;
|
|
allow $1 scanner_device_t:chr_file rw_file_perms;
|
|
')
|
|
|
|
########################################
|
|
## <summary>
|
|
## Get the attributes of the the power management device.
|
|
## </summary>
|
|
## <param name="domain">
|
|
## Domain allowed access.
|
|
## </param>
|
|
#
|
|
interface(`dev_getattr_power_management',`
|
|
gen_require(`
|
|
type device_t, power_device_t;
|
|
class dir r_dir_perms;
|
|
class chr_file getattr;
|
|
')
|
|
|
|
allow $1 device_t:dir r_dir_perms;
|
|
allow $1 power_device_t:chr_file getattr;
|
|
')
|
|
|
|
########################################
|
|
## <summary>
|
|
## Set the attributes of the the power management device.
|
|
## </summary>
|
|
## <param name="domain">
|
|
## Domain allowed access.
|
|
## </param>
|
|
#
|
|
interface(`dev_setattr_power_management',`
|
|
gen_require(`
|
|
type device_t, power_device_t;
|
|
class dir r_dir_perms;
|
|
class chr_file setattr;
|
|
')
|
|
|
|
allow $1 device_t:dir r_dir_perms;
|
|
allow $1 power_device_t:chr_file setattr;
|
|
')
|
|
|
|
########################################
|
|
## <summary>
|
|
## Read and write the the power management device.
|
|
## </summary>
|
|
## <param name="domain">
|
|
## Domain allowed access.
|
|
## </param>
|
|
#
|
|
interface(`dev_rw_power_management',`
|
|
gen_require(`
|
|
type device_t, power_device_t;
|
|
class dir r_dir_perms;
|
|
class chr_file rw_file_perms;
|
|
')
|
|
|
|
allow $1 device_t:dir r_dir_perms;
|
|
allow $1 power_device_t:chr_file rw_file_perms;
|
|
')
|
|
|
|
########################################
|
|
## <summary>
|
|
## Get the attributes of sysfs directories.
|
|
## </summary>
|
|
## <param name="domain">
|
|
## The type of the process performing this action.
|
|
## </param>
|
|
#
|
|
interface(`dev_getattr_sysfs_dir',`
|
|
gen_require(`
|
|
type sysfs_t;
|
|
class dir getattr;
|
|
')
|
|
|
|
allow $1 sysfs_t:dir getattr;
|
|
')
|
|
|
|
########################################
|
|
## <summary>
|
|
## Search the sysfs directories.
|
|
## </summary>
|
|
## <param name="domain">
|
|
## The type of the process performing this action.
|
|
## </param>
|
|
#
|
|
interface(`dev_search_sysfs',`
|
|
gen_require(`
|
|
type sysfs_t;
|
|
class dir search;
|
|
')
|
|
|
|
allow $1 sysfs_t:dir search;
|
|
')
|
|
|
|
########################################
|
|
## <summary>
|
|
## Do not audit attempts to search sysfs.
|
|
## </summary>
|
|
## <param name="domain">
|
|
## The type of the process performing this action.
|
|
## </param>
|
|
#
|
|
interface(`dev_dontaudit_search_sysfs',`
|
|
gen_require(`
|
|
type sysfs_t;
|
|
class dir search;
|
|
')
|
|
|
|
dontaudit $1 sysfs_t:dir search;
|
|
')
|
|
|
|
########################################
|
|
## <summary>
|
|
## List the contents of the sysfs directories.
|
|
## </summary>
|
|
## <param name="domain">
|
|
## The type of the process performing this action.
|
|
## </param>
|
|
#
|
|
interface(`dev_list_sysfs',`
|
|
gen_require(`
|
|
type sysfs_t;
|
|
class dir r_dir_perms;
|
|
')
|
|
|
|
allow $1 sysfs_t:dir r_dir_perms;
|
|
')
|
|
|
|
########################################
|
|
## <summary>
|
|
## Allow caller to read hardware state information.
|
|
## </summary>
|
|
## <param name="domain">
|
|
## The process type reading hardware state information.
|
|
## </param>
|
|
#
|
|
interface(`dev_read_sysfs',`
|
|
gen_require(`
|
|
type sysfs_t;
|
|
class dir r_dir_perms;
|
|
class file r_file_perms;
|
|
class lnk_file r_file_perms;
|
|
')
|
|
|
|
allow $1 sysfs_t:dir r_dir_perms;
|
|
allow $1 sysfs_t:{ file lnk_file } r_file_perms;
|
|
')
|
|
|
|
########################################
|
|
## <summary>
|
|
## Allow caller to modify hardware state information.
|
|
## </summary>
|
|
## <param name="domain">
|
|
## The process type modifying hardware state information.
|
|
## </param>
|
|
#
|
|
interface(`dev_rw_sysfs',`
|
|
gen_require(`
|
|
type sysfs_t;
|
|
class dir r_dir_perms;
|
|
class file rw_file_perms;
|
|
class lnk_file r_file_perms;
|
|
')
|
|
|
|
allow $1 sysfs_t:dir r_dir_perms;
|
|
allow $1 sysfs_t:lnk_file r_file_perms;
|
|
allow $1 sysfs_t:file rw_file_perms;
|
|
')
|
|
|
|
########################################
|
|
## <summary>
|
|
## Mount a usbfs filesystem.
|
|
## </summary>
|
|
## <param name="domain">
|
|
## The type of the process performing this action.
|
|
## </param>
|
|
#
|
|
interface(`dev_mount_usbfs',`
|
|
gen_require(`
|
|
type usbfs_t;
|
|
class filesystem mount;
|
|
')
|
|
|
|
allow $1 usbfs_t:filesystem mount;
|
|
')
|
|
|
|
########################################
|
|
## <summary>
|
|
## Get the attributes of a directory in the usb filesystem.
|
|
## </summary>
|
|
## <param name="domain">
|
|
## Domain allowed access.
|
|
## </param>
|
|
#
|
|
interface(`dev_getattr_usbfs_dir',`
|
|
gen_require(`
|
|
type usbfs_t;
|
|
class dir getattr;
|
|
')
|
|
|
|
allow $1 usbfs_t:dir getattr;
|
|
')
|
|
|
|
########################################
|
|
## <summary>
|
|
## Search the directory containing USB hardware information.
|
|
## </summary>
|
|
## <param name="domain">
|
|
## The type of the process performing this action.
|
|
## </param>
|
|
#
|
|
interface(`dev_search_usbfs',`
|
|
gen_require(`
|
|
type usbfs_t;
|
|
class dir search;
|
|
')
|
|
|
|
allow $1 usbfs_t:dir search;
|
|
')
|
|
|
|
########################################
|
|
## <summary>
|
|
## Allow caller to get a list of usb hardware.
|
|
## </summary>
|
|
## <param name="domain">
|
|
## The process type getting the list.
|
|
## </param>
|
|
#
|
|
interface(`dev_list_usbfs',`
|
|
gen_require(`
|
|
type usbfs_t;
|
|
class dir r_dir_perms;
|
|
class file getattr;
|
|
class lnk_file r_file_perms;
|
|
')
|
|
|
|
allow $1 usbfs_t:dir r_dir_perms;
|
|
allow $1 usbfs_t:lnk_file r_file_perms;
|
|
allow $1 usbfs_t:file getattr;
|
|
')
|
|
|
|
########################################
|
|
## <summary>
|
|
## Read USB hardware information using
|
|
## the usbfs filesystem interface.
|
|
## </summary>
|
|
## <param name="domain">
|
|
## The type of the process performing this action.
|
|
## </param>
|
|
#
|
|
interface(`dev_read_usbfs',`
|
|
gen_require(`
|
|
type usbfs_t;
|
|
class dir r_dir_perms;
|
|
class file r_file_perms;
|
|
class lnk_file r_file_perms;
|
|
')
|
|
|
|
allow $1 usbfs_t:dir r_dir_perms;
|
|
allow $1 usbfs_t:{ file lnk_file } r_file_perms;
|
|
')
|
|
|
|
########################################
|
|
## <summary>
|
|
## Allow caller to modify usb hardware configuration files.
|
|
## </summary>
|
|
## <param name="domain">
|
|
## The process type modifying the options.
|
|
## </param>
|
|
#
|
|
interface(`dev_rw_usbfs',`
|
|
gen_require(`
|
|
type usbfs_t;
|
|
class dir r_dir_perms;
|
|
class file rw_file_perms;
|
|
class lnk_file r_file_perms;
|
|
')
|
|
|
|
allow $1 usbfs_t:dir r_dir_perms;
|
|
allow $1 usbfs_t:lnk_file r_file_perms;
|
|
allow $1 usbfs_t:file rw_file_perms;
|
|
')
|
|
|
|
########################################
|
|
## <summary>
|
|
## Get the attributes of video4linux devices.
|
|
## </summary>
|
|
## <param name="domain">
|
|
## Domain allowed access.
|
|
## </param>
|
|
#
|
|
interface(`dev_getattr_video_dev',`
|
|
gen_require(`
|
|
type device_t, v4l_device_t;
|
|
class dir r_dir_perms;
|
|
class chr_file getattr;
|
|
')
|
|
|
|
allow $1 device_t:dir r_dir_perms;
|
|
allow $1 v4l_device_t:chr_file getattr;
|
|
')
|
|
|
|
########################################
|
|
## <summary>
|
|
## Do not audit attempts to get the attributes
|
|
## of video4linux device nodes.
|
|
## </summary>
|
|
## <param name="domain">
|
|
## Domain to not audit.
|
|
## </param>
|
|
#
|
|
interface(`dev_dontaudit_getattr_video_dev',`
|
|
gen_require(`
|
|
type v4l_device_t;
|
|
class chr_file getattr;
|
|
')
|
|
|
|
dontaudit $1 v4l_device_t:chr_file getattr;
|
|
')
|
|
|
|
########################################
|
|
## <summary>
|
|
## Set the attributes of video4linux device nodes.
|
|
## </summary>
|
|
## <param name="domain">
|
|
## Domain allowed access.
|
|
## </param>
|
|
#
|
|
interface(`dev_setattr_video_dev',`
|
|
gen_require(`
|
|
type device_t, v4l_device_t;
|
|
class dir r_dir_perms;
|
|
class chr_file setattr;
|
|
')
|
|
|
|
allow $1 device_t:dir r_dir_perms;
|
|
allow $1 v4l_device_t:chr_file setattr;
|
|
')
|
|
|
|
########################################
|
|
## <summary>
|
|
## Do not audit attempts to set the attributes
|
|
## of video4linux device nodes.
|
|
## </summary>
|
|
## <param name="domain">
|
|
## Domain to not audit.
|
|
## </param>
|
|
#
|
|
interface(`dev_dontaudit_setattr_video_dev',`
|
|
gen_require(`
|
|
type v4l_device_t;
|
|
class chr_file setattr;
|
|
')
|
|
|
|
dontaudit $1 v4l_device_t:chr_file setattr;
|
|
')
|
|
|
|
########################################
|
|
## <summary>
|
|
## Unconfined access to devices.
|
|
## </summary>
|
|
## <param name="domain">
|
|
## Domain allowed access.
|
|
## </param>
|
|
#
|
|
interface(`dev_unconfined',`
|
|
gen_require(`
|
|
attribute device_node, memory_raw_write, memory_raw_read;
|
|
type mtrr_device_t;
|
|
')
|
|
|
|
allow $1 device_node:devfile_class_set *;
|
|
allow $1 mtrr_device_t:file *;
|
|
|
|
allow $1 self:capability sys_rawio;
|
|
typeattribute $1 memory_raw_write, memory_raw_read;
|
|
')
|
|
|