Changeset 2745
- Timestamp:
- 07/08/08 10:43:41 (5 months ago)
- Files:
-
- branches/rbacsep/Changelog (modified) (2 diffs)
- branches/rbacsep/VERSION (modified) (1 diff)
- branches/rbacsep/doc/policy.dtd (modified) (1 diff)
- branches/rbacsep/doc/templates/interface.html (modified) (2 diffs)
- branches/rbacsep/doc/templates/template.html (modified) (2 diffs)
- branches/rbacsep/policy/modules/admin/acct.te (modified) (1 diff)
- branches/rbacsep/policy/modules/admin/alsa.te (modified) (1 diff)
- branches/rbacsep/policy/modules/admin/amanda.te (modified) (1 diff)
- branches/rbacsep/policy/modules/admin/anaconda.te (modified) (1 diff)
- branches/rbacsep/policy/modules/admin/bootloader.te (modified) (1 diff)
- branches/rbacsep/policy/modules/admin/dmesg.te (modified) (1 diff)
- branches/rbacsep/policy/modules/admin/firstboot.te (modified) (1 diff)
- branches/rbacsep/policy/modules/admin/kudzu.te (modified) (1 diff)
- branches/rbacsep/policy/modules/admin/logrotate.te (modified) (1 diff)
- branches/rbacsep/policy/modules/admin/logwatch.te (modified) (1 diff)
- branches/rbacsep/policy/modules/admin/mrtg.te (modified) (1 diff)
- branches/rbacsep/policy/modules/admin/portage.te (modified) (1 diff)
- branches/rbacsep/policy/modules/admin/readahead.te (modified) (1 diff)
- branches/rbacsep/policy/modules/admin/usermanage.te (modified) (1 diff)
- branches/rbacsep/policy/modules/admin/vbetool.if (modified) (1 diff)
- branches/rbacsep/policy/modules/apps/calamaris.te (modified) (1 diff)
- branches/rbacsep/policy/modules/apps/games.te (modified) (1 diff)
- branches/rbacsep/policy/modules/apps/gpg.te (modified) (1 diff)
- branches/rbacsep/policy/modules/apps/mono.if (modified) (1 diff)
- branches/rbacsep/policy/modules/apps/mono.te (modified) (1 diff)
- branches/rbacsep/policy/modules/apps/podsleuth.fc (copied) (copied from trunk/policy/modules/apps/podsleuth.fc)
- branches/rbacsep/policy/modules/apps/podsleuth.if (copied) (copied from trunk/policy/modules/apps/podsleuth.if)
- branches/rbacsep/policy/modules/apps/podsleuth.te (copied) (copied from trunk/policy/modules/apps/podsleuth.te)
- branches/rbacsep/policy/modules/apps/qemu.fc (copied) (copied from trunk/policy/modules/apps/qemu.fc)
- branches/rbacsep/policy/modules/apps/qemu.if (copied) (copied from trunk/policy/modules/apps/qemu.if)
- branches/rbacsep/policy/modules/apps/qemu.te (copied) (copied from trunk/policy/modules/apps/qemu.te)
- branches/rbacsep/policy/modules/apps/uml.te (modified) (1 diff)
- branches/rbacsep/policy/modules/apps/userhelper.te (modified) (1 diff)
- branches/rbacsep/policy/modules/apps/vmware.fc (modified) (1 diff)
- branches/rbacsep/policy/modules/apps/vmware.if (modified) (1 diff)
- branches/rbacsep/policy/modules/apps/vmware.te (modified) (6 diffs)
- branches/rbacsep/policy/modules/kernel/corecommands.fc (modified) (8 diffs)
- branches/rbacsep/policy/modules/kernel/corecommands.te (modified) (1 diff)
- branches/rbacsep/policy/modules/kernel/filesystem.te (modified) (1 diff)
- branches/rbacsep/policy/modules/kernel/kernel.if (modified) (1 diff)
- branches/rbacsep/policy/modules/kernel/kernel.te (modified) (4 diffs)
- branches/rbacsep/policy/modules/services/afs.te (modified) (1 diff)
- branches/rbacsep/policy/modules/services/amavis.te (modified) (1 diff)
- branches/rbacsep/policy/modules/services/apache.if (modified) (1 diff)
- branches/rbacsep/policy/modules/services/apache.te (modified) (7 diffs)
- branches/rbacsep/policy/modules/services/apm.te (modified) (1 diff)
- branches/rbacsep/policy/modules/services/arpwatch.te (modified) (1 diff)
- branches/rbacsep/policy/modules/services/asterisk.te (modified) (1 diff)
- branches/rbacsep/policy/modules/services/audioentropy.te (modified) (1 diff)
- branches/rbacsep/policy/modules/services/automount.te (modified) (1 diff)
- branches/rbacsep/policy/modules/services/avahi.te (modified) (1 diff)
- branches/rbacsep/policy/modules/services/bind.te (modified) (1 diff)
- branches/rbacsep/policy/modules/services/bluetooth.te (modified) (1 diff)
- branches/rbacsep/policy/modules/services/canna.te (modified) (1 diff)
- branches/rbacsep/policy/modules/services/comsat.te (modified) (1 diff)
- branches/rbacsep/policy/modules/services/courier.te (modified) (1 diff)
- branches/rbacsep/policy/modules/services/cpucontrol.if (modified) (1 diff)
- branches/rbacsep/policy/modules/services/cron.if (modified) (1 diff)
- branches/rbacsep/policy/modules/services/cups.te (modified) (1 diff)
- branches/rbacsep/policy/modules/services/cyrus.te (modified) (1 diff)
- branches/rbacsep/policy/modules/services/dante.te (modified) (1 diff)
- branches/rbacsep/policy/modules/services/dbus.if (modified) (1 diff)
- branches/rbacsep/policy/modules/services/dbus.te (modified) (1 diff)
- branches/rbacsep/policy/modules/services/dcc.te (modified) (1 diff)
- branches/rbacsep/policy/modules/services/ddclient.te (modified) (1 diff)
- branches/rbacsep/policy/modules/services/dhcp.te (modified) (1 diff)
- branches/rbacsep/policy/modules/services/distcc.te (modified) (1 diff)
- branches/rbacsep/policy/modules/services/dnsmasq.te (modified) (1 diff)
- branches/rbacsep/policy/modules/services/dovecot.te (modified) (1 diff)
- branches/rbacsep/policy/modules/services/exim.te (modified) (1 diff)
- branches/rbacsep/policy/modules/services/fetchmail.te (modified) (1 diff)
- branches/rbacsep/policy/modules/services/finger.te (modified) (1 diff)
- branches/rbacsep/policy/modules/services/ftp.te (modified) (1 diff)
- branches/rbacsep/policy/modules/services/gatekeeper.te (modified) (1 diff)
- branches/rbacsep/policy/modules/services/gpm.te (modified) (1 diff)
- branches/rbacsep/policy/modules/services/hal.fc (modified) (2 diffs)
- branches/rbacsep/policy/modules/services/hal.te (modified) (13 diffs)
- branches/rbacsep/policy/modules/services/howl.te (modified) (1 diff)
- branches/rbacsep/policy/modules/services/i18n_input.te (modified) (1 diff)
- branches/rbacsep/policy/modules/services/imaze.te (modified) (1 diff)
- branches/rbacsep/policy/modules/services/inetd.te (modified) (1 diff)
- branches/rbacsep/policy/modules/services/inn.te (modified) (1 diff)
- branches/rbacsep/policy/modules/services/ircd.te (modified) (1 diff)
- branches/rbacsep/policy/modules/services/irqbalance.te (modified) (1 diff)
- branches/rbacsep/policy/modules/services/jabber.te (modified) (1 diff)
- branches/rbacsep/policy/modules/services/kerberos.te (modified) (1 diff)
- branches/rbacsep/policy/modules/services/ldap.te (modified) (1 diff)
- branches/rbacsep/policy/modules/services/lpd.te (modified) (1 diff)
- branches/rbacsep/policy/modules/services/mailman.te (modified) (1 diff)
- branches/rbacsep/policy/modules/services/monop.te (modified) (1 diff)
- branches/rbacsep/policy/modules/services/mta.if (modified) (1 diff)
- branches/rbacsep/policy/modules/services/mta.te (modified) (1 diff)
- branches/rbacsep/policy/modules/services/munin.te (modified) (1 diff)
- branches/rbacsep/policy/modules/services/mysql.te (modified) (1 diff)
- branches/rbacsep/policy/modules/services/nagios.te (modified) (1 diff)
- branches/rbacsep/policy/modules/services/nessus.te (modified) (1 diff)
- branches/rbacsep/policy/modules/services/networkmanager.te (modified) (1 diff)
- branches/rbacsep/policy/modules/services/nis.te (modified) (1 diff)
- branches/rbacsep/policy/modules/services/nscd.te (modified) (1 diff)
- branches/rbacsep/policy/modules/services/nsd.te (modified) (1 diff)
- branches/rbacsep/policy/modules/services/ntop.te (modified) (1 diff)
- branches/rbacsep/policy/modules/services/ntp.if (modified) (1 diff)
- branches/rbacsep/policy/modules/services/ntp.te (modified) (1 diff)
- branches/rbacsep/policy/modules/services/oav.te (modified) (1 diff)
- branches/rbacsep/policy/modules/services/oddjob.te (modified) (1 diff)
- branches/rbacsep/policy/modules/services/openct.te (modified) (1 diff)
- branches/rbacsep/policy/modules/services/pegasus.te (modified) (1 diff)
- branches/rbacsep/policy/modules/services/perdition.te (modified) (1 diff)
- branches/rbacsep/policy/modules/services/portmap.te (modified) (1 diff)
- branches/rbacsep/policy/modules/services/postfix.fc (modified) (1 diff)
- branches/rbacsep/policy/modules/services/postfix.if (modified) (1 diff)
- branches/rbacsep/policy/modules/services/postfix.te (modified) (3 diffs)
- branches/rbacsep/policy/modules/services/postgresql.fc (modified) (2 diffs)
- branches/rbacsep/policy/modules/services/postgresql.if (modified) (2 diffs)
- branches/rbacsep/policy/modules/services/postgresql.te (modified) (7 diffs)
- branches/rbacsep/policy/modules/services/postgrey.te (modified) (1 diff)
- branches/rbacsep/policy/modules/services/ppp.te (modified) (1 diff)
- branches/rbacsep/policy/modules/services/prelude.fc (copied) (copied from trunk/policy/modules/services/prelude.fc)
- branches/rbacsep/policy/modules/services/prelude.if (copied) (copied from trunk/policy/modules/services/prelude.if)
- branches/rbacsep/policy/modules/services/prelude.te (copied) (copied from trunk/policy/modules/services/prelude.te)
- branches/rbacsep/policy/modules/services/privoxy.te (modified) (1 diff)
- branches/rbacsep/policy/modules/services/procmail.te (modified) (1 diff)
- branches/rbacsep/policy/modules/services/pxe.te (modified) (1 diff)
- branches/rbacsep/policy/modules/services/pyzor.te (modified) (1 diff)
- branches/rbacsep/policy/modules/services/radius.te (modified) (1 diff)
- branches/rbacsep/policy/modules/services/radvd.te (modified) (1 diff)
- branches/rbacsep/policy/modules/services/rhgb.if (modified) (1 diff)
- branches/rbacsep/policy/modules/services/rhgb.te (modified) (1 diff)
- branches/rbacsep/policy/modules/services/rlogin.te (modified) (1 diff)
- branches/rbacsep/policy/modules/services/roundup.te (modified) (1 diff)
- branches/rbacsep/policy/modules/services/rpc.if (modified) (1 diff)
- branches/rbacsep/policy/modules/services/samba.te (modified) (1 diff)
- branches/rbacsep/policy/modules/services/sasl.te (modified) (1 diff)
- branches/rbacsep/policy/modules/services/sendmail.if (modified) (1 diff)
- branches/rbacsep/policy/modules/services/sendmail.te (modified) (1 diff)
- branches/rbacsep/policy/modules/services/setroubleshoot.te (modified) (1 diff)
- branches/rbacsep/policy/modules/services/slrnpull.te (modified) (1 diff)
- branches/rbacsep/policy/modules/services/smartmon.te (modified) (1 diff)
- branches/rbacsep/policy/modules/services/snmp.te (modified) (1 diff)
- branches/rbacsep/policy/modules/services/snort.te (modified) (1 diff)
- branches/rbacsep/policy/modules/services/soundserver.te (modified) (1 diff)
- branches/rbacsep/policy/modules/services/spamassassin.te (modified) (1 diff)
- branches/rbacsep/policy/modules/services/speedtouch.te (modified) (1 diff)
- branches/rbacsep/policy/modules/services/squid.te (modified) (1 diff)
- branches/rbacsep/policy/modules/services/stunnel.te (modified) (1 diff)
- branches/rbacsep/policy/modules/services/sysstat.te (modified) (1 diff)
- branches/rbacsep/policy/modules/services/telnet.te (modified) (1 diff)
- branches/rbacsep/policy/modules/services/tftp.te (modified) (1 diff)
- branches/rbacsep/policy/modules/services/timidity.te (modified) (1 diff)
- branches/rbacsep/policy/modules/services/transproxy.te (modified) (1 diff)
- branches/rbacsep/policy/modules/services/uptime.te (modified) (1 diff)
- branches/rbacsep/policy/modules/services/uwimap.te (modified) (1 diff)
- branches/rbacsep/policy/modules/services/virt.fc (copied) (copied from trunk/policy/modules/services/virt.fc)
- branches/rbacsep/policy/modules/services/virt.if (copied) (copied from trunk/policy/modules/services/virt.if)
- branches/rbacsep/policy/modules/services/virt.te (copied) (copied from trunk/policy/modules/services/virt.te)
- branches/rbacsep/policy/modules/services/watchdog.te (modified) (1 diff)
- branches/rbacsep/policy/modules/services/xfs.te (modified) (1 diff)
- branches/rbacsep/policy/modules/services/xprint.te (modified) (1 diff)
- branches/rbacsep/policy/modules/services/xserver.te (modified) (2 diffs)
- branches/rbacsep/policy/modules/services/zebra.te (modified) (1 diff)
- branches/rbacsep/policy/modules/system/authlogin.te (modified) (1 diff)
- branches/rbacsep/policy/modules/system/hotplug.te (modified) (1 diff)
- branches/rbacsep/policy/modules/system/init.fc (modified) (1 diff)
- branches/rbacsep/policy/modules/system/init.te (modified) (1 diff)
- branches/rbacsep/policy/modules/system/ipsec.te (modified) (1 diff)
- branches/rbacsep/policy/modules/system/libraries.fc (modified) (1 diff)
- branches/rbacsep/policy/modules/system/libraries.te (modified) (2 diffs)
- branches/rbacsep/policy/modules/system/locallogin.te (modified) (1 diff)
- branches/rbacsep/policy/modules/system/logging.te (modified) (1 diff)
- branches/rbacsep/policy/modules/system/lvm.te (modified) (1 diff)
- branches/rbacsep/policy/modules/system/modutils.te (modified) (1 diff)
- branches/rbacsep/policy/modules/system/pcmcia.if (modified) (1 diff)
- branches/rbacsep/policy/modules/system/pcmcia.te (modified) (1 diff)
- branches/rbacsep/policy/modules/system/raid.te (modified) (1 diff)
- branches/rbacsep/policy/modules/system/selinuxutil.te (modified) (1 diff)
- branches/rbacsep/policy/modules/system/setrans.if (modified) (1 diff)
- branches/rbacsep/policy/modules/system/sysnetwork.te (modified) (1 diff)
- branches/rbacsep/policy/modules/system/unconfined.if (modified) (1 diff)
- branches/rbacsep/policy/modules/system/unconfined.te (modified) (1 diff)
- branches/rbacsep/policy/modules/system/userdomain.if (modified) (3 diffs)
- branches/rbacsep/policy/modules/system/userdomain.te (modified) (1 diff)
- branches/rbacsep/policy/modules/system/xen.te (modified) (1 diff)
- branches/rbacsep/policy/users (modified) (1 diff)
- branches/rbacsep/support/sedoctool.py (modified) (2 diffs)
Legend:
- Unmodified
- Added
- Removed
- Modified
- Copied
- Moved
branches/rbacsep/Changelog
r2705 r2745 1 * Wed Jul 02 2008 Chris PeBenito <selinux@tresys.com> - 20080702 2 - Fix httpd_enable_homedirs to actually provide the access it is supposed to 3 provide. 4 - Add unused interface/template parameter metadata in XML. 5 - Patch to handle postfix data_directory from Vaclav Ovsik. 6 - SE-Postgresql policy from KaiGai Kohei. 7 - Patch for X.org dbus support from Martin Orr. 1 8 - Patch for labeled networking controls in 2.6.25 from Paul Moore. 2 9 - Module loading now requires setsched on kernel threads. … … 12 19 kerneloops (Dan Walsh) 13 20 kismet (Dan Walsh) 21 podsleuth (Dan Walsh) 22 prelude (Dan Walsh) 23 qemu (Dan Walsh) 24 virt (Dan Walsh) 14 25 15 26 * Wed Apr 02 2008 Chris PeBenito <selinux@tresys.com> - 20080402 branches/rbacsep/VERSION
r2675 r2745 1 20080 4021 20080702 branches/rbacsep/doc/policy.dtd
r2243 r2745 29 29 <!ATTLIST param 30 30 name CDATA #REQUIRED 31 optional (true|false) "false"> 31 optional (true|false) "false" 32 unused (true|false) "false"> 32 33 <!ELEMENT infoflow EMPTY> 33 34 <!ATTLIST infoflow branches/rbacsep/doc/templates/interface.html
r476 r2745 36 36 [[end]] 37 37 <h5>Parameters</h5> 38 <table border="1" cellspacing="0" cellpadding="3" width=" 80%">39 <tr><th >Parameter:</t d><th >Description:</td><th >Optional:</td></tr>38 <table border="1" cellspacing="0" cellpadding="3" width="65%"> 39 <tr><th >Parameter:</th><th >Description:</th></tr> 40 40 [[for arg in int['interface_parameters']]] 41 41 <tr><td> … … 43 43 </td><td> 44 44 [[arg['desc']]] 45 </td><td>46 [[arg['optional']]]47 45 </td></tr> 48 46 [[end]] branches/rbacsep/doc/templates/template.html
r476 r2745 36 36 [[end]] 37 37 <h5>Parameters</h5> 38 <table border="1" cellspacing="0" cellpadding="3" width=" 80%">39 <tr><th >Parameter:</t d><th >Description:</td><th >Optional:</td></tr>38 <table border="1" cellspacing="0" cellpadding="3" width="65%"> 39 <tr><th >Parameter:</th><th >Description:</th></tr> 40 40 [[for arg in temp['template_parameters']]] 41 41 <tr><td> … … 43 43 </td><td> 44 44 [[arg['desc']]] 45 </td><td>46 [[arg['optional']]]47 45 </td></tr> 48 46 [[end]] branches/rbacsep/policy/modules/admin/acct.te
r2675 r2745 1 1 2 policy_module(acct, 1.1.1)2 policy_module(acct, 1.2.0) 3 3 4 4 ######################################## branches/rbacsep/policy/modules/admin/alsa.te
r2675 r2745 1 1 2 policy_module(alsa, 1.4.1)2 policy_module(alsa, 1.5.0) 3 3 4 4 ######################################## branches/rbacsep/policy/modules/admin/amanda.te
r2705 r2745 1 1 2 policy_module(amanda, 1.8.1)2 policy_module(amanda, 1.9.0) 3 3 4 4 ####################################### branches/rbacsep/policy/modules/admin/anaconda.te
r2675 r2745 1 1 2 policy_module(anaconda, 1.2.1)2 policy_module(anaconda, 1.3.0) 3 3 4 4 ######################################## branches/rbacsep/policy/modules/admin/bootloader.te
r2675 r2745 1 1 2 policy_module(bootloader, 1.7.1)2 policy_module(bootloader, 1.8.0) 3 3 4 4 ######################################## branches/rbacsep/policy/modules/admin/dmesg.te
r2675 r2745 1 1 2 policy_module(dmesg, 1.1.1)2 policy_module(dmesg, 1.2.0) 3 3 4 4 ######################################## branches/rbacsep/policy/modules/admin/firstboot.te
r2675 r2745 1 1 2 policy_module(firstboot, 1.6.1)2 policy_module(firstboot, 1.7.0) 3 3 4 4 gen_require(` branches/rbacsep/policy/modules/admin/kudzu.te
r2675 r2745 1 1 2 policy_module(kudzu, 1.5.1)2 policy_module(kudzu, 1.6.0) 3 3 4 4 ######################################## branches/rbacsep/policy/modules/admin/logrotate.te
r2675 r2745 1 1 2 policy_module(logrotate, 1.8.1)2 policy_module(logrotate, 1.9.0) 3 3 4 4 ######################################## branches/rbacsep/policy/modules/admin/logwatch.te
r2675 r2745 1 1 2 policy_module(logwatch, 1.7.1)2 policy_module(logwatch, 1.8.0) 3 3 4 4 ################################# branches/rbacsep/policy/modules/admin/mrtg.te
r2675 r2745 1 1 2 policy_module(mrtg, 1.3.1)2 policy_module(mrtg, 1.4.0) 3 3 4 4 ######################################## branches/rbacsep/policy/modules/admin/portage.te
r2705 r2745 1 1 2 policy_module(portage, 1.5.2)2 policy_module(portage, 1.6.0) 3 3 4 4 ######################################## branches/rbacsep/policy/modules/admin/readahead.te
r2675 r2745 1 1 2 policy_module(readahead, 1.5.1)2 policy_module(readahead, 1.6.0) 3 3 4 4 ######################################## branches/rbacsep/policy/modules/admin/usermanage.te
r2727 r2745 1 1 2 policy_module(usermanage, 1.10.1)2 policy_module(usermanage, 1.11.0) 3 3 4 4 ######################################## branches/rbacsep/policy/modules/admin/vbetool.if
r2239 r2745 5 5 ## Execute vbetool application in the vbetool domain. 6 6 ## </summary> 7 ## <param name="domain" optional="true">7 ## <param name="domain"> 8 8 ## <summary> 9 ## N/A9 ## Domain allowed access. 10 10 ## </summary> 11 11 ## </param> branches/rbacsep/policy/modules/apps/calamaris.te
r2675 r2745 1 1 2 policy_module(calamaris, 1.2.1)2 policy_module(calamaris, 1.3.0) 3 3 4 4 ######################################## branches/rbacsep/policy/modules/apps/games.te
r2724 r2745 1 1 2 policy_module(games, 1.6.1)2 policy_module(games, 1.7.0) 3 3 4 4 ######################################## branches/rbacsep/policy/modules/apps/gpg.te
r2724 r2745 1 1 2 policy_module(gpg, 1. 5.1)2 policy_module(gpg, 1.6.0) 3 3 4 4 ######################################## branches/rbacsep/policy/modules/apps/mono.if
r2169 r2745 19 19 domtrans_pattern($1, mono_exec_t, mono_t) 20 20 ') 21 22 ######################################## 23 ## <summary> 24 ## Execute the mono program in the caller domain. 25 ## </summary> 26 ## <param name="domain"> 27 ## <summary> 28 ## Domain allowed access. 29 ## </summary> 30 ## </param> 31 # 32 interface(`mono_exec',` 33 gen_require(` 34 type mono_t, mono_exec_t; 35 ') 36 37 corecmd_search_bin($1) 38 can_exec($1, mono_exec_t) 39 ') branches/rbacsep/policy/modules/apps/mono.te
r2675 r2745 1 1 2 policy_module(mono, 1.4.1)2 policy_module(mono, 1.5.0) 3 3 4 4 ######################################## branches/rbacsep/policy/modules/apps/uml.te
r2720 r2745 1 1 2 policy_module(uml, 1.5.1)2 policy_module(uml, 1.6.0) 3 3 4 4 ######################################## branches/rbacsep/policy/modules/apps/userhelper.te
r2724 r2745 1 1 2 policy_module(userhelper, 1.3.1)2 policy_module(userhelper, 1.4.0) 3 3 4 4 ######################################## branches/rbacsep/policy/modules/apps/vmware.fc
r2437 r2745 29 29 30 30 /usr/lib/vmware/config -- gen_context(system_u:object_r:vmware_sys_conf_t,s0) 31 /usr/lib/vmware/bin/vmplayer -- gen_context(system_u:object_r:vmware_exec_t,s0) 31 32 /usr/lib/vmware/bin/vmware-mks -- gen_context(system_u:object_r:vmware_exec_t,s0) 32 33 /usr/lib/vmware/bin/vmware-ui -- gen_context(system_u:object_r:vmware_exec_t,s0) 34 /usr/lib/vmware/bin/vmware-vmx -- gen_context(system_u:object_r:vmware_host_exec_t,s0) 35 36 ifdef(`distro_redhat',` 37 /usr/lib/vmware-tools/sbin32/vmware.* -- gen_context(system_u:object_r:vmware_host_exec_t,s0) 38 /usr/lib/vmware-tools/sbin64/vmware.* -- gen_context(system_u:object_r:vmware_host_exec_t,s0) 39 ') 33 40 34 41 /usr/lib64/vmware/config -- gen_context(system_u:object_r:vmware_sys_conf_t,s0) 35 42 /usr/lib64/vmware/bin/vmware-mks -- gen_context(system_u:object_r:vmware_exec_t,s0) 36 43 /usr/lib64/vmware/bin/vmware-ui -- gen_context(system_u:object_r:vmware_exec_t,s0) 44 /usr/lib64/vmware/bin/vmplayer -- gen_context(system_u:object_r:vmware_exec_t,s0) 45 /usr/lib64/vmware/bin/vmware-vmx -- gen_context(system_u:object_r:vmware_host_exec_t,s0) 46 47 /usr/sbin/vmware-guest.* -- gen_context(system_u:object_r:vmware_host_exec_t,s0) 48 /usr/sbin/vmware-serverd -- gen_context(system_u:object_r:vmware_exec_t,s0) 37 49 38 50 ifdef(`distro_gentoo',` 39 /opt/vmware/ workstation/bin/vmnet-bridge -- gen_context(system_u:object_r:vmware_host_exec_t,s0)40 /opt/vmware/ workstation/bin/vmnet-dhcpd-- gen_context(system_u:object_r:vmware_host_exec_t,s0)41 /opt/vmware/ workstation/bin/vmnet-natd -- gen_context(system_u:object_r:vmware_host_exec_t,s0)42 /opt/vmware/ workstation/bin/vmnet-netifup -- gen_context(system_u:object_r:vmware_host_exec_t,s0)43 /opt/vmware/ workstation/bin/vmnet-sniffer -- gen_context(system_u:object_r:vmware_host_exec_t,s0)44 /opt/vmware/ workstation/bin/vmware-nmbd-- gen_context(system_u:object_r:vmware_host_exec_t,s0)45 /opt/vmware/ workstation/bin/vmware-ping-- gen_context(system_u:object_r:vmware_host_exec_t,s0)46 /opt/vmware/ workstation/bin/vmware-smbd-- gen_context(system_u:object_r:vmware_host_exec_t,s0)47 /opt/vmware/ workstation/bin/vmware-smbpasswd -- gen_context(system_u:object_r:vmware_host_exec_t,s0)48 /opt/vmware/ workstation/bin/vmware-smbpasswd\.bin -- gen_context(system_u:object_r:vmware_host_exec_t,s0)49 /opt/vmware/ workstation/bin/vmware-wizard -- gen_context(system_u:object_r:vmware_exec_t,s0)50 /opt/vmware/ workstation/bin/vmware-- gen_context(system_u:object_r:vmware_exec_t,s0)51 /opt/vmware/(workstation|player)/bin/vmnet-bridge -- gen_context(system_u:object_r:vmware_host_exec_t,s0) 52 /opt/vmware/(workstation|player)/bin/vmnet-dhcpd -- gen_context(system_u:object_r:vmware_host_exec_t,s0) 53 /opt/vmware/(workstation|player)/bin/vmnet-natd -- gen_context(system_u:object_r:vmware_host_exec_t,s0) 54 /opt/vmware/(workstation|player)/bin/vmnet-netifup -- gen_context(system_u:object_r:vmware_host_exec_t,s0) 55 /opt/vmware/(workstation|player)/bin/vmnet-sniffer -- gen_context(system_u:object_r:vmware_host_exec_t,s0) 56 /opt/vmware/(workstation|player)/bin/vmware-nmbd -- gen_context(system_u:object_r:vmware_host_exec_t,s0) 57 /opt/vmware/(workstation|player)/bin/vmware-ping -- gen_context(system_u:object_r:vmware_host_exec_t,s0) 58 /opt/vmware/(workstation|player)/bin/vmware-smbd -- gen_context(system_u:object_r:vmware_host_exec_t,s0) 59 /opt/vmware/(workstation|player)/bin/vmware-smbpasswd -- gen_context(system_u:object_r:vmware_host_exec_t,s0) 60 /opt/vmware/(workstation|player)/bin/vmware-smbpasswd\.bin -- gen_context(system_u:object_r:vmware_host_exec_t,s0) 61 /opt/vmware/(workstation|player)/bin/vmware-wizard -- gen_context(system_u:object_r:vmware_exec_t,s0) 62 /opt/vmware/(workstation|player)/bin/vmware -- gen_context(system_u:object_r:vmware_exec_t,s0) 51 63 ') 64 65 /var/log/vmware.* -- gen_context(system_u:object_r:vmware_log_t,s0) 66 67 /var/run/vmnat.* -s gen_context(system_u:object_r:vmware_var_run_t,s0) 68 /var/run/vmware.* gen_context(system_u:object_r:vmware_var_run_t,s0) branches/rbacsep/policy/modules/apps/vmware.if
r2726 r2745 70 70 allow $1 vmware_sys_conf_t:file append; 71 71 ') 72 73 ######################################## 74 ## <summary> 75 ## Append to VMWare log files. 76 ## </summary> 77 ## <param name="domain"> 78 ## <summary> 79 ## Domain allowed access. 80 ## </summary> 81 ## </param> 82 # 83 interface(`vmware_append_log',` 84 gen_require(` 85 type vmware_log_t; 86 ') 87 88 logging_search_logs($1) 89 append_files_pattern($1, vmware_log_t, vmware_log_t) 90 ') branches/rbacsep/policy/modules/apps/vmware.te
r2724 r2745 1 1 2 policy_module(vmware, 1.5.1)2 policy_module(vmware, 1.6.0) 3 3 4 4 ######################################## … … 26 26 files_pid_file(vmware_host_pid_t) 27 27 28 type vmware_log_t; 29 logging_log_file(vmware_log_t) 30 28 31 type vmware_pid_t; 29 32 files_pid_file(vmware_pid_t) … … 44 47 # 45 48 46 allow vmware_host_t self:capability { set uid net_raw };49 allow vmware_host_t self:capability { setgid setuid net_raw }; 47 50 dontaudit vmware_host_t self:capability sys_tty_config; 48 51 allow vmware_host_t self:process signal_perms; … … 50 53 allow vmware_host_t self:unix_stream_socket create_stream_socket_perms; 51 54 allow vmware_host_t self:rawip_socket create_socket_perms; 55 allow vmware_host_t self:tcp_so
