mysql.if 9.3 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474
  1. ## <summary>Open source database.</summary>
  2. ########################################
  3. ## <summary>
  4. ## Role access for mysql.
  5. ## </summary>
  6. ## <param name="role">
  7. ## <summary>
  8. ## Role allowed access.
  9. ## </summary>
  10. ## </param>
  11. ## <param name="domain">
  12. ## <summary>
  13. ## User domain for the role.
  14. ## </summary>
  15. ## </param>
  16. #
  17. interface(`mysql_role',`
  18. refpolicywarn(`$0($*) has been deprecated')
  19. ')
  20. ######################################
  21. ## <summary>
  22. ## Execute MySQL in the mysql domain.
  23. ## </summary>
  24. ## <param name="domain">
  25. ## <summary>
  26. ## Domain allowed to transition.
  27. ## </summary>
  28. ## </param>
  29. #
  30. interface(`mysql_domtrans',`
  31. gen_require(`
  32. type mysqld_t, mysqld_exec_t;
  33. ')
  34. corecmd_search_bin($1)
  35. domtrans_pattern($1, mysqld_exec_t, mysqld_t)
  36. ')
  37. ########################################
  38. ## <summary>
  39. ## Execute mysqld in the mysqld domain, and
  40. ## allow the specified role the mysqld domain.
  41. ## </summary>
  42. ## <param name="domain">
  43. ## <summary>
  44. ## Domain allowed to transition.
  45. ## </summary>
  46. ## </param>
  47. ## <param name="role">
  48. ## <summary>
  49. ## Role allowed access.
  50. ## </summary>
  51. ## </param>
  52. #
  53. interface(`mysql_run_mysqld',`
  54. gen_require(`
  55. attribute_role mysqld_roles;
  56. ')
  57. mysql_domtrans($1)
  58. roleattribute $2 mysqld_roles;
  59. ')
  60. ########################################
  61. ## <summary>
  62. ## Send generic signals to mysqld.
  63. ## </summary>
  64. ## <param name="domain">
  65. ## <summary>
  66. ## Domain allowed access.
  67. ## </summary>
  68. ## </param>
  69. #
  70. interface(`mysql_signal',`
  71. gen_require(`
  72. type mysqld_t;
  73. ')
  74. allow $1 mysqld_t:process signal;
  75. ')
  76. ########################################
  77. ## <summary>
  78. ## Connect to mysqld with a tcp socket.
  79. ## </summary>
  80. ## <param name="domain">
  81. ## <summary>
  82. ## Domain allowed access.
  83. ## </summary>
  84. ## </param>
  85. #
  86. interface(`mysql_tcp_connect',`
  87. gen_require(`
  88. type mysqld_t;
  89. ')
  90. corenet_tcp_recvfrom_labeled($1, mysqld_t)
  91. corenet_tcp_sendrecv_mysqld_port($1)
  92. corenet_tcp_connect_mysqld_port($1)
  93. corenet_sendrecv_mysqld_client_packets($1)
  94. ')
  95. ########################################
  96. ## <summary>
  97. ## Connect to mysqld with a unix
  98. # domain stream socket.
  99. ## </summary>
  100. ## <param name="domain">
  101. ## <summary>
  102. ## Domain allowed access.
  103. ## </summary>
  104. ## </param>
  105. ## <rolecap/>
  106. #
  107. interface(`mysql_stream_connect',`
  108. gen_require(`
  109. type mysqld_t, mysqld_var_run_t, mysqld_db_t;
  110. ')
  111. files_search_pids($1)
  112. stream_connect_pattern($1, { mysqld_db_t mysqld_var_run_t }, mysqld_var_run_t, mysqld_t)
  113. ')
  114. ########################################
  115. ## <summary>
  116. ## Read mysqld configuration content.
  117. ## </summary>
  118. ## <param name="domain">
  119. ## <summary>
  120. ## Domain allowed access.
  121. ## </summary>
  122. ## </param>
  123. ## <rolecap/>
  124. #
  125. interface(`mysql_read_config',`
  126. gen_require(`
  127. type mysqld_etc_t;
  128. ')
  129. files_search_etc($1)
  130. allow $1 mysqld_etc_t:dir list_dir_perms;
  131. allow $1 mysqld_etc_t:file read_file_perms;
  132. allow $1 mysqld_etc_t:lnk_file read_lnk_file_perms;
  133. ')
  134. ########################################
  135. ## <summary>
  136. ## Search mysqld db directories.
  137. ## </summary>
  138. ## <param name="domain">
  139. ## <summary>
  140. ## Domain allowed access.
  141. ## </summary>
  142. ## </param>
  143. #
  144. interface(`mysql_search_db',`
  145. gen_require(`
  146. type mysqld_db_t;
  147. ')
  148. files_search_var_lib($1)
  149. allow $1 mysqld_db_t:dir search_dir_perms;
  150. ')
  151. ########################################
  152. ## <summary>
  153. ## Read and write mysqld database directories.
  154. ## </summary>
  155. ## <param name="domain">
  156. ## <summary>
  157. ## Domain allowed access.
  158. ## </summary>
  159. ## </param>
  160. #
  161. interface(`mysql_rw_db_dirs',`
  162. gen_require(`
  163. type mysqld_db_t;
  164. ')
  165. files_search_var_lib($1)
  166. allow $1 mysqld_db_t:dir rw_dir_perms;
  167. ')
  168. ########################################
  169. ## <summary>
  170. ## Create, read, write, and delete
  171. ## mysqld database directories.
  172. ## </summary>
  173. ## <param name="domain">
  174. ## <summary>
  175. ## Domain allowed access.
  176. ## </summary>
  177. ## </param>
  178. #
  179. interface(`mysql_manage_db_dirs',`
  180. gen_require(`
  181. type mysqld_db_t;
  182. ')
  183. files_search_var_lib($1)
  184. allow $1 mysqld_db_t:dir manage_dir_perms;
  185. ')
  186. #######################################
  187. ## <summary>
  188. ## Append mysqld database files.
  189. ## </summary>
  190. ## <param name="domain">
  191. ## <summary>
  192. ## Domain allowed access.
  193. ## </summary>
  194. ## </param>
  195. #
  196. interface(`mysql_append_db_files',`
  197. gen_require(`
  198. type mysqld_db_t;
  199. ')
  200. files_search_var_lib($1)
  201. append_files_pattern($1, mysqld_db_t, mysqld_db_t)
  202. ')
  203. #######################################
  204. ## <summary>
  205. ## Read and write mysqld database files.
  206. ## </summary>
  207. ## <param name="domain">
  208. ## <summary>
  209. ## Domain allowed access.
  210. ## </summary>
  211. ## </param>
  212. #
  213. interface(`mysql_rw_db_files',`
  214. gen_require(`
  215. type mysqld_db_t;
  216. ')
  217. files_search_var_lib($1)
  218. rw_files_pattern($1, mysqld_db_t, mysqld_db_t)
  219. ')
  220. #######################################
  221. ## <summary>
  222. ## Create, read, write, and delete
  223. ## mysqld database files.
  224. ## </summary>
  225. ## <param name="domain">
  226. ## <summary>
  227. ## Domain allowed access.
  228. ## </summary>
  229. ## </param>
  230. #
  231. interface(`mysql_manage_db_files',`
  232. gen_require(`
  233. type mysqld_db_t;
  234. ')
  235. files_search_var_lib($1)
  236. manage_files_pattern($1, mysqld_db_t, mysqld_db_t)
  237. ')
  238. ########################################
  239. ## <summary>
  240. ## Read and write mysqld database sockets.
  241. ## named socket.
  242. ## </summary>
  243. ## <param name="domain">
  244. ## <summary>
  245. ## Domain allowed access.
  246. ## </summary>
  247. ## </param>
  248. #
  249. interface(`mysql_rw_db_sockets',`
  250. refpolicywarn(`$0($*) has been deprecated.')
  251. ')
  252. ########################################
  253. ## <summary>
  254. ## Create, read, write, and delete
  255. ## mysqld home files.
  256. ## </summary>
  257. ## <param name="domain">
  258. ## <summary>
  259. ## Domain allowed access.
  260. ## </summary>
  261. ## </param>
  262. #
  263. interface(`mysql_manage_mysqld_home_files',`
  264. gen_require(`
  265. type mysqld_home_t;
  266. ')
  267. userdom_search_user_home_dirs($1)
  268. allow $1 mysqld_home_t:file manage_file_perms;
  269. ')
  270. ########################################
  271. ## <summary>
  272. ## Relabel mysqld home files.
  273. ## </summary>
  274. ## <param name="domain">
  275. ## <summary>
  276. ## Domain allowed access.
  277. ## </summary>
  278. ## </param>
  279. #
  280. interface(`mysql_relabel_mysqld_home_files',`
  281. gen_require(`
  282. type mysqld_home_t;
  283. ')
  284. userdom_search_user_home_dirs($1)
  285. allow $1 mysqld_home_t:file relabel_file_perms;
  286. ')
  287. ########################################
  288. ## <summary>
  289. ## Create objects in user home
  290. ## directories with the mysqld home type.
  291. ## </summary>
  292. ## <param name="domain">
  293. ## <summary>
  294. ## Domain allowed access.
  295. ## </summary>
  296. ## </param>
  297. ## <param name="object_class">
  298. ## <summary>
  299. ## Class of the object being created.
  300. ## </summary>
  301. ## </param>
  302. ## <param name="name" optional="true">
  303. ## <summary>
  304. ## The name of the object being created.
  305. ## </summary>
  306. ## </param>
  307. #
  308. interface(`mysql_home_filetrans_mysqld_home',`
  309. gen_require(`
  310. type mysqld_home_t;
  311. ')
  312. userdom_user_home_dir_filetrans($1, mysqld_home_t, $2, $3)
  313. ')
  314. ########################################
  315. ## <summary>
  316. ## Write mysqld log files.
  317. ## </summary>
  318. ## <param name="domain">
  319. ## <summary>
  320. ## Domain allowed access.
  321. ## </summary>
  322. ## </param>
  323. #
  324. interface(`mysql_write_log',`
  325. gen_require(`
  326. type mysqld_log_t;
  327. ')
  328. logging_search_logs($1)
  329. allow $1 mysqld_log_t:file write_file_perms;
  330. ')
  331. ######################################
  332. ## <summary>
  333. ## Execute mysqld safe in the
  334. ## mysqld safe domain.
  335. ## </summary>
  336. ## <param name="domain">
  337. ## <summary>
  338. ## Domain allowed to transition.
  339. ## </summary>
  340. ## </param>
  341. #
  342. interface(`mysql_domtrans_mysql_safe',`
  343. gen_require(`
  344. type mysqld_safe_t, mysqld_safe_exec_t;
  345. ')
  346. corecmd_search_bin($1)
  347. domtrans_pattern($1, mysqld_safe_exec_t, mysqld_safe_t)
  348. ')
  349. #####################################
  350. ## <summary>
  351. ## Read mysqld pid files.
  352. ## </summary>
  353. ## <param name="domain">
  354. ## <summary>
  355. ## Domain allowed access.
  356. ## </summary>
  357. ## </param>
  358. #
  359. interface(`mysql_read_pid_files',`
  360. gen_require(`
  361. type mysqld_var_run_t;
  362. ')
  363. files_search_pids($1)
  364. read_files_pattern($1, mysqld_var_run_t, mysqld_var_run_t)
  365. ')
  366. #####################################
  367. ## <summary>
  368. ## Search mysqld pid files.
  369. ## </summary>
  370. ## <param name="domain">
  371. ## <summary>
  372. ## Domain allowed access.
  373. ## </summary>
  374. ## </param>
  375. ##
  376. #
  377. interface(`mysql_search_pid_files',`
  378. gen_require(`
  379. type mysqld_var_run_t;
  380. ')
  381. files_search_pids($1)
  382. search_dirs_pattern($1, mysqld_var_run_t, mysqld_var_run_t)
  383. ')
  384. ########################################
  385. ## <summary>
  386. ## All of the rules required to
  387. ## administrate an mysqld environment.
  388. ## </summary>
  389. ## <param name="domain">
  390. ## <summary>
  391. ## Domain allowed access.
  392. ## </summary>
  393. ## </param>
  394. ## <param name="role">
  395. ## <summary>
  396. ## Role allowed access.
  397. ## </summary>
  398. ## </param>
  399. ## <rolecap/>
  400. #
  401. interface(`mysql_admin',`
  402. gen_require(`
  403. type mysqld_t, mysqld_var_run_t, mysqld_etc_t;
  404. type mysqld_tmp_t, mysqld_db_t, mysqld_log_t;
  405. type mysqld_safe_t, mysqlmanagerd_t, mysqlmanagerd_var_run_t;
  406. type mysqld_initrc_exec_t, mysqlmanagerd_initrc_exec_t, mysqld_home_t;
  407. ')
  408. allow $1 { mysqld_safe_t mysqld_t mysqlmanagerd_t }:process { ptrace signal_perms };
  409. ps_process_pattern($1, { mysqld_safe_t mysqld_t mysqlmanagerd_t })
  410. init_labeled_script_domtrans($1, { mysqlmanagerd_initrc_exec_t mysqld_initrc_exec_t })
  411. domain_system_change_exemption($1)
  412. role_transition $2 { mysqlmanagerd_initrc_exec_t mysqld_initrc_exec_t } system_r;
  413. allow $2 system_r;
  414. files_search_pids($1)
  415. admin_pattern($1, { mysqlmanagerd_var_run_t mysqld_var_run_t })
  416. files_search_var_lib($1)
  417. admin_pattern($1, mysqld_db_t)
  418. files_search_etc($1)
  419. admin_pattern($1, { mysqld_etc_t mysqld_home_t })
  420. logging_search_logs($1)
  421. admin_pattern($1, mysqld_log_t)
  422. files_search_tmp($1)
  423. admin_pattern($1, mysqld_tmp_t)
  424. mysql_run_mysqld($1, $2)
  425. ')