atop.te 3.5 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129
  1. policy_module(atop, 0.1.17)
  2. ########################################
  3. #
  4. # Declarations
  5. #
  6. attribute_role atop_roles;
  7. type atop_t;
  8. type atop_exec_t;
  9. init_daemon_domain(atop_t, atop_exec_t)
  10. role atop_roles types atop_t;
  11. type atopacct_t;
  12. type atopacct_exec_t;
  13. init_daemon_domain(atopacct_t, atopacct_exec_t)
  14. type atop_initrc_exec_t;
  15. init_script_file(atop_initrc_exec_t)
  16. type atopacct_initrc_exec_t;
  17. init_script_file(atopacct_initrc_exec_t)
  18. type atop_var_log_t;
  19. logging_log_file(atop_var_log_t)
  20. type atop_var_run_t;
  21. files_pid_file(atop_var_run_t)
  22. type atopacct_var_run_t;
  23. files_pid_file(atopacct_var_run_t)
  24. type atop_var_cache_t;
  25. files_type(atop_var_cache_t)
  26. ########################################
  27. #
  28. # Local policy
  29. #
  30. allow atop_t atop_exec_t:file execute_no_trans;
  31. allow atop_t self:capability { setuid sys_nice sys_resource ipc_lock sys_pacct dac_override net_raw sys_ptrace };
  32. allow atop_t self:process { setsched sigkill setrlimit setpgid signal };
  33. allow atop_t self:sem { write read create unix_write unix_read };
  34. allow atop_t self:udp_socket { create ioctl };
  35. allow atop_t self:sem associate;
  36. allow atop_t self:rawip_socket { create getopt };
  37. allow atop_t self:fifo_file { getattr ioctl read write };
  38. allow atop_t atopacct_t:sem { associate read unix_write write };
  39. manage_dirs_pattern(atop_t, atop_var_log_t, atop_var_log_t)
  40. append_files_pattern(atop_t, atop_var_log_t, atop_var_log_t)
  41. create_files_pattern(atop_t, atop_var_log_t, atop_var_log_t)
  42. setattr_files_pattern(atop_t, atop_var_log_t, atop_var_log_t)
  43. rw_files_pattern(atop_t, atop_var_log_t, atop_var_log_t)
  44. logging_log_filetrans(atop_t, atop_var_log_t, file)
  45. manage_dirs_pattern(atop_t, atop_var_cache_t, atop_var_cache_t)
  46. manage_files_pattern(atop_t, atop_var_cache_t, atop_var_cache_t)
  47. manage_dirs_pattern(atop_t, atop_var_run_t, atop_var_run_t)
  48. manage_files_pattern(atop_t, atop_var_run_t, atop_var_run_t)
  49. files_pid_filetrans(atop_t, atop_var_run_t, { file dir })
  50. read_files_pattern(atop_t, atopacct_var_run_t, atopacct_var_run_t)
  51. corecmd_exec_bin(atop_t)
  52. optional_policy(`
  53. gen_require(`
  54. type initrc_t;
  55. ')
  56. allow atop_t initrc_t:sem { read unix_write write associate };
  57. ')
  58. userdom_getattr_user_home_dirs(atop_t)
  59. kernel_getattr_proc(atop_t)
  60. kernel_search_proc(atop_t)
  61. kernel_list_proc(atop_t)
  62. kernel_getattr_proc_files(atop_t)
  63. kernel_read_proc_symlinks(atop_t)
  64. kernel_read_system_state(atop_t)
  65. kernel_get_sysvipc_info(atop_t)
  66. kernel_read_kernel_sysctls(atop_t)
  67. domain_read_all_domains_state(atop_t)
  68. corecmd_shell_entry_type(atop_t)
  69. kernel_read_network_state(atop_t)
  70. fs_getattr_tmpfs(atop_t)
  71. auth_use_nsswitch(atop_t)
  72. storage_getattr_fixed_disk_dev(atop_t)
  73. miscfiles_read_localization(atop_t)
  74. dev_getattr_lvm_control(atop_t)
  75. cron_system_entry(atop_t, atop_exec_t)
  76. init_read_utmp(atop_t)
  77. ### atopacct policy
  78. allow atopacct_t self:capability { net_admin sys_nice sys_pacct };
  79. allow atopacct_t self:netlink_generic_socket { bind create read setopt write };
  80. allow atopacct_t self:process { setsched signal };
  81. allow atopacct_t self:unix_dgram_socket { connect create write };
  82. allow atopacct_t self:sem { read unix_read };
  83. manage_dirs_pattern(atopacct_t, atopacct_var_run_t, atopacct_var_run_t)
  84. manage_files_pattern(atopacct_t, atopacct_var_run_t, atopacct_var_run_t)
  85. files_pid_filetrans(atopacct_t, atopacct_var_run_t, { file dir })
  86. logging_send_syslog_msg(atopacct_t)
  87. miscfiles_read_localization(atopacct_t)
  88. kernel_read_system_state(atopacct_t)
  89. fs_getattr_tmpfs(atopacct_t)
  90. optional_policy(`
  91. gen_require(`
  92. type initrc_t;
  93. ')
  94. allow atopacct_t initrc_t:sem { associate read unix_read unix_write write };
  95. ')