2 policy_module(portmap, 1.7.0)
4 ########################################
11 init_daemon_domain(portmap_t,portmap_exec_t)
13 type portmap_helper_t;
14 type portmap_helper_exec_t;
15 init_system_domain(portmap_helper_t,portmap_helper_exec_t)
16 role system_r types portmap_helper_t;
19 files_tmp_file(portmap_tmp_t)
21 type portmap_var_run_t;
22 files_pid_file(portmap_var_run_t)
24 ########################################
26 # Portmap local policy
29 allow portmap_t self:capability { setuid setgid };
30 dontaudit portmap_t self:capability sys_tty_config;
31 allow portmap_t self:netlink_route_socket r_netlink_socket_perms;
32 allow portmap_t self:unix_dgram_socket create_socket_perms;
33 allow portmap_t self:unix_stream_socket create_stream_socket_perms;
34 allow portmap_t self:tcp_socket create_stream_socket_perms;
35 allow portmap_t self:udp_socket create_socket_perms;
37 manage_dirs_pattern(portmap_t,portmap_tmp_t,portmap_tmp_t)
38 manage_files_pattern(portmap_t,portmap_tmp_t,portmap_tmp_t)
39 files_tmp_filetrans(portmap_t, portmap_tmp_t, { file dir })
41 manage_files_pattern(portmap_t,portmap_var_run_t,portmap_var_run_t)
42 files_pid_filetrans(portmap_t,portmap_var_run_t,file)
44 kernel_read_kernel_sysctls(portmap_t)
45 kernel_list_proc(portmap_t)
46 kernel_read_proc_symlinks(portmap_t)
48 corenet_all_recvfrom_unlabeled(portmap_t)
49 corenet_all_recvfrom_netlabel(portmap_t)
50 corenet_tcp_sendrecv_all_if(portmap_t)
51 corenet_udp_sendrecv_all_if(portmap_t)
52 corenet_tcp_sendrecv_all_nodes(portmap_t)
53 corenet_udp_sendrecv_all_nodes(portmap_t)
54 corenet_tcp_sendrecv_all_ports(portmap_t)
55 corenet_udp_sendrecv_all_ports(portmap_t)
56 corenet_tcp_bind_all_nodes(portmap_t)
57 corenet_udp_bind_all_nodes(portmap_t)
58 corenet_tcp_bind_portmap_port(portmap_t)
59 corenet_udp_bind_portmap_port(portmap_t)
60 corenet_tcp_connect_all_ports(portmap_t)
61 corenet_sendrecv_portmap_client_packets(portmap_t)
62 corenet_sendrecv_portmap_server_packets(portmap_t)
63 # portmap binds to arbitary ports
64 corenet_tcp_bind_generic_port(portmap_t)
65 corenet_udp_bind_generic_port(portmap_t)
66 corenet_tcp_bind_reserved_port(portmap_t)
67 corenet_udp_bind_reserved_port(portmap_t)
68 corenet_dontaudit_tcp_bind_all_reserved_ports(portmap_t)
69 corenet_dontaudit_udp_bind_all_ports(portmap_t)
71 dev_read_sysfs(portmap_t)
73 fs_getattr_all_fs(portmap_t)
74 fs_search_auto_mountpoints(portmap_t)
76 domain_use_interactive_fds(portmap_t)
78 files_read_etc_files(portmap_t)
80 libs_use_ld_so(portmap_t)
81 libs_use_shared_libs(portmap_t)
83 logging_send_syslog_msg(portmap_t)
85 miscfiles_read_localization(portmap_t)
87 sysnet_read_config(portmap_t)
89 userdom_dontaudit_use_unpriv_user_fds(portmap_t)
91 sysadm_dontaudit_search_home_dirs(portmap_t)
94 nis_use_ypbind(portmap_t)
98 nscd_socket_use(portmap_t)
102 seutil_sigchld_newrole(portmap_t)
106 udev_read_db(portmap_t)
109 ########################################
111 # Portmap helper local policy
114 dontaudit portmap_helper_t self:capability net_admin;
115 allow portmap_helper_t self:netlink_route_socket r_netlink_socket_perms;
116 allow portmap_helper_t self:tcp_socket create_stream_socket_perms;
117 allow portmap_helper_t self:udp_socket create_socket_perms;
119 allow portmap_helper_t portmap_var_run_t:file manage_file_perms;
120 files_pid_filetrans(portmap_helper_t,portmap_var_run_t,file)
122 corenet_all_recvfrom_unlabeled(portmap_helper_t)
123 corenet_all_recvfrom_netlabel(portmap_helper_t)
124 corenet_tcp_sendrecv_all_if(portmap_helper_t)
125 corenet_udp_sendrecv_all_if(portmap_helper_t)
126 corenet_raw_sendrecv_all_if(portmap_helper_t)
127 corenet_tcp_sendrecv_all_nodes(portmap_helper_t)
128 corenet_udp_sendrecv_all_nodes(portmap_helper_t)
129 corenet_raw_sendrecv_all_nodes(portmap_helper_t)
130 corenet_tcp_sendrecv_all_ports(portmap_helper_t)
131 corenet_udp_sendrecv_all_ports(portmap_helper_t)
132 corenet_tcp_bind_all_nodes(portmap_helper_t)
133 corenet_udp_bind_all_nodes(portmap_helper_t)
134 corenet_tcp_bind_reserved_port(portmap_helper_t)
135 corenet_udp_bind_reserved_port(portmap_helper_t)
136 corenet_dontaudit_tcp_bind_all_reserved_ports(portmap_helper_t)
137 corenet_dontaudit_udp_bind_all_reserved_ports(portmap_helper_t)
138 corenet_tcp_connect_all_ports(portmap_helper_t)
140 domain_dontaudit_use_interactive_fds(portmap_helper_t)
142 files_read_etc_files(portmap_helper_t)
143 files_rw_generic_pids(portmap_helper_t)
145 init_rw_utmp(portmap_helper_t)
147 libs_use_ld_so(portmap_helper_t)
148 libs_use_shared_libs(portmap_helper_t)
150 logging_send_syslog_msg(portmap_helper_t)
152 sysnet_read_config(portmap_helper_t)
154 userdom_dontaudit_use_all_users_fds(portmap_helper_t)
157 nis_use_ypbind(portmap_helper_t)