1 policy_module(mplayer, 2.2.1)
3 ########################################
10 ## Allow mplayer executable stack
13 gen_tunable(allow_mplayer_execstack, false)
17 typealias mencoder_t alias { user_mencoder_t staff_mencoder_t sysadm_mencoder_t };
18 typealias mencoder_t alias { auditadm_mencoder_t secadm_mencoder_t };
19 application_domain(mencoder_t, mencoder_exec_t)
20 ubac_constrained(mencoder_t)
24 typealias mplayer_t alias { user_mplayer_t staff_mplayer_t sysadm_mplayer_t };
25 typealias mplayer_t alias { auditadm_mplayer_t secadm_mplayer_t };
26 application_domain(mplayer_t, mplayer_exec_t)
27 ubac_constrained(mplayer_t)
30 files_config_file(mplayer_etc_t)
33 typealias mplayer_home_t alias { user_mplayer_home_t staff_mplayer_home_t sysadm_mplayer_home_t };
34 typealias mplayer_home_t alias { auditadm_mplayer_home_t secadm_mplayer_home_t };
35 files_poly_member(mplayer_home_t)
36 userdom_user_home_content(mplayer_home_t)
39 typealias mplayer_tmpfs_t alias { user_mplayer_tmpfs_t staff_mplayer_tmpfs_t sysadm_mplayer_tmpfs_t };
40 typealias mplayer_tmpfs_t alias { auditadm_mplayer_tmpfs_t secadm_mplayer_tmpfs_t };
41 files_tmpfs_file(mplayer_tmpfs_t)
42 ubac_constrained(mplayer_tmpfs_t)
44 ########################################
46 # mencoder local policy
49 manage_dirs_pattern(mencoder_t, mplayer_home_t, mplayer_home_t)
50 manage_files_pattern(mencoder_t, mplayer_home_t, mplayer_home_t)
51 manage_lnk_files_pattern(mencoder_t, mplayer_home_t, mplayer_home_t)
54 allow mencoder_t mplayer_etc_t:dir list_dir_perms;
55 read_files_pattern(mencoder_t, mplayer_etc_t, mplayer_etc_t)
56 read_lnk_files_pattern(mencoder_t, mplayer_etc_t, mplayer_etc_t)
58 # Read /proc files and directories
59 # Necessary for /proc/meminfo, /proc/cpuinfo, etc..
60 kernel_read_system_state(mencoder_t)
61 # Sysctl on kernel version
62 kernel_read_kernel_sysctls(mencoder_t)
64 # Required for win32 binary loader
65 dev_rwx_zero(mencoder_t)
66 # Access to DVD/CD/V4L
67 dev_read_video_dev(mencoder_t)
69 # Read data in /usr/share (fonts, icons..)
70 files_read_usr_files(mencoder_t)
71 files_read_usr_symlinks(mencoder_t)
73 fs_search_auto_mountpoints(mencoder_t)
75 # Access to DVD/CD/V4L
76 storage_raw_read_removable_device(mencoder_t)
78 miscfiles_read_localization(mencoder_t)
80 userdom_use_inherited_user_terminals(mencoder_t)
81 # Handle removable media, /tmp, and /home
82 userdom_list_user_tmp(mencoder_t)
83 userdom_read_user_tmp_files(mencoder_t)
84 userdom_read_user_tmp_symlinks(mencoder_t)
85 userdom_read_user_home_content_files(mencoder_t)
86 userdom_read_user_home_content_symlinks(mencoder_t)
87 userdom_home_manager(mencoder_t)
89 # Read content to encode
91 fs_search_removable(mencoder_t)
92 fs_read_removable_files(mencoder_t)
93 fs_read_removable_symlinks(mencoder_t)
96 tunable_policy(`deny_execmem',`',`
97 allow mencoder_t self:process execmem;
100 tunable_policy(`allow_execmod',`
101 dev_execmod_zero(mencoder_t)
104 tunable_policy(`allow_mplayer_execstack',`
105 allow mencoder_t self:process { execmem execstack };
108 ########################################
110 # mplayer local policy
113 allow mplayer_t self:process { signal_perms getsched };
114 allow mplayer_t self:fifo_file rw_fifo_file_perms;
115 allow mplayer_t self:sem create_sem_perms;
116 allow mplayer_t self:netlink_route_socket create_netlink_socket_perms;
117 allow mplayer_t self:tcp_socket create_socket_perms;
118 allow mplayer_t self:unix_dgram_socket sendto;
120 manage_dirs_pattern(mplayer_t, mplayer_home_t, mplayer_home_t)
121 manage_files_pattern(mplayer_t, mplayer_home_t, mplayer_home_t)
122 manage_lnk_files_pattern(mplayer_t, mplayer_home_t, mplayer_home_t)
123 userdom_user_home_dir_filetrans(mplayer_t, mplayer_home_t, dir)
124 userdom_search_user_home_dirs(mplayer_t)
126 manage_files_pattern(mplayer_t, mplayer_tmpfs_t, mplayer_tmpfs_t)
127 manage_lnk_files_pattern(mplayer_t, mplayer_tmpfs_t, mplayer_tmpfs_t)
128 manage_fifo_files_pattern(mplayer_t, mplayer_tmpfs_t, mplayer_tmpfs_t)
129 manage_sock_files_pattern(mplayer_t, mplayer_tmpfs_t, mplayer_tmpfs_t)
130 fs_tmpfs_filetrans(mplayer_t, mplayer_tmpfs_t,{ dir file lnk_file sock_file fifo_file })
133 allow mplayer_t mplayer_etc_t:dir list_dir_perms;
134 read_files_pattern(mplayer_t, mplayer_etc_t, mplayer_etc_t)
135 read_lnk_files_pattern(mplayer_t, mplayer_etc_t, mplayer_etc_t)
137 kernel_dontaudit_list_unlabeled(mplayer_t)
138 kernel_dontaudit_getattr_unlabeled_files(mplayer_t)
139 kernel_dontaudit_read_unlabeled_files(mplayer_t)
140 # Necessary for /proc/meminfo, /proc/cpuinfo, etc..
141 kernel_read_system_state(mplayer_t)
142 # Sysctl on kernel version
143 kernel_read_kernel_sysctls(mplayer_t)
145 corenet_all_recvfrom_netlabel(mplayer_t)
146 corenet_all_recvfrom_unlabeled(mplayer_t)
147 corenet_tcp_sendrecv_generic_if(mplayer_t)
148 corenet_tcp_sendrecv_generic_node(mplayer_t)
149 corenet_tcp_bind_generic_node(mplayer_t)
150 corenet_tcp_connect_pulseaudio_port(mplayer_t)
151 corenet_sendrecv_pulseaudio_client_packets(mplayer_t)
154 corecmd_exec_bin(mplayer_t)
155 corecmd_exec_shell(mplayer_t)
157 dev_read_rand(mplayer_t)
158 dev_read_urand(mplayer_t)
159 # Required for win32 binary loader
160 dev_rwx_zero(mplayer_t)
161 # Access to DVD/CD/V4L
162 dev_read_video_dev(mplayer_t)
163 dev_write_video_dev(mplayer_t)
165 dev_read_sound_mixer(mplayer_t)
166 dev_write_sound_mixer(mplayer_t)
168 dev_read_realtime_clock(mplayer_t)
170 domain_use_interactive_fds(mplayer_t)
172 # Access to DVD/CD/V4L
173 storage_raw_read_removable_device(mplayer_t)
175 files_read_etc_files(mplayer_t)
176 files_dontaudit_list_non_security(mplayer_t)
177 files_dontaudit_getattr_non_security_files(mplayer_t)
178 files_read_non_security_files(mplayer_t)
179 # Unfortunately the ancient file dialog starts in /
180 files_list_home(mplayer_t)
182 files_read_etc_runtime_files(mplayer_t)
183 # Read data in /usr/share (fonts, icons..)
184 files_read_usr_files(mplayer_t)
185 files_read_usr_symlinks(mplayer_t)
187 fs_dontaudit_getattr_all_fs(mplayer_t)
188 fs_search_auto_mountpoints(mplayer_t)
189 fs_list_inotifyfs(mplayer_t)
191 auth_use_nsswitch(mplayer_t)
193 logging_send_syslog_msg(mplayer_t)
195 miscfiles_read_localization(mplayer_t)
196 miscfiles_read_fonts(mplayer_t)
198 userdom_use_inherited_user_terminals(mplayer_t)
200 userdom_list_user_tmp(mplayer_t)
201 userdom_read_user_tmp_files(mplayer_t)
202 userdom_read_user_tmp_symlinks(mplayer_t)
203 userdom_read_user_home_content_files(mplayer_t)
204 userdom_read_user_home_content_symlinks(mplayer_t)
205 userdom_write_user_tmp_sockets(mplayer_t)
206 userdom_home_manager(mplayer_t)
208 xserver_user_x_domain_template(mplayer, mplayer_t, mplayer_tmpfs_t)
211 ifdef(`enable_mls',`',`
212 fs_search_removable(mplayer_t)
213 fs_read_removable_files(mplayer_t)
214 fs_read_removable_symlinks(mplayer_t)
217 tunable_policy(`deny_execmem',`',`
218 allow mplayer_t self:process execmem;
221 tunable_policy(`allow_execmod',`
222 dev_execmod_zero(mplayer_t)
225 tunable_policy(`allow_mplayer_execstack',`
226 allow mplayer_t self:process { execmem execstack };
229 # Legacy domain issues
230 tunable_policy(`allow_mplayer_execstack',`
231 allow mplayer_t mplayer_tmpfs_t:file execute;
234 userdom_home_manager(mplayer_t)
237 alsa_read_rw_config(mplayer_t)
241 gnome_setattr_config_dirs(mplayer_t)
245 pulseaudio_exec(mplayer_t)
246 pulseaudio_stream_connect(mplayer_t)