]> git.ipfire.org Git - people/stevee/selinux-policy.git/blob - policy/modules/apps/mplayer.te
320963bee4840efcf268a9f5e32b2e8ab3e9b8c0
[people/stevee/selinux-policy.git] / policy / modules / apps / mplayer.te
1 policy_module(mplayer, 2.2.1)
2
3 ########################################
4 #
5 # Declarations
6 #
7
8 ## <desc>
9 ## <p>
10 ## Allow mplayer executable stack
11 ## </p>
12 ## </desc>
13 gen_tunable(allow_mplayer_execstack, false)
14
15 type mencoder_t;
16 type mencoder_exec_t;
17 typealias mencoder_t alias { user_mencoder_t staff_mencoder_t sysadm_mencoder_t };
18 typealias mencoder_t alias { auditadm_mencoder_t secadm_mencoder_t };
19 application_domain(mencoder_t, mencoder_exec_t)
20 ubac_constrained(mencoder_t)
21
22 type mplayer_t;
23 type mplayer_exec_t;
24 typealias mplayer_t alias { user_mplayer_t staff_mplayer_t sysadm_mplayer_t };
25 typealias mplayer_t alias { auditadm_mplayer_t secadm_mplayer_t };
26 application_domain(mplayer_t, mplayer_exec_t)
27 ubac_constrained(mplayer_t)
28
29 type mplayer_etc_t;
30 files_config_file(mplayer_etc_t)
31
32 type mplayer_home_t;
33 typealias mplayer_home_t alias { user_mplayer_home_t staff_mplayer_home_t sysadm_mplayer_home_t };
34 typealias mplayer_home_t alias { auditadm_mplayer_home_t secadm_mplayer_home_t };
35 files_poly_member(mplayer_home_t)
36 userdom_user_home_content(mplayer_home_t)
37
38 type mplayer_tmpfs_t;
39 typealias mplayer_tmpfs_t alias { user_mplayer_tmpfs_t staff_mplayer_tmpfs_t sysadm_mplayer_tmpfs_t };
40 typealias mplayer_tmpfs_t alias { auditadm_mplayer_tmpfs_t secadm_mplayer_tmpfs_t };
41 files_tmpfs_file(mplayer_tmpfs_t)
42 ubac_constrained(mplayer_tmpfs_t)
43
44 ########################################
45 #
46 # mencoder local policy
47 #
48
49 manage_dirs_pattern(mencoder_t, mplayer_home_t, mplayer_home_t)
50 manage_files_pattern(mencoder_t, mplayer_home_t, mplayer_home_t)
51 manage_lnk_files_pattern(mencoder_t, mplayer_home_t, mplayer_home_t)
52
53 # Read global config
54 allow mencoder_t mplayer_etc_t:dir list_dir_perms;
55 read_files_pattern(mencoder_t, mplayer_etc_t, mplayer_etc_t)
56 read_lnk_files_pattern(mencoder_t, mplayer_etc_t, mplayer_etc_t)
57
58 # Read /proc files and directories
59 # Necessary for /proc/meminfo, /proc/cpuinfo, etc..
60 kernel_read_system_state(mencoder_t)
61 # Sysctl on kernel version
62 kernel_read_kernel_sysctls(mencoder_t)
63
64 # Required for win32 binary loader
65 dev_rwx_zero(mencoder_t)
66 # Access to DVD/CD/V4L
67 dev_read_video_dev(mencoder_t)
68
69 # Read data in /usr/share (fonts, icons..)
70 files_read_usr_files(mencoder_t)
71 files_read_usr_symlinks(mencoder_t)
72
73 fs_search_auto_mountpoints(mencoder_t)
74
75 # Access to DVD/CD/V4L
76 storage_raw_read_removable_device(mencoder_t)
77
78 miscfiles_read_localization(mencoder_t)
79
80 userdom_use_inherited_user_terminals(mencoder_t)
81 # Handle removable media, /tmp, and /home
82 userdom_list_user_tmp(mencoder_t)
83 userdom_read_user_tmp_files(mencoder_t)
84 userdom_read_user_tmp_symlinks(mencoder_t)
85 userdom_read_user_home_content_files(mencoder_t)
86 userdom_read_user_home_content_symlinks(mencoder_t)
87 userdom_home_manager(mencoder_t)
88
89 # Read content to encode
90 ifndef(`enable_mls',`
91 fs_search_removable(mencoder_t)
92 fs_read_removable_files(mencoder_t)
93 fs_read_removable_symlinks(mencoder_t)
94 ')
95
96 tunable_policy(`deny_execmem',`',`
97 allow mencoder_t self:process execmem;
98 ')
99
100 tunable_policy(`allow_execmod',`
101 dev_execmod_zero(mencoder_t)
102 ')
103
104 tunable_policy(`allow_mplayer_execstack',`
105 allow mencoder_t self:process { execmem execstack };
106 ')
107
108 ########################################
109 #
110 # mplayer local policy
111 #
112
113 allow mplayer_t self:process { signal_perms getsched };
114 allow mplayer_t self:fifo_file rw_fifo_file_perms;
115 allow mplayer_t self:sem create_sem_perms;
116 allow mplayer_t self:netlink_route_socket create_netlink_socket_perms;
117 allow mplayer_t self:tcp_socket create_socket_perms;
118 allow mplayer_t self:unix_dgram_socket sendto;
119
120 manage_dirs_pattern(mplayer_t, mplayer_home_t, mplayer_home_t)
121 manage_files_pattern(mplayer_t, mplayer_home_t, mplayer_home_t)
122 manage_lnk_files_pattern(mplayer_t, mplayer_home_t, mplayer_home_t)
123 userdom_user_home_dir_filetrans(mplayer_t, mplayer_home_t, dir)
124 userdom_search_user_home_dirs(mplayer_t)
125
126 manage_files_pattern(mplayer_t, mplayer_tmpfs_t, mplayer_tmpfs_t)
127 manage_lnk_files_pattern(mplayer_t, mplayer_tmpfs_t, mplayer_tmpfs_t)
128 manage_fifo_files_pattern(mplayer_t, mplayer_tmpfs_t, mplayer_tmpfs_t)
129 manage_sock_files_pattern(mplayer_t, mplayer_tmpfs_t, mplayer_tmpfs_t)
130 fs_tmpfs_filetrans(mplayer_t, mplayer_tmpfs_t,{ dir file lnk_file sock_file fifo_file })
131
132 # Read global config
133 allow mplayer_t mplayer_etc_t:dir list_dir_perms;
134 read_files_pattern(mplayer_t, mplayer_etc_t, mplayer_etc_t)
135 read_lnk_files_pattern(mplayer_t, mplayer_etc_t, mplayer_etc_t)
136
137 kernel_dontaudit_list_unlabeled(mplayer_t)
138 kernel_dontaudit_getattr_unlabeled_files(mplayer_t)
139 kernel_dontaudit_read_unlabeled_files(mplayer_t)
140 # Necessary for /proc/meminfo, /proc/cpuinfo, etc..
141 kernel_read_system_state(mplayer_t)
142 # Sysctl on kernel version
143 kernel_read_kernel_sysctls(mplayer_t)
144
145 corenet_all_recvfrom_netlabel(mplayer_t)
146 corenet_all_recvfrom_unlabeled(mplayer_t)
147 corenet_tcp_sendrecv_generic_if(mplayer_t)
148 corenet_tcp_sendrecv_generic_node(mplayer_t)
149 corenet_tcp_bind_generic_node(mplayer_t)
150 corenet_tcp_connect_pulseaudio_port(mplayer_t)
151 corenet_sendrecv_pulseaudio_client_packets(mplayer_t)
152
153 # Run bash/sed (??)
154 corecmd_exec_bin(mplayer_t)
155 corecmd_exec_shell(mplayer_t)
156
157 dev_read_rand(mplayer_t)
158 dev_read_urand(mplayer_t)
159 # Required for win32 binary loader
160 dev_rwx_zero(mplayer_t)
161 # Access to DVD/CD/V4L
162 dev_read_video_dev(mplayer_t)
163 dev_write_video_dev(mplayer_t)
164 # Audio, alsa.conf
165 dev_read_sound_mixer(mplayer_t)
166 dev_write_sound_mixer(mplayer_t)
167 # RTC clock
168 dev_read_realtime_clock(mplayer_t)
169
170 domain_use_interactive_fds(mplayer_t)
171
172 # Access to DVD/CD/V4L
173 storage_raw_read_removable_device(mplayer_t)
174
175 files_read_etc_files(mplayer_t)
176 files_dontaudit_list_non_security(mplayer_t)
177 files_dontaudit_getattr_non_security_files(mplayer_t)
178 files_read_non_security_files(mplayer_t)
179 # Unfortunately the ancient file dialog starts in /
180 files_list_home(mplayer_t)
181 # Read /etc/mtab
182 files_read_etc_runtime_files(mplayer_t)
183 # Read data in /usr/share (fonts, icons..)
184 files_read_usr_files(mplayer_t)
185 files_read_usr_symlinks(mplayer_t)
186
187 fs_dontaudit_getattr_all_fs(mplayer_t)
188 fs_search_auto_mountpoints(mplayer_t)
189 fs_list_inotifyfs(mplayer_t)
190
191 auth_use_nsswitch(mplayer_t)
192
193 logging_send_syslog_msg(mplayer_t)
194
195 miscfiles_read_localization(mplayer_t)
196 miscfiles_read_fonts(mplayer_t)
197
198 userdom_use_inherited_user_terminals(mplayer_t)
199 # Read media files
200 userdom_list_user_tmp(mplayer_t)
201 userdom_read_user_tmp_files(mplayer_t)
202 userdom_read_user_tmp_symlinks(mplayer_t)
203 userdom_read_user_home_content_files(mplayer_t)
204 userdom_read_user_home_content_symlinks(mplayer_t)
205 userdom_write_user_tmp_sockets(mplayer_t)
206 userdom_home_manager(mplayer_t)
207
208 xserver_user_x_domain_template(mplayer, mplayer_t, mplayer_tmpfs_t)
209
210 # Read songs
211 ifdef(`enable_mls',`',`
212 fs_search_removable(mplayer_t)
213 fs_read_removable_files(mplayer_t)
214 fs_read_removable_symlinks(mplayer_t)
215 ')
216
217 tunable_policy(`deny_execmem',`',`
218 allow mplayer_t self:process execmem;
219 ')
220
221 tunable_policy(`allow_execmod',`
222 dev_execmod_zero(mplayer_t)
223 ')
224
225 tunable_policy(`allow_mplayer_execstack',`
226 allow mplayer_t self:process { execmem execstack };
227 ')
228
229 # Legacy domain issues
230 tunable_policy(`allow_mplayer_execstack',`
231 allow mplayer_t mplayer_tmpfs_t:file execute;
232 ')
233
234 userdom_home_manager(mplayer_t)
235
236 optional_policy(`
237 alsa_read_rw_config(mplayer_t)
238 ')
239
240 optional_policy(`
241 gnome_setattr_config_dirs(mplayer_t)
242 ')
243
244 optional_policy(`
245 pulseaudio_exec(mplayer_t)
246 pulseaudio_stream_connect(mplayer_t)
247 ')