--- nsaserefpolicy/policy/modules/admin/sudo.if 2008-08-07 11:15:13.000000000 -0400 +++ serefpolicy-3.5.5/policy/modules/admin/sudo.if 2008-08-14 13:53:54.000000000 -0400 @@ -55,7 +55,7 @@ # # Use capabilities. - allow $1_sudo_t self:capability { fowner setuid setgid dac_override sys_resource }; + allow $1_sudo_t self:capability { fowner setuid setgid dac_override sys_nice sys_resource }; allow $1_sudo_t self:process ~{ ptrace setcurrent setexec setfscreate setrlimit execmem execstack execheap }; allow $1_sudo_t self:process { setexec setrlimit }; allow $1_sudo_t self:fd use; @@ -68,33 +68,35 @@ allow $1_sudo_t self:unix_stream_socket create_stream_socket_perms; allow $1_sudo_t self:unix_dgram_socket sendto; allow $1_sudo_t self:unix_stream_socket connectto; - allow $1_sudo_t self:netlink_audit_socket { create bind write nlmsg_read read }; + allow $1_sudo_t self:key manage_key_perms; + allow $1_sudo_t $1_t:key search; # Enter this derived domain from the user domain domtrans_pattern($2, sudo_exec_t, $1_sudo_t) # By default, revert to the calling domain when a shell is executed. corecmd_shell_domtrans($1_sudo_t, $2) + corecmd_bin_domtrans($1_sudo_t, $2) allow $2 $1_sudo_t:fd use; allow $2 $1_sudo_t:fifo_file rw_file_perms; allow $2 $1_sudo_t:process sigchld; kernel_read_kernel_sysctls($1_sudo_t) kernel_read_system_state($1_sudo_t) - kernel_search_key($1_sudo_t) + kernel_link_key($1_sudo_t) dev_read_urand($1_sudo_t) fs_search_auto_mountpoints($1_sudo_t) fs_getattr_xattr_fs($1_sudo_t) - auth_domtrans_chk_passwd($1_sudo_t) + auth_run_chk_passwd($1_sudo_t, $3, { $1_tty_device_t $1_devpts_t }) # sudo stores a token in the pam_pid directory auth_manage_pam_pid($1_sudo_t) auth_use_nsswitch($1_sudo_t) corecmd_read_bin_symlinks($1_sudo_t) - corecmd_getattr_all_executables($1_sudo_t) + corecmd_exec_all_executables($1_sudo_t) domain_use_interactive_fds($1_sudo_t) domain_sigchld_interactive_fds($1_sudo_t) @@ -106,32 +108,50 @@ files_getattr_usr_files($1_sudo_t) # for some PAM modules and for cwd files_dontaudit_search_home($1_sudo_t) + files_list_tmp($1_sudo_t) init_rw_utmp($1_sudo_t) libs_use_ld_so($1_sudo_t) libs_use_shared_libs($1_sudo_t) + logging_send_audit_msgs($1_sudo_t) logging_send_syslog_msg($1_sudo_t) miscfiles_read_localization($1_sudo_t) - userdom_manage_user_home_content_files($1, $1_sudo_t) - userdom_manage_user_home_content_symlinks($1, $1_sudo_t) - userdom_manage_user_tmp_files($1, $1_sudo_t) - userdom_manage_user_tmp_symlinks($1, $1_sudo_t) + mta_per_role_template($1, $1_sudo_t, $3) + + unprivuser_manage_home_content_files($1_sudo_t) + unprivuser_manage_home_content_symlinks($1_sudo_t) + tunable_policy(`use_nfs_home_dirs',` + fs_manage_nfs_files($1_sudo_t) + ') + + tunable_policy(`use_samba_home_dirs',` + fs_manage_cifs_files($1_sudo_t) + ') + unprivuser_manage_tmp_files($1_sudo_t) + unprivuser_manage_tmp_symlinks($1_sudo_t) + userdom_exec_user_home_content_files($1, $1_sudo_t) userdom_use_user_terminals($1, $1_sudo_t) userdom_use_unpriv_users_fds($1_sudo_t) # for some PAM modules and for cwd + sysadm_search_home_content_dirs($1_sudo_t) userdom_dontaudit_search_all_users_home_content($1_sudo_t) + userdom_manage_all_users_keys($1_sudo_t) - ifdef(`TODO',` - # for when the network connection is killed - dontaudit unpriv_userdomain $1_sudo_t:process signal; - - ifdef(`mta.te', ` - domain_auto_trans($1_sudo_t, sendmail_exec_t, $1_mail_t) - ') + domain_role_change_exemption($1_sudo_t) + userdom_spec_domtrans_all_users($1_sudo_t) - ') dnl end TODO + selinux_validate_context($1_sudo_t) + selinux_compute_relabel_context($1_sudo_t) + selinux_getattr_fs($1_sudo_t) + seutil_read_config($1_sudo_t) + seutil_search_default_contexts($1_sudo_t) + + term_use_all_user_ttys($1_sudo_t) + term_use_all_user_ptys($1_sudo_t) + term_relabel_all_user_ttys($1_sudo_t) + term_relabel_all_user_ptys($1_sudo_t) ')