# Overview

This notebook provides a core set of analysis on a policy, primary focused on least-privilege and system self-protection. This is geared towards systems that have a customized SELinux policy based upon reference policy (and usually a RHEL or Fedora derivative).

To use this notebook you should:

   * Replace the policies loaded with the system policies that you are interested in.
   * Run each analysis and examine the output - this notebook doesn't give you yes/no answers. It requires interpretation.
   
# Getting the Policies

To use these notebook you need the source and binary versions of two policies: the system and base policy. Base policy, here, meaning the policy that the system developers started with. This is typically the policy from the version of RHEL or Fedora that the system is based upon.

System developers typically either add policy modules, directly modify the base policy, or both. Regardless of the approach, it's nice to have the base policy in both source and binary form.

Getting the source and binary policies for the system is dependent on how the system is developed.

The easiest way to get the source for the base policy is to start with the source for selinux-policy. You can grab those from:

   * http://vault.centos.org/
   * http://archives.fedoraproject.org/pub/archive/fedora/linux/updates/
   
Once you have the source rpm, you need to at least partially build it so that all of the patches are applied. First setup your system to build rpms - there is some info at https://wiki.centos.org/HowTos/RebuildSRPM. From there, just rpmbuild -bp will output the patched source to ~/rpmbuild/BUILD.

You can also build the binary policy this way, but it's actually kind of pain. It's easier to just grab the rpm and extract it with:

`rpm2cpio selinux-policy-targeted-3.13.1-190.fc24.noarch.rpm | cpio -idmv`

After you have done this, the policy should be under etc/selinux/targeted/policy/policy.30 (or similar) in the current directory.

Once you've collected the policies, simply save the source and binaries under the same directory with this notebook.

## Import and load the policies

You should change policy_paths.config to match the policies that you want to analyze.

As an example for this notebook, we are going to use a Fedora 25 policy as the system policy and a Fedora 24 policy as the base policy.

In [1]:
# Import senotebook - this complication is just to handle running this in the development tree
try:
    import span as se
except:
    import os
    path = os.path.dirname(os.getcwd())
    import sys
    sys.path.insert(0, path)
    import span as se

import pandas as pd
from IPython.display import display, HTML

# P - binary system policy
# ps - source system policy
# bp - binary base policy
# bps - source base policy
p, ps, bp, bps = se.load_policies_from_config("policy_paths.config")

# Basic Policy Summary

## Numer of Types

In [2]:
p_types = set(se.as_str(p.types()))
print("total types in custom policy: %d" % len(p_types))

p_domains = p.domain_types()
print("total number of domain types: %d" % len(p_domains))

total types in custom policy: 4792
total number of domain types: 820


## Custom Types

This is a quick way to figure out the _potentially_ custom types. It's only potentially, because it's possible that the base policy may have backported policy modules from newer policies and included them. So types not in the base policy would be present but not really custom to the system being analyzed.

Having said that, this approach is typically a good first approximation.

In [3]:
custom_types, custom_domains = p.new_types(bp)

print("total number of potentially custom types: %d" % len(custom_types))
print("total number of potentially custom domains: %d" % len(custom_domains))

total number of potentially custom types: 34
total number of potentially custom domains: 5


In [4]:
p.types_summary(custom_domains)

Unnamed: 0,name,attributes
0,container_t,"[corenet_unlabeled_type, domain, kernel_system_state_reader, mcs_constrained_type, netlabel_peer_type, nsswitch_domain, pcmcia_typeattr_1, pcmcia_typeattr_2, pcmcia_typeattr_3, pcmcia_typeattr_4, pcmcia_typeattr_5, pcmcia_typeattr_6, pcmcia_typeattr_7, process_user_target, sandbox_caps_domain, sandbox_net_domain, svirt_sandbox_domain, syslog_client_type]"
1,hwloc_dhwd_t,"[application_domain_type, corenet_unlabeled_type, domain, pcmcia_typeattr_1, pcmcia_typeattr_2, pcmcia_typeattr_3, pcmcia_typeattr_4, pcmcia_typeattr_5, pcmcia_typeattr_6, pcmcia_typeattr_7, systemprocess]"
2,ipa_ods_exporter_t,"[corenet_unlabeled_type, daemon, domain, ipa_domain, netlabel_peer_type, nsswitch_domain, pcmcia_typeattr_1, pcmcia_typeattr_2, pcmcia_typeattr_3, pcmcia_typeattr_4, pcmcia_typeattr_5, pcmcia_typeattr_6, pcmcia_typeattr_7, syslog_client_type]"
3,sbd_t,"[corenet_unlabeled_type, daemon, domain, kernel_system_state_reader, pcmcia_typeattr_1, pcmcia_typeattr_2, pcmcia_typeattr_3, pcmcia_typeattr_4, pcmcia_typeattr_5, pcmcia_typeattr_6, pcmcia_typeattr_7, syslog_client_type]"
4,systemd_modules_load_t,"[can_load_kernmodule, corenet_unlabeled_type, daemon, domain, kernel_system_state_reader, netlabel_peer_type, nsswitch_domain, pcmcia_typeattr_1, pcmcia_typeattr_2, pcmcia_typeattr_3, pcmcia_typeattr_4, pcmcia_typeattr_5, pcmcia_typeattr_6, pcmcia_typeattr_7, systemd_domain]"


In [5]:
p.types_summary(custom_types)

Unnamed: 0,name,attributes
0,brltty_log_t,"[file_type, logfile, non_auth_file_type, non_security_file_type, sandbox_typeattr_1, sandbox_typeattr_2, sandbox_typeattr_3, sandbox_typeattr_4]"
1,container_file_t,"[device_node, file_type, filesystem_type, mountpoint, non_auth_file_type, non_security_file_type, noxattrfs, ptynode, sandbox_typeattr_1, sandbox_typeattr_2, sandbox_typeattr_3, sandbox_typeattr_4, svirt_file_type]"
2,container_ro_file_t,"[file_type, mountpoint, non_auth_file_type, non_security_file_type, sandbox_typeattr_1, sandbox_typeattr_2, sandbox_typeattr_3, sandbox_typeattr_4, svirt_file_type]"
3,container_t,"[corenet_unlabeled_type, domain, kernel_system_state_reader, mcs_constrained_type, netlabel_peer_type, nsswitch_domain, pcmcia_typeattr_1, pcmcia_typeattr_2, pcmcia_typeattr_3, pcmcia_typeattr_4, pcmcia_typeattr_5, pcmcia_typeattr_6, pcmcia_typeattr_7, process_user_target, sandbox_caps_domain, sandbox_net_domain, svirt_sandbox_domain, syslog_client_type]"
4,fac_restore_client_packet_t,"[client_packet_type, packet_type]"
5,fac_restore_port_t,"[defined_port_type, port_type, unreserved_port_type]"
6,fac_restore_server_packet_t,"[packet_type, server_packet_type]"
7,hsa_device_t,[device_node]
8,hwloc_dhwd_exec_t,"[application_exec_type, entry_type, exec_type, file_type, non_auth_file_type, non_security_file_type, systemprocess_entry]"
9,hwloc_dhwd_t,"[application_domain_type, corenet_unlabeled_type, domain, pcmcia_typeattr_1, pcmcia_typeattr_2, pcmcia_typeattr_3, pcmcia_typeattr_4, pcmcia_typeattr_5, pcmcia_typeattr_6, pcmcia_typeattr_7, systemprocess]"


## Initial SIDs
This is the list of initial security identifiers for object classes present in this policy.

In [6]:
def initsids_as_dataframe(p):
    initsids = [{ "name": str(x), "context": str(x.context)} for x in p.initialsids()]
    return pd.DataFrame(initsids)[["name", "context"]]
    
initsids_as_dataframe(p)

Unnamed: 0,name,context
0,kernel,system_u:system_r:kernel_t:s0
1,security,system_u:object_r:security_t:s0
2,unlabeled,system_u:object_r:unlabeled_t:s0
3,fs,system_u:object_r:fs_t:s0
4,file,system_u:object_r:unlabeled_t:s0
5,file_labels,system_u:object_r:unlabeled_t:s0
6,init,system_u:object_r:unlabeled_t:s0
7,any_socket,system_u:object_r:unlabeled_t:s0
8,port,system_u:object_r:port_t:s0
9,netif,system_u:object_r:netif_t:s0


In [7]:
p_initsids = {str(x): str(x.context) for x in p.initialsids()}
b_initsids = {str(x): str(x.context) for x in bp.initialsids()}

Any new or missing initial sids?

In [8]:
new_initsids = set(p_initsids.keys()) - set(b_initsids.keys())
print("new initial sids: " + str(new_initsids))

missing_initsids = set(b_initsids.keys()) - set(p_initsids.keys())
print("missing initial sids: " + str(missing_initsids))

new initial sids: set()
missing initial sids: set()


Changed labels?

In [9]:
changed_initsids = []
for i in p_initsids.keys():
    if not i in b_initsids:
        changed_initsids.append({"name": i, "system": p_initsids[i], "base": "NOT PRESENT"})
        continue
    if p_initsids[i] != b_initsids[i]:
        changed_initsids.append({"name": i, "system": p_initsids[i], "base": b_initsids[i]})
        
if len(changed_initsids) > 0:
    display(pd.DataFrame(changed_initsids)[["name", "system", "base"]])
else:
    print("No changed initial sid labels")


No changed initial sid labels


## Object Classes
This is the list of new object classes, both kernel and userspace, present in the policy.

In [10]:
se.as_strset(p.classes()) - se.as_strset(bp.classes())

{'cap2_userns', 'cap_userns'}

New permissions or missing permissions:

In [11]:
# We are going to do commons separately becase they can be named the same as
# object classes
p_commons = {str(x): se.as_strset(x.perms) for x in p.commons()}
p_classes = {str(x): se.as_strset(x.perms) for x in p.classes()}
b_commons = {str(x): se.as_strset(x.perms) for x in bp.commons()}
b_classes = {str(x): se.as_strset(x.perms) for x in bp.classes()}

print("new commons: " + str(set(p_commons.keys()) - set(b_commons.keys())))
print("new object classes: " + str(set(p_classes.keys()) - set(b_classes.keys())))
print("removed object classes: " + str(set(b_classes.keys()) - set(p_classes.keys())))
print("removed commons: " + str(set(b_commons.keys()) - set(p_commons.keys())))


new commons: {'cap', 'cap2'}
new object classes: {'cap_userns', 'cap2_userns'}
removed object classes: set()
removed commons: set()


Changed permissions:

In [12]:
def find_object_changes(name, pc, bc):
    cc = []
    for c in pc:
        if not c in bc:
            cc.append({"name": c, "added": str(pc[c]), "removed": "New Class"})
            continue
        added = pc[c] - bc[c]
        removed = bc[c] - pc[c]

        if len(added) or len(removed):
            cc.append({"name": c, "added": str(added), "removed": str(removed)})

    if len(cc) > 0:
        print("Changed %s permissions:" % name)
        display(pd.DataFrame(cc)[["name", "added", "removed"]])
    else:
        print("No changed %s permissions." % name)
        
find_object_changes("common", p_commons, b_commons)
find_object_changes("object class", p_classes, b_classes)
    

Changed common permissions:


Unnamed: 0,name,added,removed
0,cap,"{'linux_immutable', 'sys_chroot', 'sys_module', 'lease', 'sys_ptrace', 'net_bind_service', 'net_broadcast', 'sys_pacct', 'audit_write', 'dac_override', 'ipc_lock', 'chown', 'kill', 'setpcap', 'fsetid', 'setgid', 'sys_rawio', 'net_raw', 'sys_nice', 'dac_read_search', 'setfcap', 'sys_time', 'audit_control', 'sys_boot', 'net_admin', 'fowner', 'setuid', 'sys_admin', 'sys_tty_config', 'sys_resource', 'ipc_owner', 'mknod'}",New Class
1,cap2,"{'audit_read', 'mac_admin', 'block_suspend', 'wake_alarm', 'mac_override', 'syslog'}",New Class


Changed object class permissions:


Unnamed: 0,name,added,removed
0,process,set(),{'ptrace_child'}
1,capability2,set(),"{'audit_read', 'mac_admin', 'mac_override', 'compromise_kernel', 'block_suspend', 'wake_alarm', 'syslog'}"
2,cap_userns,set(),New Class
3,capability,set(),"{'sys_chroot', 'sys_ptrace', 'net_bind_service', 'sys_pacct', 'audit_write', 'dac_override', 'kill', 'sys_rawio', 'net_raw', 'sys_nice', 'dac_read_search', 'setfcap', 'sys_time', 'audit_control', 'sys_boot', 'net_admin', 'fowner', 'sys_resource', 'linux_immutable', 'sys_module', 'lease', 'net_broadcast', 'ipc_lock', 'chown', 'setpcap', 'fsetid', 'setgid', 'setuid', 'sys_admin', 'sys_tty_config', 'ipc_owner', 'mknod'}"
4,cap2_userns,set(),New Class
5,system,"{'stop', 'start'}",set()


## Constraints
Since analysis tools do not address constraints in a meaningful way, here is a raw dump of the constraints for reference.

In [13]:
HTML(ps.diff_mls_constraints(bps))

In [14]:
HTML(ps.diff_mcs_constraints(bps))

In [15]:
HTML(ps.diff_constraints(bps))

## Policy Caps

Policy capabilities control how policy enforcement is done on a system and is used to control optional features and backwards compatibility. Some documentation can be found at https://selinuxproject.org/page/Policy_Configuration_Statements.

In [16]:
se.as_str(p.polcaps())

['network_peer_controls', 'open_perms']

Changed policy capabilities:

In [17]:
se.as_strset(p.polcaps()) ^ se.as_strset(bp.polcaps())

set()

# System Self Protection Analysis

Analyses of access that can compromise the ability of the system to protect itself from malicious processes.

## Write Rules - boot_t
Files labeled boot_t include files for bootstrapping the system, including the critical kernel image and initial ramdisk image. Domains that can modify these files can completely compromise a system by replacing the kernel or initrd.

In [18]:
print(ps.file_contexts("boot_t"))

./kernel/files.fc:9:/initrd\.img.*		-l	gen_context(system_u:object_r:boot_t,s0)
./kernel/files.fc:10:/vmlinuz.*		-l	gen_context(system_u:object_r:boot_t,s0)
./kernel/files.fc:31:/boot				gen_context(system_u:object_r:boot_t,s0)
./kernel/files.fc:32:/boot/.*			gen_context(system_u:object_r:boot_t,s0)



In [19]:
p.object_info_flow(object_type="boot_t", direction="w")

Unnamed: 0,type,conditional,perms
0,abrt_dump_oops_t,,"{setattr, rename, read, lock, open, link, append, unlink, ioctl, write, getattr, create}"
1,amtu_t,,"{setattr, create, rename, unlink, read, lock, ioctl, write, open, link, getattr, append}"
2,bootloader_t,,"{setattr, rename, read, lock, open, link, append, unlink, ioctl, write, getattr, create}"
3,files_unconfined_type,,"{setattr, mounton, open, link, audit_access, execmod, unlink, quotaon, write, getattr, relabelto, rename, execute_no_trans, read, lock, relabelfrom, swapon, append, ioctl, create, execute}"
4,initrc_t,,"{setattr, rename, read, lock, open, link, append, unlink, ioctl, write, getattr, create}"
5,kdumpctl_t,,"{setattr, rename, read, lock, open, link, append, unlink, ioctl, write, getattr, create}"
6,kdumpgui_t,,"{setattr, rename, read, lock, open, link, append, unlink, ioctl, write, getattr, create}"
7,pegasus_openlmi_logicalfile_t,,"{setattr, rename, read, lock, open, link, append, unlink, ioctl, write, getattr, create}"
8,restorecond_t,,"{read, lock, relabelfrom, ioctl, open, getattr, relabelto}"
9,rpm_script_t,,"{setattr, rename, read, lock, relabelfrom, open, link, append, create, unlink, write, ioctl, getattr, relabelto}"


## Read Rules - system_map_t
Files labeled system_map_t contain the kernel symbol table which can be used to lookup the address of symbols in the kernel to aid in exploitation of the system. 

In [20]:
print(ps.file_contexts("system_map_t"))

./kernel/files.fc:34:/boot/efi(/.*)?/System\.map(-.*)? -- gen_context(system_u:object_r:system_map_t,s0)
./kernel/files.fc:37:/boot/System\.map(-.*)?	--	gen_context(system_u:object_r:system_map_t,s0)



In [21]:
p.object_info_flow(object_type="system_map_t", direction="r")

Unnamed: 0,type,conditional,perms
0,abrt_dump_oops_t,,"{setattr, rename, read, lock, open, link, append, unlink, ioctl, write, getattr, create}"
1,abrt_t,,"{read, lock, ioctl, open, getattr}"
2,aide_t,,"{read, lock, ioctl, open, getattr}"
3,amanda_t,,"{read, lock, ioctl, open, getattr}"
4,bacula_t,,"{read, lock, ioctl, open, getattr}"
5,bootloader_t,,"{read, lock, ioctl, open, getattr}"
6,cgred_t,,"{getattr, read}"
7,cluster_t,,"{read, lock, ioctl, open, getattr}"
8,collectd_t,,"{read, lock, ioctl, open, getattr}"
9,container_t,,"{read, lock, ioctl, open, getattr}"


## Write Rules - modules_object_t
modules_object_t is the label placed on kernel modules. Files with this label contain kernel code that, depending on other aspects of system configuration, can be automatically loaded into the kernel as needed. Domains that can write to these files can compromise the integrity of the system.

In [22]:
p.object_info_flow(object_type="modules_object_t", direction="w", tclass=["file", "dir"])

Unnamed: 0,type,conditional,perms
0,abrt_dump_oops_t,,"{setattr, reparent, search, open, link, unlink, rmdir, write, getattr, rename, read, lock, append, add_name, remove_name, ioctl, create}"
1,automount_t,,"{setattr, add_name, rename, unlink, remove_name, read, reparent, search, lock, rmdir, ioctl, write, open, link, getattr, create}"
2,bootloader_t,,"{setattr, rename, read, search, lock, open, link, append, add_name, unlink, remove_name, ioctl, write, getattr, create}"
3,depmod_t,,"{add_name, remove_name, read, search, lock, ioctl, write, open, getattr}"
4,files_unconfined_type,,"{setattr, mounton, reparent, search, open, link, audit_access, execmod, unlink, quotaon, rmdir, write, getattr, relabelto, rename, execute_no_trans, read, lock, relabelfrom, swapon, append, add_name, remove_name, ioctl, create, execute}"
5,glusterd_t,,"{setattr, write, mounton}"
6,insmod_t,,"{setattr, rename, read, search, lock, open, link, append, add_name, unlink, remove_name, ioctl, write, getattr, create}"
7,neutron_t,,"{setattr, write, mounton}"
8,pegasus_openlmi_logicalfile_t,,"{setattr, reparent, search, open, link, unlink, rmdir, write, getattr, rename, read, lock, append, add_name, remove_name, ioctl, create}"
9,prelink_t,,{write}


## Read/Write Rules - memory_device_t
Files labeled memory_device_t provide access to the raw physical memory of the solution. As such, reading from these files can compromise the confidentiality of the solution. Writing to these files can compromise the integrity of the solution.

In [23]:
p.terules_query(target="memory_device_t", perms=["read"], tclass=["chr_file"])

Unnamed: 0,source,target,tclass,perms,cond
0,abrt_t,memory_device_t,chr_file,"{read, lock, ioctl, open, getattr}",
1,colord_t,memory_device_t,chr_file,"{read, lock, ioctl, write, open, getattr, append}",
2,devices_unconfined_type,device_node,chr_file,"{setattr, append, rename, unlink, quotaon, mounton, execute_no_trans, read, open, audit_access, lock, relabelfrom, ioctl, write, execute, link, getattr, swapon, create, relabelto}",
3,dmesg_t,memory_device_t,chr_file,"{read, lock, ioctl, open, getattr}",
4,dmidecode_t,memory_device_t,chr_file,"{read, lock, ioctl, open, getattr}",
5,freeipmi_bmc_watchdog_t,memory_device_t,chr_file,"{read, lock, ioctl, open, getattr}",
6,freeipmi_ipmiseld_t,memory_device_t,chr_file,"{read, lock, ioctl, open, getattr}",
7,init_t,memory_device_t,chr_file,"{read, lock, ioctl, open, getattr}",
8,initrc_t,memory_device_t,chr_file,"{read, lock, ioctl, write, open, getattr, append, execute}",
9,kdumpctl_t,device_node,chr_file,"{setattr, append, rename, unlink, read, open, lock, relabelfrom, ioctl, write, link, getattr, create, relabelto}",


In [24]:
p.terules_query(target="memory_device_t", perms=["write", "append"], tclass=["chr_file"])

Unnamed: 0,source,target,tclass,perms,cond
0,colord_t,memory_device_t,chr_file,"{read, lock, ioctl, write, open, getattr, append}",
1,devices_unconfined_type,device_node,chr_file,"{setattr, append, rename, unlink, quotaon, mounton, execute_no_trans, read, open, audit_access, lock, relabelfrom, ioctl, write, execute, link, getattr, swapon, create, relabelto}",
2,initrc_t,memory_device_t,chr_file,"{read, lock, ioctl, write, open, getattr, append, execute}",
3,kdumpctl_t,device_node,chr_file,"{setattr, append, rename, unlink, read, open, lock, relabelfrom, ioctl, write, link, getattr, create, relabelto}",
4,rpm_script_t,device_node,chr_file,"{setattr, append, rename, unlink, read, open, lock, ioctl, write, link, getattr, create}",
5,rpm_t,device_node,chr_file,"{setattr, append, rename, unlink, read, open, lock, relabelfrom, ioctl, write, link, getattr, create, relabelto}",
6,rtas_errd_t,memory_device_t,chr_file,"{read, lock, ioctl, write, open, getattr, append}",
7,sandbox_domain,device_node,chr_file,"{read, lock, ioctl, write, getattr, append}",
8,systemd_tmpfiles_t,device_node,chr_file,"{setattr, append, rename, unlink, read, open, lock, relabelfrom, ioctl, write, link, getattr, create, relabelto}",
9,udev_t,device_node,chr_file,"{setattr, append, rename, unlink, read, open, lock, relabelfrom, ioctl, write, link, getattr, create, relabelto}",


## Read/Write Rules - proc_kcore_t
Similar to files labeled proc_kcore_t provide access to the virtual memory of the solution. As such, reading from these files can compromise the confidentiality of the solution. Writing to these files can compromise the integrity of the solution.

In [25]:
print(ps.genfscon("proc"))

./kernel/devices.te:204:genfscon proc /mtrr gen_context(system_u:object_r:mtrr_device_t,s0)
./kernel/files.te:156:genfscon proc /kallsyms gen_context(system_u:object_r:system_map_t,s0)
./kernel/kernel.te:85:genfscon proc / gen_context(system_u:object_r:proc_t,s0)
./kernel/kernel.te:86:genfscon proc /sysvipc gen_context(system_u:object_r:proc_t,s0)
./kernel/kernel.te:89:genfscon proc /fs/openafs gen_context(system_u:object_r:proc_afs_t,s0)
./kernel/kernel.te:93:genfscon proc /kmsg gen_context(system_u:object_r:proc_kmsg_t,mls_systemhigh)
./kernel/kernel.te:99:genfscon proc /kcore gen_context(system_u:object_r:proc_kcore_t,mls_systemhigh)
./kernel/kernel.te:102:genfscon proc /mdstat gen_context(system_u:object_r:proc_mdstat_t,s0)
./kernel/kernel.te:105:genfscon proc /numatools gen_context(system_u:object_r:proc_numa_t,s0)
./kernel/kernel.te:109:genfscon proc /net gen_context(system_u:object_r:proc_net_t,s0)
./kernel/kernel.te:112:genfscon proc /sys/fs/protected_hardlinks gen_context(syst

In [26]:
p.terules_query(target="proc_kcore_t", perms=["read"], tclass=["file"])

Unnamed: 0,source,target,tclass,perms,cond
0,abrt_t,proc_type,file,"{read, lock, ioctl, open, getattr}",
1,collectd_t,proc_type,file,"{read, lock, ioctl, open, getattr}",
2,container_t,proc_type,file,"{read, lock, ioctl, open, getattr}",
3,gpg_agent_t,proc_kcore_t,file,"{read, lock, ioctl, open, getattr}",
4,kdump_t,proc_kcore_t,file,"{read, lock, ioctl, open, getattr}",
5,kern_unconfined,proc_type,file,"{setattr, mounton, open, link, audit_access, execmod, unlink, quotaon, write, getattr, relabelto, rename, execute_no_trans, read, lock, relabelfrom, swapon, append, ioctl, create, execute}",
6,snmpd_t,proc_type,file,"{read, lock, ioctl, open, getattr}",
7,svirt_kvm_net_t,proc_type,file,"{read, lock, ioctl, open, getattr}",
8,svirt_qemu_net_t,proc_type,file,"{read, lock, ioctl, open, getattr}",
9,sysadm_t,proc_type,file,"{read, lock, ioctl, open, getattr}",


In [27]:
p.terules_query(target="proc_kcore_t", perms=["write", "append"], tclass=["file"])

Unnamed: 0,source,target,tclass,perms,cond
0,kern_unconfined,proc_type,file,"{setattr, mounton, open, link, audit_access, execmod, unlink, quotaon, write, getattr, relabelto, rename, execute_no_trans, read, lock, relabelfrom, swapon, append, ioctl, create, execute}",


## Read/Write Rules - Terminal Types
Terminal files represent a large information flow between domains that can read/write from these possibly shared devices. One example - a domain writes a password prompt to another terminal and then reads the data entered by a user.

### Read Terminals

In [28]:
p.terules_query(target=["console_device_t", "tty_device_t", "ptmx_t", "devpts_t"], perms=["read"], tclass=["chr_file"])

Unnamed: 0,source,target,tclass,perms,cond
0,NetworkManager_t,tty_device_t,chr_file,"{read, lock, ioctl, write, open, getattr, append}",
1,ajaxterm_t,ptmx_t,chr_file,"{read, lock, ioctl, write, open, getattr, append}",
2,amanda_t,file_type,chr_file,"{read, lock, ioctl, open, getattr}",
3,apcupsd_t,console_device_t,chr_file,"{read, lock, ioctl, write, open, getattr, append}",
4,apcupsd_t,devpts_t,chr_file,"{read, lock, ioctl, write, open, getattr, append}",
5,apcupsd_t,tty_device_t,chr_file,"{read, lock, ioctl, write, open, getattr, append}",
6,apm_t,console_device_t,chr_file,"{read, lock, ioctl, write, getattr, append}",
7,apm_t,devpts_t,chr_file,"{read, lock, ioctl, write, getattr, append}",
8,apm_t,tty_device_t,chr_file,"{read, lock, ioctl, write, getattr, append}",
9,auditctl_t,console_device_t,chr_file,"{read, lock, ioctl, write, getattr, append}",


### Write Terminals

In [29]:
p.terules_query(target=["console_device_t", "tty_device_t", "ptmx_t", "devpts_t"], perms=["write", "append", "ioctl"], tclass=["chr_file"])

Unnamed: 0,source,target,tclass,perms,cond
0,NetworkManager_t,tty_device_t,chr_file,"{read, lock, ioctl, write, open, getattr, append}",
1,ajaxterm_t,ptmx_t,chr_file,"{read, lock, ioctl, write, open, getattr, append}",
2,amanda_t,file_type,chr_file,"{read, lock, ioctl, open, getattr}",
3,apcupsd_t,console_device_t,chr_file,"{read, lock, ioctl, write, open, getattr, append}",
4,apcupsd_t,devpts_t,chr_file,"{read, lock, ioctl, write, open, getattr, append}",
5,apcupsd_t,tty_device_t,chr_file,"{read, lock, ioctl, write, open, getattr, append}",
6,apm_t,console_device_t,chr_file,"{read, lock, ioctl, write, getattr, append}",
7,apm_t,devpts_t,chr_file,"{read, lock, ioctl, write, getattr, append}",
8,apm_t,tty_device_t,chr_file,"{read, lock, ioctl, write, getattr, append}",
9,auditctl_t,console_device_t,chr_file,"{read, lock, ioctl, write, getattr, append}",


## Write Rules - etc_t
Files labeled etc_t includes a variety of files for system-wide configuration. In addition, default poilicies often fail to split out sensitive files into separate types outside of etc_t. One example that can impact stateless systems is rwtab and statetab. Modifications to these files can alter what state is retained across reboots.

On solutions prior to RHEL 7, the default label for the password file /etc/passwd us also etc_t, thus any domain that can write to etc_t can modify the file containing key userdata (though no longer password hashes), e.g., changing an unpriv user ID to UID 0.

In [30]:
p.object_info_flow(object_type="etc_t", tclass=["file", "dir"], direction="w")

Unnamed: 0,type,conditional,perms
0,NetworkManager_t,,"{add_name, remove_name, read, search, lock, ioctl, write, open, getattr}"
1,abrt_dump_oops_t,,"{setattr, reparent, search, open, link, unlink, rmdir, write, getattr, rename, read, lock, append, add_name, remove_name, ioctl, create}"
2,alsa_t,,"{add_name, remove_name, read, search, lock, ioctl, write, open, getattr}"
3,apcupsd_t,,"{add_name, remove_name, read, search, lock, ioctl, write, open, getattr}"
4,automount_t,,"{setattr, add_name, rename, unlink, remove_name, read, reparent, search, lock, rmdir, ioctl, write, open, link, getattr, create}"
5,avahi_t,,"{add_name, remove_name, read, search, lock, ioctl, write, open, getattr}"
6,bootloader_t,,"{add_name, remove_name, read, search, lock, ioctl, write, open, getattr}"
7,cardmgr_t,,"{add_name, remove_name, read, search, lock, ioctl, write, open, getattr}"
8,chfn_t,,"{add_name, remove_name, read, search, lock, ioctl, write, open, getattr}"
9,cobblerd_t,,"{add_name, remove_name, read, search, lock, ioctl, write, open, getattr}"


## Write Rules - system_conf_t
Files labeled sys_conf_t are applied to system-wide configuration files, such as those residing in /etc/sysconfig. Included in that set, are the iptables configuration files. Domains with the ability to write to these files can alter the firewall ruleset, including SELinux packet labels applied via SECMARK, in effect, providing the ability to alter the intent of the policy.

In [31]:
p.terules_query(target="system_conf_t", perms=["write", "append", "unlink"], tclass=["file"])

Unnamed: 0,source,target,tclass,perms,cond
0,abrt_dump_oops_t,non_security_file_type,file,"{setattr, append, rename, unlink, read, open, lock, ioctl, write, link, getattr, create}",
1,files_unconfined_type,file_type,file,"{setattr, append, rename, unlink, quotaon, mounton, execute_no_trans, read, open, audit_access, lock, relabelfrom, ioctl, write, execute, link, getattr, swapon, create, relabelto}",
2,firewallgui_t,system_conf_t,file,"{setattr, append, rename, unlink, read, open, lock, ioctl, write, link, getattr, create}",
3,ftpd_t,non_security_file_type,file,"{setattr, append, rename, unlink, read, open, lock, ioctl, write, link, getattr, create}",ftpd_full_access
4,glusterd_t,non_security_file_type,file,"{setattr, append, rename, unlink, read, open, lock, ioctl, write, link, getattr, create}",gluster_export_all_rw
5,initrc_t,system_conf_t,file,"{setattr, append, rename, unlink, read, open, lock, ioctl, write, link, getattr, create}",
6,iptables_t,system_conf_t,file,"{setattr, append, rename, unlink, read, open, lock, ioctl, write, link, getattr, create}",
7,kernel_t,non_security_file_type,file,"{setattr, append, rename, unlink, read, open, lock, ioctl, write, link, getattr, create}",nfs_export_all_rw
8,mount_t,non_security_file_type,file,"{read, write}",mount_anyfile
9,ncftool_t,system_conf_t,file,"{setattr, append, rename, unlink, read, open, lock, ioctl, write, link, getattr, create, relabelto}",


## Write Rules - net_conf_t
Files labeled net_conf_t are applied to network configuration files. These files contain the information the system uses to config network devices. Domains that can modify these files can alter the configuration of devices such  as eth0.

In [32]:
p.object_info_flow(object_type="net_conf_t", direction="w")

Unnamed: 0,type,conditional,perms
0,NetworkManager_t,,"{setattr, rename, read, lock, open, link, append, unlink, ioctl, write, getattr, create}"
1,abrt_dump_oops_t,,"{setattr, rename, read, lock, open, link, append, unlink, ioctl, write, getattr, create}"
2,avahi_t,,"{setattr, rename, read, lock, open, link, append, unlink, ioctl, write, getattr, create}"
3,cardmgr_t,,"{setattr, rename, read, lock, open, link, append, unlink, ioctl, write, getattr, create}"
4,cobblerd_t,,"{read, lock, ioctl, write, open, getattr, append}"
5,denyhosts_t,,"{setattr, rename, read, lock, open, link, append, unlink, ioctl, write, getattr, create}"
6,dhcpc_t,,"{setattr, rename, read, lock, relabelfrom, open, link, append, unlink, ioctl, write, getattr, create, relabelto}"
7,dnssec_trigger_t,,"{setattr, rename, read, lock, relabelfrom, open, link, append, unlink, ioctl, write, getattr, create, relabelto}"
8,fail2ban_t,,"{setattr, rename, read, lock, open, link, append, unlink, ioctl, write, getattr, create}"
9,files_unconfined_type,,"{setattr, mounton, open, link, audit_access, execmod, unlink, quotaon, write, getattr, relabelto, rename, execute_no_trans, read, lock, relabelfrom, swapon, append, ioctl, create, execute}"


## Write Rules - lib_t
Files labeled lib_t are used by dynamically linked applications. A vast number of shared libraries are labeled lib_t. Domains that can modify these files can alter the behavior of any application linked against these files.

In [33]:
p.object_info_flow(object_type="lib_t", direction="w")

Unnamed: 0,type,conditional,perms
0,abrt_dump_oops_t,,"{setattr, rename, read, lock, open, link, append, unlink, ioctl, write, getattr, create}"
1,files_unconfined_type,,"{setattr, mounton, open, link, audit_access, execmod, unlink, quotaon, write, getattr, relabelto, rename, execute_no_trans, read, lock, relabelfrom, swapon, append, ioctl, create, execute}"
2,ldconfig_t,,"{setattr, create, rename, unlink, read, lock, ioctl, write, link, getattr, append}"
3,pegasus_openlmi_logicalfile_t,,"{setattr, rename, read, lock, open, link, append, unlink, ioctl, write, getattr, create}"
4,prelink_t,,"{setattr, execmod, create, rename, unlink, read, lock, relabelfrom, relabelto, ioctl, write, open, link, getattr, append, execute}"
5,restorecond_t,,"{read, lock, relabelfrom, ioctl, open, getattr, relabelto}"
6,rpm_script_t,,"{setattr, rename, read, lock, relabelfrom, open, link, append, create, unlink, write, ioctl, getattr, relabelto}"
7,rpm_t,,"{setattr, rename, read, lock, relabelfrom, open, link, append, create, unlink, write, ioctl, getattr, relabelto}"
8,secadm_t,,"{relabelfrom, getattr, relabelto}"
9,setfiles_mac_t,,"{relabelfrom, getattr, relabelto}"


## Read/Write Rules - auditd_log_t var_log_t
Files labeled auditd_log_t contain the audit messages generated by the audit frameworks which is critical to monitoring the security posture of the solution. Files labeled var_log_t are typically files that should have a different label as var_log_t is a generic label and many base system domains have the ability to modify files with that label. Modifying these files can allow a domain to report mis-information or truncate otherwise sensitive log and audit entries.

In [34]:
# Write Audit logs
p.object_info_flow(object_type="auditd_log_t", direction="w")

Unnamed: 0,type,conditional,perms
0,auditadm_t,,"{setattr, create, rename, unlink, read, lock, ioctl, write, open, link, getattr, append}"
1,auditd_t,,"{setattr, rename, read, lock, open, link, append, unlink, ioctl, write, getattr, create}"
2,files_unconfined_type,,"{setattr, mounton, open, link, audit_access, execmod, unlink, quotaon, write, getattr, relabelto, rename, execute_no_trans, read, lock, relabelfrom, swapon, append, ioctl, create, execute}"
3,logadm_t,,"{setattr, create, rename, unlink, read, lock, ioctl, write, open, link, getattr, append}"
4,restorecond_t,,"{read, lock, relabelfrom, ioctl, open, getattr, relabelto}"
5,rpm_script_t,,"{setattr, rename, read, lock, relabelfrom, open, link, append, create, unlink, write, ioctl, getattr, relabelto}"
6,rpm_t,,"{setattr, rename, read, lock, relabelfrom, open, link, append, create, unlink, write, ioctl, getattr, relabelto}"
7,sandbox_domain,,"{read, lock, ioctl, write, getattr, append}"
8,secadm_t,,"{relabelfrom, getattr, relabelto}"
9,setfiles_mac_t,,"{relabelfrom, getattr, relabelto}"


In [35]:
# Read object logs
p.object_info_flow(object_type="auditd_log_t", direction="r")

Unnamed: 0,type,conditional,perms
0,aide_t,,"{read, lock, ioctl, open, getattr}"
1,amanda_t,,"{read, lock, ioctl, open, getattr}"
2,auditadm_t,,"{setattr, create, rename, unlink, read, lock, ioctl, write, open, link, getattr, append}"
3,auditd_t,,"{setattr, rename, read, lock, open, link, append, unlink, ioctl, write, getattr, create}"
4,bacula_t,,"{read, lock, ioctl, open, getattr}"
5,cgred_t,,"{getattr, read}"
6,fail2ban_client_t,,"{read, lock, ioctl, open, getattr}"
7,fail2ban_t,,"{read, lock, ioctl, open, getattr}"
8,files_unconfined_type,,"{setattr, mounton, open, link, audit_access, execmod, unlink, quotaon, write, getattr, relabelto, rename, execute_no_trans, read, lock, relabelfrom, swapon, append, ioctl, create, execute}"
9,logadm_t,,"{setattr, create, rename, unlink, read, lock, ioctl, write, open, link, getattr, append}"


In [36]:
# Write generic logs
p.object_info_flow(object_type="var_log_t", direction="w")

Unnamed: 0,type,conditional,perms
0,abrt_dump_oops_t,,"{setattr, rename, read, lock, open, link, append, unlink, ioctl, write, getattr, create}"
1,application_domain_type,,"{ioctl, getattr, append, lock}"
2,bootloader_t,,"{setattr, create, rename, unlink, read, lock, ioctl, write, open, link, getattr, append}"
3,daemon,,"{ioctl, getattr, append, lock}"
4,dmesg_t,,"{lock, ioctl, write, open, getattr, append}"
5,dovecot_deliver_t,,"{lock, ioctl, open, getattr, append}"
6,files_unconfined_type,,"{setattr, mounton, open, link, audit_access, execmod, unlink, quotaon, write, getattr, relabelto, rename, execute_no_trans, read, lock, relabelfrom, swapon, append, ioctl, create, execute}"
7,httpd_sys_script_t,,"{ioctl, getattr, append, lock}"
8,init_t,,"{read, lock, ioctl, write, open, getattr, append}"
9,initrc_t,,"{setattr, create, rename, unlink, read, lock, ioctl, write, open, link, getattr, append}"


## Read/Write Rules - shadow_t
Files labeled shadow_t contain user password data, including salts and hashes. Domains that can write to these files can modify user passwords.

Domains that can read from these files can collect user password data for use in, e.g., brute force attacks.

In [37]:
p.object_info_flow(object_type="shadow_t", tclass=["file"], direction="w")

Unnamed: 0,type,conditional,perms
0,cockpit_session_t,,"{setattr, create, rename, unlink, read, lock, ioctl, write, open, link, getattr, append}"
1,files_unconfined_type,,"{setattr, create, rename, unlink, quotaon, mounton, execute_no_trans, getattr, read, lock, relabelfrom, relabelto, ioctl, write, open, link, audit_access, swapon, append, execute}"
2,groupadd_t,,"{setattr, create, rename, unlink, read, lock, relabelfrom, ioctl, write, open, link, getattr, append, relabelto}"
3,passwd_t,,"{setattr, create, rename, unlink, read, lock, relabelfrom, ioctl, write, open, link, getattr, append, relabelto}"
4,pegasus_openlmi_account_t,,"{setattr, create, rename, unlink, read, lock, relabelfrom, ioctl, write, open, link, getattr, append, relabelto}"
5,rpm_script_t,,"{setattr, rename, read, lock, relabelfrom, open, link, append, unlink, ioctl, write, getattr, create, relabelto}"
6,rpm_t,,"{setattr, rename, read, lock, relabelfrom, open, link, append, unlink, ioctl, write, getattr, create, relabelto}"
7,sandbox_domain,,"{read, lock, ioctl, write, getattr, append}"
8,secadm_t,,"{relabelfrom, getattr, relabelto}"
9,setfiles_mac_t,,"{relabelfrom, getattr, relabelto}"


In [38]:
p.object_info_flow(object_type="shadow_t", tclass=["file"], direction="r")

Unnamed: 0,type,conditional,perms
0,accountsd_t,,"{read, lock, ioctl, open, getattr}"
1,aide_t,,"{read, lock, ioctl, open, getattr}"
2,amanda_t,,"{read, lock, ioctl, open, getattr}"
3,bacula_t,,"{read, lock, ioctl, open, getattr}"
4,chkpwd_t,,"{read, lock, ioctl, open, getattr}"
5,cockpit_session_t,,"{setattr, create, rename, unlink, read, lock, ioctl, write, open, link, getattr, append}"
6,files_unconfined_type,,"{setattr, create, rename, unlink, quotaon, mounton, execute_no_trans, getattr, read, lock, relabelfrom, relabelto, ioctl, write, open, link, audit_access, swapon, append, execute}"
7,groupadd_t,,"{setattr, create, rename, unlink, read, lock, relabelfrom, ioctl, write, open, link, getattr, append, relabelto}"
8,passwd_t,,"{setattr, create, rename, unlink, read, lock, relabelfrom, ioctl, write, open, link, getattr, append, relabelto}"
9,pegasus_openlmi_account_t,,"{setattr, create, rename, unlink, read, lock, relabelfrom, ioctl, write, open, link, getattr, append, relabelto}"


## Read/Write Rules - unlabeled_t Files
unlabeled_t is the default label for a number of object classes, such as packets and files. Almost nothing should have access to this type.

In [39]:
p.object_info_flow(object_type="unlabeled_t", direction="w")

Unnamed: 0,type,conditional,perms
0,abrt_dump_oops_t,,"{setattr, rename, read, lock, open, link, append, unlink, ioctl, write, getattr, create}"
1,afs_t,,"{read, lock, ioctl, write, open, getattr, append}"
2,bootloader_t,,"{setattr, rename, read, lock, open, link, append, unlink, ioctl, write, getattr, create}"
3,ccs_t,,"{setattr, create, rename, unlink, read, lock, ioctl, write, open, link, getattr, append}"
4,files_unconfined_type,,"{setattr, mounton, open, link, audit_access, execmod, unlink, quotaon, write, getattr, relabelto, rename, execute_no_trans, read, lock, relabelfrom, swapon, append, ioctl, create, execute}"
5,fsadm_t,,"{read, lock, ioctl, write, open, getattr, append}"
6,kern_unconfined,,"{setattr, mounton, open, link, audit_access, entrypoint, execmod, unlink, quotaon, write, getattr, relabelto, rename, execute_no_trans, read, lock, relabelfrom, swapon, append, ioctl, create, execute}"
7,pegasus_openlmi_logicalfile_t,,"{setattr, rename, read, lock, open, link, append, unlink, ioctl, write, getattr, create}"
8,restorecond_t,,"{read, lock, relabelfrom, ioctl, open, getattr, relabelto}"
9,rpm_script_t,,"{setattr, rename, read, lock, relabelfrom, open, link, append, create, unlink, write, ioctl, getattr, relabelto}"


In [40]:
p.object_info_flow(object_type="unlabeled_t", direction="r")

Unnamed: 0,type,conditional,perms
0,NetworkManager_t,,"{read, lock, ioctl, open, getattr}"
1,abrt_dump_oops_t,,"{setattr, rename, read, lock, open, link, append, unlink, ioctl, write, getattr, create}"
2,afs_t,,"{read, lock, ioctl, write, open, getattr, append}"
3,aide_t,,"{read, lock, ioctl, open, getattr}"
4,amanda_t,,"{read, lock, ioctl, open, getattr}"
5,bacula_t,,"{read, lock, ioctl, open, getattr}"
6,bootloader_t,,"{setattr, rename, read, lock, open, link, append, unlink, ioctl, write, getattr, create}"
7,ccs_t,,"{setattr, create, rename, unlink, read, lock, ioctl, write, open, link, getattr, append}"
8,cgred_t,,"{getattr, read}"
9,cluster_t,,"{read, lock, ioctl, open, getattr}"


## Write Rules - wtmp_t
wtmp contains login data - another component of overall system logging and auditing. Writing to this allows one to modify the login records of the system.

In [41]:
p.object_info_flow(object_type="wtmp_t", direction="w")

Unnamed: 0,type,conditional,perms
0,abrt_dump_oops_t,,"{setattr, rename, read, lock, open, link, append, unlink, ioctl, write, getattr, create}"
1,acct_t,,"{setattr, create, rename, unlink, read, lock, ioctl, write, open, link, getattr, append}"
2,application_domain_type,,"{ioctl, getattr, append, lock}"
3,audisp_remote_t,,"{lock, ioctl, open, getattr, append}"
4,auditadm_su_t,,"{read, lock, ioctl, open, getattr, append}"
5,chfn_t,,"{read, lock, ioctl, open, getattr, append}"
6,cockpit_session_t,,"{read, lock, ioctl, write, open, getattr, append}"
7,consolekit_t,,"{lock, ioctl, write, open, getattr, append}"
8,daemon,,"{ioctl, getattr, append, lock}"
9,dirsrv_t,,"{read, lock, ioctl, open, getattr, append}"


## Write Rules - shell_exec_t
Shell binaries are relied upon by numerous system components. The ability to modify these binaries represents significant risk.

In [42]:
p.object_info_flow(object_type="shell_exec_t", direction="w")

Unnamed: 0,type,conditional,perms
0,abrt_dump_oops_t,,"{setattr, rename, read, lock, open, link, append, unlink, ioctl, write, getattr, create}"
1,files_unconfined_type,,"{setattr, mounton, open, link, audit_access, execmod, unlink, quotaon, write, getattr, relabelto, rename, execute_no_trans, read, lock, relabelfrom, swapon, append, ioctl, create, execute}"
2,pegasus_openlmi_logicalfile_t,,"{setattr, rename, read, lock, open, link, append, unlink, ioctl, write, getattr, create}"
3,prelink_t,,"{setattr, create, rename, unlink, read, lock, relabelfrom, relabelto, ioctl, write, open, link, getattr, append, execute}"
4,restorecond_t,,"{read, lock, relabelfrom, ioctl, open, getattr, relabelto}"
5,rpm_script_t,,"{setattr, rename, read, lock, relabelfrom, open, link, append, create, unlink, write, ioctl, getattr, relabelto}"
6,rpm_t,,"{setattr, rename, read, lock, relabelfrom, open, link, append, create, unlink, write, ioctl, getattr, relabelto}"
7,secadm_t,,"{relabelfrom, getattr, relabelto}"
8,setfiles_mac_t,,"{relabelfrom, getattr, relabelto}"
9,setfiles_t,,"{read, relabelfrom, getattr, relabelto}"


## Write Rules - bin_t
Binaries labeled bin_t are relied upon by numerous system components. The ability to modify these binaries represents significant risk.

In [43]:
p.object_info_flow(object_type="bin_t", direction="w")

Unnamed: 0,type,conditional,perms
0,abrt_dump_oops_t,,"{setattr, rename, read, lock, open, link, append, unlink, ioctl, write, getattr, create}"
1,files_unconfined_type,,"{setattr, mounton, open, link, audit_access, execmod, unlink, quotaon, write, getattr, relabelto, rename, execute_no_trans, read, lock, relabelfrom, swapon, append, ioctl, create, execute}"
2,pegasus_openlmi_logicalfile_t,,"{setattr, rename, read, lock, open, link, append, unlink, ioctl, write, getattr, create}"
3,prelink_t,,"{setattr, rename, read, lock, relabelfrom, link, open, append, unlink, ioctl, write, execute, getattr, create, relabelto}"
4,restorecond_t,,"{read, lock, relabelfrom, ioctl, open, getattr, relabelto}"
5,rpm_script_t,,"{setattr, rename, read, lock, relabelfrom, open, link, append, create, unlink, write, ioctl, getattr, relabelto}"
6,rpm_t,,"{setattr, rename, read, lock, relabelfrom, open, link, append, create, unlink, write, ioctl, getattr, relabelto}"
7,secadm_t,,"{relabelfrom, getattr, relabelto}"
8,setfiles_mac_t,,"{relabelfrom, getattr, relabelto}"
9,setfiles_t,,"{read, relabelfrom, getattr, relabelto}"


## Read/Write Rules - fixed_disk_device_t
Fixed storage devices e.g., HDDs, should have strictly controlled raw write access, or write access in general. Writing to fixed disk devicces can compromise the integrity of the system. Reading from fixed disk devices can compromise the confidentiality of data residing on the system.

In [44]:
# Write to fixed disk devices
p.terules_query(target="fixed_disk_device_t", perms=["write"], tclass=["blk_file"])

Unnamed: 0,source,target,tclass,perms,cond
0,bootloader_t,fixed_disk_device_t,blk_file,"{read, lock, ioctl, write, open, getattr, append}",
1,clogd_t,fixed_disk_device_t,blk_file,"{read, lock, ioctl, write, open, getattr, append}",
2,clvmd_t,fixed_disk_device_t,blk_file,"{setattr, append, rename, unlink, read, open, lock, relabelfrom, ioctl, write, link, getattr, create, relabelto}",
3,cmirrord_t,fixed_disk_device_t,blk_file,"{read, lock, ioctl, write, open, getattr, create}",
4,devicekit_disk_t,fixed_disk_device_t,blk_file,"{read, lock, ioctl, write, open, getattr, append}",
5,devices_unconfined_type,device_node,blk_file,"{setattr, execmod, append, rename, unlink, quotaon, mounton, read, open, audit_access, lock, relabelfrom, ioctl, write, execute, link, getattr, swapon, create, relabelto}",
6,drbd_t,fixed_disk_device_t,blk_file,"{read, lock, ioctl, write, open, getattr, append}",
7,fenced_t,fixed_disk_device_t,blk_file,"{read, lock, ioctl, write, open, getattr, append}",
8,fsadm_t,fixed_disk_device_t,blk_file,"{read, lock, ioctl, write, open, getattr, swapon, append}",
9,fsdaemon_t,fixed_disk_device_t,blk_file,"{append, read, lock, ioctl, write, open, getattr, create}",


In [45]:
# Read from fixed disk devices
p.terules_query(target="fixed_disk_device_t", perms=["read"], tclass=["blk_file"])

Unnamed: 0,source,target,tclass,perms,cond
0,amanda_t,fixed_disk_device_t,blk_file,"{read, lock, ioctl, open, getattr}",
1,bacula_t,fixed_disk_device_t,blk_file,"{read, lock, ioctl, open, getattr}",
2,blkmapd_t,fixed_disk_device_t,blk_file,"{read, lock, ioctl, open, getattr}",
3,bootloader_t,fixed_disk_device_t,blk_file,"{read, lock, ioctl, write, open, getattr, append}",
4,clogd_t,fixed_disk_device_t,blk_file,"{read, lock, ioctl, write, open, getattr, append}",
5,cloud_init_t,fixed_disk_device_t,blk_file,"{read, lock, ioctl, open, getattr}",
6,cluster_t,fixed_disk_device_t,blk_file,"{read, lock, ioctl, open, getattr}",
7,clvmd_t,fixed_disk_device_t,blk_file,"{setattr, append, rename, unlink, read, open, lock, relabelfrom, ioctl, write, link, getattr, create, relabelto}",
8,cmirrord_t,fixed_disk_device_t,blk_file,"{read, lock, ioctl, write, open, getattr, create}",
9,devicekit_disk_t,fixed_disk_device_t,blk_file,"{read, lock, ioctl, write, open, getattr, append}",


## Write Rules - default_t
Anything labeled default_t is in indication a more-specific label does not exist, which means there is a problem with the policy.

In [46]:
p.object_info_flow(object_type="default_t", direction="w")

Unnamed: 0,type,conditional,perms
0,abrt_dump_oops_t,,"{setattr, rename, read, lock, open, link, append, unlink, ioctl, write, getattr, create}"
1,files_unconfined_type,,"{setattr, mounton, open, link, audit_access, execmod, unlink, quotaon, write, getattr, relabelto, rename, execute_no_trans, read, lock, relabelfrom, swapon, append, ioctl, create, execute}"
2,pegasus_openlmi_logicalfile_t,,"{setattr, rename, read, lock, open, link, append, unlink, ioctl, write, getattr, create}"
3,restorecond_t,,"{read, lock, relabelfrom, ioctl, open, getattr, relabelto}"
4,ricci_modstorage_t,,"{setattr, create, rename, unlink, read, lock, ioctl, write, open, link, getattr, append}"
5,rpm_script_t,,"{setattr, rename, read, lock, relabelfrom, open, link, append, create, unlink, write, ioctl, getattr, relabelto}"
6,rpm_t,,"{setattr, rename, read, lock, relabelfrom, open, link, append, create, unlink, write, ioctl, getattr, relabelto}"
7,sandbox_domain,,"{read, lock, ioctl, write, getattr, append}"
8,secadm_t,,"{relabelfrom, getattr, relabelto}"
9,setfiles_mac_t,,"{relabelfrom, getattr, relabelto}"


## Transition - initrc_t
On versions <= RHEL 6, initrc_t is a very powerful domain. Domains that can transition to initrc_t can start, stop, or otherwise influence services running on the system.

In [47]:
p.domains_with(target_name="initrc_t", tclass=["process"], perms=["transition"])

Unnamed: 0,type,conditional,perms
0,NetworkManager_t,,"{transition, signal, signull, sigkill}"
1,anaconda_t,,{transition}
2,apmd_t,,{transition}
3,authconfig_t,,"{transition, sigchld}"
4,certmonger_unconfined_t,,{transition}
5,cluster_t,,"{transition, getattr}"
6,cobblerd_t,,{transition}
7,condor_startd_t,,{transition}
8,crond_t,,{transition}
9,ctdbd_t,,{transition}


## Memory Permissions
These permissions control access to specific operations on memory segments. Granting these permissions makes it easier to exploit a vulnerable process and should be avoided. Most can be addressed via code or compilation flag changes.

In [48]:
p.domains_with(target_name="", tclass=["process"], perms=["execmem", "execmod", "execheap", "execstack"])

Unnamed: 0,type,conditional,perms
0,anaconda_t,,"{transition, signull, sigchld, getcap, execmem, sigkill, sigstop, getsched, fork, signal, dyntransition}"
1,blueman_t,,"{setsched, signull, sigchld, getcap, execmem, sigkill, sigstop, getsched, fork, signal}"
2,boinc_project_t,,"{transition, setsched, execstack, signull, sigchld, setcap, getcap, sigkill, sigstop, getsched, fork, signal, setpgid, dyntransition}"
3,bootloader_t,,"{transition, signull, sigchld, getcap, execmem, sigkill, sigstop, getsched, fork, signal, dyntransition}"
4,chrome_sandbox_nacl_t,,"{setsched, signull, sigchld, getcap, execmem, sigkill, sigstop, getsched, fork, signal}"
5,chrome_sandbox_t,,"{setsched, execstack, signull, sigchld, getcap, execmem, sigkill, sigstop, getsched, fork, signal, setrlimit}"
6,condor_startd_t,,"{transition, signull, sigchld, getcap, execmem, sigkill, sigstop, getsched, fork, signal, dyntransition}"
7,container_t,,"{setsched, execstack, signull, sigchld, setcap, getcap, setrlimit, execmem, sigkill, getpgid, sigstop, getattr, getsched, fork, signal, setpgid}"
8,couchdb_t,,"{setsched, signull, sigchld, getcap, execmem, sigkill, sigstop, getsched, fork, signal}"
9,fsadm_t,,"{signull, rlimitinh, getcap, setkeycreate, sigkill, setsched, share, getsession, noatsecure, getpgid, setcap, getattr, fork, dyntransition, setpgid, transition, sigchld, execstack, setsockcreate, signal, sigstop, getsched, siginh}"


## SELinux

The ability to load policy, toggle enforcement, and change booleans is obviously important for system protection.

In [49]:
p.domains_with(target_name="", tclass=["security"], perms=["load_policy", "setbool", "setenforce"], expand_attrs=True)

Unnamed: 0,type,conditional,perms
0,init_t,,"{check_context, load_policy, compute_user, compute_av, compute_create}"
1,abrt_handle_event_t,secure_mode_policyload,{setenforce}
2,anaconda_t,secure_mode_policyload,{setenforce}
3,authconfig_t,secure_mode_policyload,{setenforce}
4,bacula_unconfined_script_t,secure_mode_policyload,{setenforce}
5,boinc_project_t,secure_mode_policyload,{setenforce}
6,bootloader_t,secure_mode_policyload,{setenforce}
7,certmonger_unconfined_t,secure_mode_policyload,{setenforce}
8,cinder_api_t,secure_mode_policyload,{setenforce}
9,cinder_backup_t,secure_mode_policyload,{setenforce}
