Signed-off-by: Jessica Frazelle <acidburn@docker.com>
| 1 | 1 |
new file mode 100644 |
| ... | ... |
@@ -0,0 +1,502 @@ |
| 0 |
+ GNU LESSER GENERAL PUBLIC LICENSE |
|
| 1 |
+ Version 2.1, February 1999 |
|
| 2 |
+ |
|
| 3 |
+ Copyright (C) 1991, 1999 Free Software Foundation, Inc. |
|
| 4 |
+ 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA |
|
| 5 |
+ Everyone is permitted to copy and distribute verbatim copies |
|
| 6 |
+ of this license document, but changing it is not allowed. |
|
| 7 |
+ |
|
| 8 |
+[This is the first released version of the Lesser GPL. It also counts |
|
| 9 |
+ as the successor of the GNU Library Public License, version 2, hence |
|
| 10 |
+ the version number 2.1.] |
|
| 11 |
+ |
|
| 12 |
+ Preamble |
|
| 13 |
+ |
|
| 14 |
+ The licenses for most software are designed to take away your |
|
| 15 |
+freedom to share and change it. By contrast, the GNU General Public |
|
| 16 |
+Licenses are intended to guarantee your freedom to share and change |
|
| 17 |
+free software--to make sure the software is free for all its users. |
|
| 18 |
+ |
|
| 19 |
+ This license, the Lesser General Public License, applies to some |
|
| 20 |
+specially designated software packages--typically libraries--of the |
|
| 21 |
+Free Software Foundation and other authors who decide to use it. You |
|
| 22 |
+can use it too, but we suggest you first think carefully about whether |
|
| 23 |
+this license or the ordinary General Public License is the better |
|
| 24 |
+strategy to use in any particular case, based on the explanations below. |
|
| 25 |
+ |
|
| 26 |
+ When we speak of free software, we are referring to freedom of use, |
|
| 27 |
+not price. Our General Public Licenses are designed to make sure that |
|
| 28 |
+you have the freedom to distribute copies of free software (and charge |
|
| 29 |
+for this service if you wish); that you receive source code or can get |
|
| 30 |
+it if you want it; that you can change the software and use pieces of |
|
| 31 |
+it in new free programs; and that you are informed that you can do |
|
| 32 |
+these things. |
|
| 33 |
+ |
|
| 34 |
+ To protect your rights, we need to make restrictions that forbid |
|
| 35 |
+distributors to deny you these rights or to ask you to surrender these |
|
| 36 |
+rights. These restrictions translate to certain responsibilities for |
|
| 37 |
+you if you distribute copies of the library or if you modify it. |
|
| 38 |
+ |
|
| 39 |
+ For example, if you distribute copies of the library, whether gratis |
|
| 40 |
+or for a fee, you must give the recipients all the rights that we gave |
|
| 41 |
+you. You must make sure that they, too, receive or can get the source |
|
| 42 |
+code. If you link other code with the library, you must provide |
|
| 43 |
+complete object files to the recipients, so that they can relink them |
|
| 44 |
+with the library after making changes to the library and recompiling |
|
| 45 |
+it. And you must show them these terms so they know their rights. |
|
| 46 |
+ |
|
| 47 |
+ We protect your rights with a two-step method: (1) we copyright the |
|
| 48 |
+library, and (2) we offer you this license, which gives you legal |
|
| 49 |
+permission to copy, distribute and/or modify the library. |
|
| 50 |
+ |
|
| 51 |
+ To protect each distributor, we want to make it very clear that |
|
| 52 |
+there is no warranty for the free library. Also, if the library is |
|
| 53 |
+modified by someone else and passed on, the recipients should know |
|
| 54 |
+that what they have is not the original version, so that the original |
|
| 55 |
+author's reputation will not be affected by problems that might be |
|
| 56 |
+introduced by others. |
|
| 57 |
+ |
|
| 58 |
+ Finally, software patents pose a constant threat to the existence of |
|
| 59 |
+any free program. We wish to make sure that a company cannot |
|
| 60 |
+effectively restrict the users of a free program by obtaining a |
|
| 61 |
+restrictive license from a patent holder. Therefore, we insist that |
|
| 62 |
+any patent license obtained for a version of the library must be |
|
| 63 |
+consistent with the full freedom of use specified in this license. |
|
| 64 |
+ |
|
| 65 |
+ Most GNU software, including some libraries, is covered by the |
|
| 66 |
+ordinary GNU General Public License. This license, the GNU Lesser |
|
| 67 |
+General Public License, applies to certain designated libraries, and |
|
| 68 |
+is quite different from the ordinary General Public License. We use |
|
| 69 |
+this license for certain libraries in order to permit linking those |
|
| 70 |
+libraries into non-free programs. |
|
| 71 |
+ |
|
| 72 |
+ When a program is linked with a library, whether statically or using |
|
| 73 |
+a shared library, the combination of the two is legally speaking a |
|
| 74 |
+combined work, a derivative of the original library. The ordinary |
|
| 75 |
+General Public License therefore permits such linking only if the |
|
| 76 |
+entire combination fits its criteria of freedom. The Lesser General |
|
| 77 |
+Public License permits more lax criteria for linking other code with |
|
| 78 |
+the library. |
|
| 79 |
+ |
|
| 80 |
+ We call this license the "Lesser" General Public License because it |
|
| 81 |
+does Less to protect the user's freedom than the ordinary General |
|
| 82 |
+Public License. It also provides other free software developers Less |
|
| 83 |
+of an advantage over competing non-free programs. These disadvantages |
|
| 84 |
+are the reason we use the ordinary General Public License for many |
|
| 85 |
+libraries. However, the Lesser license provides advantages in certain |
|
| 86 |
+special circumstances. |
|
| 87 |
+ |
|
| 88 |
+ For example, on rare occasions, there may be a special need to |
|
| 89 |
+encourage the widest possible use of a certain library, so that it becomes |
|
| 90 |
+a de-facto standard. To achieve this, non-free programs must be |
|
| 91 |
+allowed to use the library. A more frequent case is that a free |
|
| 92 |
+library does the same job as widely used non-free libraries. In this |
|
| 93 |
+case, there is little to gain by limiting the free library to free |
|
| 94 |
+software only, so we use the Lesser General Public License. |
|
| 95 |
+ |
|
| 96 |
+ In other cases, permission to use a particular library in non-free |
|
| 97 |
+programs enables a greater number of people to use a large body of |
|
| 98 |
+free software. For example, permission to use the GNU C Library in |
|
| 99 |
+non-free programs enables many more people to use the whole GNU |
|
| 100 |
+operating system, as well as its variant, the GNU/Linux operating |
|
| 101 |
+system. |
|
| 102 |
+ |
|
| 103 |
+ Although the Lesser General Public License is Less protective of the |
|
| 104 |
+users' freedom, it does ensure that the user of a program that is |
|
| 105 |
+linked with the Library has the freedom and the wherewithal to run |
|
| 106 |
+that program using a modified version of the Library. |
|
| 107 |
+ |
|
| 108 |
+ The precise terms and conditions for copying, distribution and |
|
| 109 |
+modification follow. Pay close attention to the difference between a |
|
| 110 |
+"work based on the library" and a "work that uses the library". The |
|
| 111 |
+former contains code derived from the library, whereas the latter must |
|
| 112 |
+be combined with the library in order to run. |
|
| 113 |
+ |
|
| 114 |
+ GNU LESSER GENERAL PUBLIC LICENSE |
|
| 115 |
+ TERMS AND CONDITIONS FOR COPYING, DISTRIBUTION AND MODIFICATION |
|
| 116 |
+ |
|
| 117 |
+ 0. This License Agreement applies to any software library or other |
|
| 118 |
+program which contains a notice placed by the copyright holder or |
|
| 119 |
+other authorized party saying it may be distributed under the terms of |
|
| 120 |
+this Lesser General Public License (also called "this License"). |
|
| 121 |
+Each licensee is addressed as "you". |
|
| 122 |
+ |
|
| 123 |
+ A "library" means a collection of software functions and/or data |
|
| 124 |
+prepared so as to be conveniently linked with application programs |
|
| 125 |
+(which use some of those functions and data) to form executables. |
|
| 126 |
+ |
|
| 127 |
+ The "Library", below, refers to any such software library or work |
|
| 128 |
+which has been distributed under these terms. A "work based on the |
|
| 129 |
+Library" means either the Library or any derivative work under |
|
| 130 |
+copyright law: that is to say, a work containing the Library or a |
|
| 131 |
+portion of it, either verbatim or with modifications and/or translated |
|
| 132 |
+straightforwardly into another language. (Hereinafter, translation is |
|
| 133 |
+included without limitation in the term "modification".) |
|
| 134 |
+ |
|
| 135 |
+ "Source code" for a work means the preferred form of the work for |
|
| 136 |
+making modifications to it. For a library, complete source code means |
|
| 137 |
+all the source code for all modules it contains, plus any associated |
|
| 138 |
+interface definition files, plus the scripts used to control compilation |
|
| 139 |
+and installation of the library. |
|
| 140 |
+ |
|
| 141 |
+ Activities other than copying, distribution and modification are not |
|
| 142 |
+covered by this License; they are outside its scope. The act of |
|
| 143 |
+running a program using the Library is not restricted, and output from |
|
| 144 |
+such a program is covered only if its contents constitute a work based |
|
| 145 |
+on the Library (independent of the use of the Library in a tool for |
|
| 146 |
+writing it). Whether that is true depends on what the Library does |
|
| 147 |
+and what the program that uses the Library does. |
|
| 148 |
+ |
|
| 149 |
+ 1. You may copy and distribute verbatim copies of the Library's |
|
| 150 |
+complete source code as you receive it, in any medium, provided that |
|
| 151 |
+you conspicuously and appropriately publish on each copy an |
|
| 152 |
+appropriate copyright notice and disclaimer of warranty; keep intact |
|
| 153 |
+all the notices that refer to this License and to the absence of any |
|
| 154 |
+warranty; and distribute a copy of this License along with the |
|
| 155 |
+Library. |
|
| 156 |
+ |
|
| 157 |
+ You may charge a fee for the physical act of transferring a copy, |
|
| 158 |
+and you may at your option offer warranty protection in exchange for a |
|
| 159 |
+fee. |
|
| 160 |
+ |
|
| 161 |
+ 2. You may modify your copy or copies of the Library or any portion |
|
| 162 |
+of it, thus forming a work based on the Library, and copy and |
|
| 163 |
+distribute such modifications or work under the terms of Section 1 |
|
| 164 |
+above, provided that you also meet all of these conditions: |
|
| 165 |
+ |
|
| 166 |
+ a) The modified work must itself be a software library. |
|
| 167 |
+ |
|
| 168 |
+ b) You must cause the files modified to carry prominent notices |
|
| 169 |
+ stating that you changed the files and the date of any change. |
|
| 170 |
+ |
|
| 171 |
+ c) You must cause the whole of the work to be licensed at no |
|
| 172 |
+ charge to all third parties under the terms of this License. |
|
| 173 |
+ |
|
| 174 |
+ d) If a facility in the modified Library refers to a function or a |
|
| 175 |
+ table of data to be supplied by an application program that uses |
|
| 176 |
+ the facility, other than as an argument passed when the facility |
|
| 177 |
+ is invoked, then you must make a good faith effort to ensure that, |
|
| 178 |
+ in the event an application does not supply such function or |
|
| 179 |
+ table, the facility still operates, and performs whatever part of |
|
| 180 |
+ its purpose remains meaningful. |
|
| 181 |
+ |
|
| 182 |
+ (For example, a function in a library to compute square roots has |
|
| 183 |
+ a purpose that is entirely well-defined independent of the |
|
| 184 |
+ application. Therefore, Subsection 2d requires that any |
|
| 185 |
+ application-supplied function or table used by this function must |
|
| 186 |
+ be optional: if the application does not supply it, the square |
|
| 187 |
+ root function must still compute square roots.) |
|
| 188 |
+ |
|
| 189 |
+These requirements apply to the modified work as a whole. If |
|
| 190 |
+identifiable sections of that work are not derived from the Library, |
|
| 191 |
+and can be reasonably considered independent and separate works in |
|
| 192 |
+themselves, then this License, and its terms, do not apply to those |
|
| 193 |
+sections when you distribute them as separate works. But when you |
|
| 194 |
+distribute the same sections as part of a whole which is a work based |
|
| 195 |
+on the Library, the distribution of the whole must be on the terms of |
|
| 196 |
+this License, whose permissions for other licensees extend to the |
|
| 197 |
+entire whole, and thus to each and every part regardless of who wrote |
|
| 198 |
+it. |
|
| 199 |
+ |
|
| 200 |
+Thus, it is not the intent of this section to claim rights or contest |
|
| 201 |
+your rights to work written entirely by you; rather, the intent is to |
|
| 202 |
+exercise the right to control the distribution of derivative or |
|
| 203 |
+collective works based on the Library. |
|
| 204 |
+ |
|
| 205 |
+In addition, mere aggregation of another work not based on the Library |
|
| 206 |
+with the Library (or with a work based on the Library) on a volume of |
|
| 207 |
+a storage or distribution medium does not bring the other work under |
|
| 208 |
+the scope of this License. |
|
| 209 |
+ |
|
| 210 |
+ 3. You may opt to apply the terms of the ordinary GNU General Public |
|
| 211 |
+License instead of this License to a given copy of the Library. To do |
|
| 212 |
+this, you must alter all the notices that refer to this License, so |
|
| 213 |
+that they refer to the ordinary GNU General Public License, version 2, |
|
| 214 |
+instead of to this License. (If a newer version than version 2 of the |
|
| 215 |
+ordinary GNU General Public License has appeared, then you can specify |
|
| 216 |
+that version instead if you wish.) Do not make any other change in |
|
| 217 |
+these notices. |
|
| 218 |
+ |
|
| 219 |
+ Once this change is made in a given copy, it is irreversible for |
|
| 220 |
+that copy, so the ordinary GNU General Public License applies to all |
|
| 221 |
+subsequent copies and derivative works made from that copy. |
|
| 222 |
+ |
|
| 223 |
+ This option is useful when you wish to copy part of the code of |
|
| 224 |
+the Library into a program that is not a library. |
|
| 225 |
+ |
|
| 226 |
+ 4. You may copy and distribute the Library (or a portion or |
|
| 227 |
+derivative of it, under Section 2) in object code or executable form |
|
| 228 |
+under the terms of Sections 1 and 2 above provided that you accompany |
|
| 229 |
+it with the complete corresponding machine-readable source code, which |
|
| 230 |
+must be distributed under the terms of Sections 1 and 2 above on a |
|
| 231 |
+medium customarily used for software interchange. |
|
| 232 |
+ |
|
| 233 |
+ If distribution of object code is made by offering access to copy |
|
| 234 |
+from a designated place, then offering equivalent access to copy the |
|
| 235 |
+source code from the same place satisfies the requirement to |
|
| 236 |
+distribute the source code, even though third parties are not |
|
| 237 |
+compelled to copy the source along with the object code. |
|
| 238 |
+ |
|
| 239 |
+ 5. A program that contains no derivative of any portion of the |
|
| 240 |
+Library, but is designed to work with the Library by being compiled or |
|
| 241 |
+linked with it, is called a "work that uses the Library". Such a |
|
| 242 |
+work, in isolation, is not a derivative work of the Library, and |
|
| 243 |
+therefore falls outside the scope of this License. |
|
| 244 |
+ |
|
| 245 |
+ However, linking a "work that uses the Library" with the Library |
|
| 246 |
+creates an executable that is a derivative of the Library (because it |
|
| 247 |
+contains portions of the Library), rather than a "work that uses the |
|
| 248 |
+library". The executable is therefore covered by this License. |
|
| 249 |
+Section 6 states terms for distribution of such executables. |
|
| 250 |
+ |
|
| 251 |
+ When a "work that uses the Library" uses material from a header file |
|
| 252 |
+that is part of the Library, the object code for the work may be a |
|
| 253 |
+derivative work of the Library even though the source code is not. |
|
| 254 |
+Whether this is true is especially significant if the work can be |
|
| 255 |
+linked without the Library, or if the work is itself a library. The |
|
| 256 |
+threshold for this to be true is not precisely defined by law. |
|
| 257 |
+ |
|
| 258 |
+ If such an object file uses only numerical parameters, data |
|
| 259 |
+structure layouts and accessors, and small macros and small inline |
|
| 260 |
+functions (ten lines or less in length), then the use of the object |
|
| 261 |
+file is unrestricted, regardless of whether it is legally a derivative |
|
| 262 |
+work. (Executables containing this object code plus portions of the |
|
| 263 |
+Library will still fall under Section 6.) |
|
| 264 |
+ |
|
| 265 |
+ Otherwise, if the work is a derivative of the Library, you may |
|
| 266 |
+distribute the object code for the work under the terms of Section 6. |
|
| 267 |
+Any executables containing that work also fall under Section 6, |
|
| 268 |
+whether or not they are linked directly with the Library itself. |
|
| 269 |
+ |
|
| 270 |
+ 6. As an exception to the Sections above, you may also combine or |
|
| 271 |
+link a "work that uses the Library" with the Library to produce a |
|
| 272 |
+work containing portions of the Library, and distribute that work |
|
| 273 |
+under terms of your choice, provided that the terms permit |
|
| 274 |
+modification of the work for the customer's own use and reverse |
|
| 275 |
+engineering for debugging such modifications. |
|
| 276 |
+ |
|
| 277 |
+ You must give prominent notice with each copy of the work that the |
|
| 278 |
+Library is used in it and that the Library and its use are covered by |
|
| 279 |
+this License. You must supply a copy of this License. If the work |
|
| 280 |
+during execution displays copyright notices, you must include the |
|
| 281 |
+copyright notice for the Library among them, as well as a reference |
|
| 282 |
+directing the user to the copy of this License. Also, you must do one |
|
| 283 |
+of these things: |
|
| 284 |
+ |
|
| 285 |
+ a) Accompany the work with the complete corresponding |
|
| 286 |
+ machine-readable source code for the Library including whatever |
|
| 287 |
+ changes were used in the work (which must be distributed under |
|
| 288 |
+ Sections 1 and 2 above); and, if the work is an executable linked |
|
| 289 |
+ with the Library, with the complete machine-readable "work that |
|
| 290 |
+ uses the Library", as object code and/or source code, so that the |
|
| 291 |
+ user can modify the Library and then relink to produce a modified |
|
| 292 |
+ executable containing the modified Library. (It is understood |
|
| 293 |
+ that the user who changes the contents of definitions files in the |
|
| 294 |
+ Library will not necessarily be able to recompile the application |
|
| 295 |
+ to use the modified definitions.) |
|
| 296 |
+ |
|
| 297 |
+ b) Use a suitable shared library mechanism for linking with the |
|
| 298 |
+ Library. A suitable mechanism is one that (1) uses at run time a |
|
| 299 |
+ copy of the library already present on the user's computer system, |
|
| 300 |
+ rather than copying library functions into the executable, and (2) |
|
| 301 |
+ will operate properly with a modified version of the library, if |
|
| 302 |
+ the user installs one, as long as the modified version is |
|
| 303 |
+ interface-compatible with the version that the work was made with. |
|
| 304 |
+ |
|
| 305 |
+ c) Accompany the work with a written offer, valid for at |
|
| 306 |
+ least three years, to give the same user the materials |
|
| 307 |
+ specified in Subsection 6a, above, for a charge no more |
|
| 308 |
+ than the cost of performing this distribution. |
|
| 309 |
+ |
|
| 310 |
+ d) If distribution of the work is made by offering access to copy |
|
| 311 |
+ from a designated place, offer equivalent access to copy the above |
|
| 312 |
+ specified materials from the same place. |
|
| 313 |
+ |
|
| 314 |
+ e) Verify that the user has already received a copy of these |
|
| 315 |
+ materials or that you have already sent this user a copy. |
|
| 316 |
+ |
|
| 317 |
+ For an executable, the required form of the "work that uses the |
|
| 318 |
+Library" must include any data and utility programs needed for |
|
| 319 |
+reproducing the executable from it. However, as a special exception, |
|
| 320 |
+the materials to be distributed need not include anything that is |
|
| 321 |
+normally distributed (in either source or binary form) with the major |
|
| 322 |
+components (compiler, kernel, and so on) of the operating system on |
|
| 323 |
+which the executable runs, unless that component itself accompanies |
|
| 324 |
+the executable. |
|
| 325 |
+ |
|
| 326 |
+ It may happen that this requirement contradicts the license |
|
| 327 |
+restrictions of other proprietary libraries that do not normally |
|
| 328 |
+accompany the operating system. Such a contradiction means you cannot |
|
| 329 |
+use both them and the Library together in an executable that you |
|
| 330 |
+distribute. |
|
| 331 |
+ |
|
| 332 |
+ 7. You may place library facilities that are a work based on the |
|
| 333 |
+Library side-by-side in a single library together with other library |
|
| 334 |
+facilities not covered by this License, and distribute such a combined |
|
| 335 |
+library, provided that the separate distribution of the work based on |
|
| 336 |
+the Library and of the other library facilities is otherwise |
|
| 337 |
+permitted, and provided that you do these two things: |
|
| 338 |
+ |
|
| 339 |
+ a) Accompany the combined library with a copy of the same work |
|
| 340 |
+ based on the Library, uncombined with any other library |
|
| 341 |
+ facilities. This must be distributed under the terms of the |
|
| 342 |
+ Sections above. |
|
| 343 |
+ |
|
| 344 |
+ b) Give prominent notice with the combined library of the fact |
|
| 345 |
+ that part of it is a work based on the Library, and explaining |
|
| 346 |
+ where to find the accompanying uncombined form of the same work. |
|
| 347 |
+ |
|
| 348 |
+ 8. You may not copy, modify, sublicense, link with, or distribute |
|
| 349 |
+the Library except as expressly provided under this License. Any |
|
| 350 |
+attempt otherwise to copy, modify, sublicense, link with, or |
|
| 351 |
+distribute the Library is void, and will automatically terminate your |
|
| 352 |
+rights under this License. However, parties who have received copies, |
|
| 353 |
+or rights, from you under this License will not have their licenses |
|
| 354 |
+terminated so long as such parties remain in full compliance. |
|
| 355 |
+ |
|
| 356 |
+ 9. You are not required to accept this License, since you have not |
|
| 357 |
+signed it. However, nothing else grants you permission to modify or |
|
| 358 |
+distribute the Library or its derivative works. These actions are |
|
| 359 |
+prohibited by law if you do not accept this License. Therefore, by |
|
| 360 |
+modifying or distributing the Library (or any work based on the |
|
| 361 |
+Library), you indicate your acceptance of this License to do so, and |
|
| 362 |
+all its terms and conditions for copying, distributing or modifying |
|
| 363 |
+the Library or works based on it. |
|
| 364 |
+ |
|
| 365 |
+ 10. Each time you redistribute the Library (or any work based on the |
|
| 366 |
+Library), the recipient automatically receives a license from the |
|
| 367 |
+original licensor to copy, distribute, link with or modify the Library |
|
| 368 |
+subject to these terms and conditions. You may not impose any further |
|
| 369 |
+restrictions on the recipients' exercise of the rights granted herein. |
|
| 370 |
+You are not responsible for enforcing compliance by third parties with |
|
| 371 |
+this License. |
|
| 372 |
+ |
|
| 373 |
+ 11. If, as a consequence of a court judgment or allegation of patent |
|
| 374 |
+infringement or for any other reason (not limited to patent issues), |
|
| 375 |
+conditions are imposed on you (whether by court order, agreement or |
|
| 376 |
+otherwise) that contradict the conditions of this License, they do not |
|
| 377 |
+excuse you from the conditions of this License. If you cannot |
|
| 378 |
+distribute so as to satisfy simultaneously your obligations under this |
|
| 379 |
+License and any other pertinent obligations, then as a consequence you |
|
| 380 |
+may not distribute the Library at all. For example, if a patent |
|
| 381 |
+license would not permit royalty-free redistribution of the Library by |
|
| 382 |
+all those who receive copies directly or indirectly through you, then |
|
| 383 |
+the only way you could satisfy both it and this License would be to |
|
| 384 |
+refrain entirely from distribution of the Library. |
|
| 385 |
+ |
|
| 386 |
+If any portion of this section is held invalid or unenforceable under any |
|
| 387 |
+particular circumstance, the balance of the section is intended to apply, |
|
| 388 |
+and the section as a whole is intended to apply in other circumstances. |
|
| 389 |
+ |
|
| 390 |
+It is not the purpose of this section to induce you to infringe any |
|
| 391 |
+patents or other property right claims or to contest validity of any |
|
| 392 |
+such claims; this section has the sole purpose of protecting the |
|
| 393 |
+integrity of the free software distribution system which is |
|
| 394 |
+implemented by public license practices. Many people have made |
|
| 395 |
+generous contributions to the wide range of software distributed |
|
| 396 |
+through that system in reliance on consistent application of that |
|
| 397 |
+system; it is up to the author/donor to decide if he or she is willing |
|
| 398 |
+to distribute software through any other system and a licensee cannot |
|
| 399 |
+impose that choice. |
|
| 400 |
+ |
|
| 401 |
+This section is intended to make thoroughly clear what is believed to |
|
| 402 |
+be a consequence of the rest of this License. |
|
| 403 |
+ |
|
| 404 |
+ 12. If the distribution and/or use of the Library is restricted in |
|
| 405 |
+certain countries either by patents or by copyrighted interfaces, the |
|
| 406 |
+original copyright holder who places the Library under this License may add |
|
| 407 |
+an explicit geographical distribution limitation excluding those countries, |
|
| 408 |
+so that distribution is permitted only in or among countries not thus |
|
| 409 |
+excluded. In such case, this License incorporates the limitation as if |
|
| 410 |
+written in the body of this License. |
|
| 411 |
+ |
|
| 412 |
+ 13. The Free Software Foundation may publish revised and/or new |
|
| 413 |
+versions of the Lesser General Public License from time to time. |
|
| 414 |
+Such new versions will be similar in spirit to the present version, |
|
| 415 |
+but may differ in detail to address new problems or concerns. |
|
| 416 |
+ |
|
| 417 |
+Each version is given a distinguishing version number. If the Library |
|
| 418 |
+specifies a version number of this License which applies to it and |
|
| 419 |
+"any later version", you have the option of following the terms and |
|
| 420 |
+conditions either of that version or of any later version published by |
|
| 421 |
+the Free Software Foundation. If the Library does not specify a |
|
| 422 |
+license version number, you may choose any version ever published by |
|
| 423 |
+the Free Software Foundation. |
|
| 424 |
+ |
|
| 425 |
+ 14. If you wish to incorporate parts of the Library into other free |
|
| 426 |
+programs whose distribution conditions are incompatible with these, |
|
| 427 |
+write to the author to ask for permission. For software which is |
|
| 428 |
+copyrighted by the Free Software Foundation, write to the Free |
|
| 429 |
+Software Foundation; we sometimes make exceptions for this. Our |
|
| 430 |
+decision will be guided by the two goals of preserving the free status |
|
| 431 |
+of all derivatives of our free software and of promoting the sharing |
|
| 432 |
+and reuse of software generally. |
|
| 433 |
+ |
|
| 434 |
+ NO WARRANTY |
|
| 435 |
+ |
|
| 436 |
+ 15. BECAUSE THE LIBRARY IS LICENSED FREE OF CHARGE, THERE IS NO |
|
| 437 |
+WARRANTY FOR THE LIBRARY, TO THE EXTENT PERMITTED BY APPLICABLE LAW. |
|
| 438 |
+EXCEPT WHEN OTHERWISE STATED IN WRITING THE COPYRIGHT HOLDERS AND/OR |
|
| 439 |
+OTHER PARTIES PROVIDE THE LIBRARY "AS IS" WITHOUT WARRANTY OF ANY |
|
| 440 |
+KIND, EITHER EXPRESSED OR IMPLIED, INCLUDING, BUT NOT LIMITED TO, THE |
|
| 441 |
+IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR |
|
| 442 |
+PURPOSE. THE ENTIRE RISK AS TO THE QUALITY AND PERFORMANCE OF THE |
|
| 443 |
+LIBRARY IS WITH YOU. SHOULD THE LIBRARY PROVE DEFECTIVE, YOU ASSUME |
|
| 444 |
+THE COST OF ALL NECESSARY SERVICING, REPAIR OR CORRECTION. |
|
| 445 |
+ |
|
| 446 |
+ 16. IN NO EVENT UNLESS REQUIRED BY APPLICABLE LAW OR AGREED TO IN |
|
| 447 |
+WRITING WILL ANY COPYRIGHT HOLDER, OR ANY OTHER PARTY WHO MAY MODIFY |
|
| 448 |
+AND/OR REDISTRIBUTE THE LIBRARY AS PERMITTED ABOVE, BE LIABLE TO YOU |
|
| 449 |
+FOR DAMAGES, INCLUDING ANY GENERAL, SPECIAL, INCIDENTAL OR |
|
| 450 |
+CONSEQUENTIAL DAMAGES ARISING OUT OF THE USE OR INABILITY TO USE THE |
|
| 451 |
+LIBRARY (INCLUDING BUT NOT LIMITED TO LOSS OF DATA OR DATA BEING |
|
| 452 |
+RENDERED INACCURATE OR LOSSES SUSTAINED BY YOU OR THIRD PARTIES OR A |
|
| 453 |
+FAILURE OF THE LIBRARY TO OPERATE WITH ANY OTHER SOFTWARE), EVEN IF |
|
| 454 |
+SUCH HOLDER OR OTHER PARTY HAS BEEN ADVISED OF THE POSSIBILITY OF SUCH |
|
| 455 |
+DAMAGES. |
|
| 456 |
+ |
|
| 457 |
+ END OF TERMS AND CONDITIONS |
|
| 458 |
+ |
|
| 459 |
+ How to Apply These Terms to Your New Libraries |
|
| 460 |
+ |
|
| 461 |
+ If you develop a new library, and you want it to be of the greatest |
|
| 462 |
+possible use to the public, we recommend making it free software that |
|
| 463 |
+everyone can redistribute and change. You can do so by permitting |
|
| 464 |
+redistribution under these terms (or, alternatively, under the terms of the |
|
| 465 |
+ordinary General Public License). |
|
| 466 |
+ |
|
| 467 |
+ To apply these terms, attach the following notices to the library. It is |
|
| 468 |
+safest to attach them to the start of each source file to most effectively |
|
| 469 |
+convey the exclusion of warranty; and each file should have at least the |
|
| 470 |
+"copyright" line and a pointer to where the full notice is found. |
|
| 471 |
+ |
|
| 472 |
+ <one line to give the library's name and a brief idea of what it does.> |
|
| 473 |
+ Copyright (C) <year> <name of author> |
|
| 474 |
+ |
|
| 475 |
+ This library is free software; you can redistribute it and/or |
|
| 476 |
+ modify it under the terms of the GNU Lesser General Public |
|
| 477 |
+ License as published by the Free Software Foundation; either |
|
| 478 |
+ version 2.1 of the License, or (at your option) any later version. |
|
| 479 |
+ |
|
| 480 |
+ This library is distributed in the hope that it will be useful, |
|
| 481 |
+ but WITHOUT ANY WARRANTY; without even the implied warranty of |
|
| 482 |
+ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU |
|
| 483 |
+ Lesser General Public License for more details. |
|
| 484 |
+ |
|
| 485 |
+ You should have received a copy of the GNU Lesser General Public |
|
| 486 |
+ License along with this library; if not, write to the Free Software |
|
| 487 |
+ Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA |
|
| 488 |
+ |
|
| 489 |
+Also add information on how to contact you by electronic and paper mail. |
|
| 490 |
+ |
|
| 491 |
+You should also get your employer (if you work as a programmer) or your |
|
| 492 |
+school, if any, to sign a "copyright disclaimer" for the library, if |
|
| 493 |
+necessary. Here is a sample; alter the names: |
|
| 494 |
+ |
|
| 495 |
+ Yoyodyne, Inc., hereby disclaims all copyright interest in the |
|
| 496 |
+ library `Frob' (a library for tweaking knobs) written by James Random Hacker. |
|
| 497 |
+ |
|
| 498 |
+ <signature of Ty Coon>, 1 April 1990 |
|
| 499 |
+ Ty Coon, President of Vice |
|
| 500 |
+ |
|
| 501 |
+That's all there is to it! |
| 0 | 502 |
new file mode 100644 |
| ... | ... |
@@ -0,0 +1,16 @@ |
| 0 |
+TARGETS?=docker |
|
| 1 |
+MODULES?=${TARGETS:=.pp.bz2}
|
|
| 2 |
+SHAREDIR?=/usr/share |
|
| 3 |
+ |
|
| 4 |
+all: ${TARGETS:=.pp.bz2}
|
|
| 5 |
+ |
|
| 6 |
+%.pp.bz2: %.pp |
|
| 7 |
+ @echo Compressing $^ -\> $@ |
|
| 8 |
+ bzip2 -9 $^ |
|
| 9 |
+ |
|
| 10 |
+%.pp: %.te |
|
| 11 |
+ make -f ${SHAREDIR}/selinux/devel/Makefile $@
|
|
| 12 |
+ |
|
| 13 |
+clean: |
|
| 14 |
+ rm -f *~ *.tc *.pp *.pp.bz2 |
|
| 15 |
+ rm -rf tmp *.tar.gz |
| 0 | 16 |
new file mode 100644 |
| ... | ... |
@@ -0,0 +1,24 @@ |
| 0 |
+/root/\.docker gen_context(system_u:object_r:docker_home_t,s0) |
|
| 1 |
+ |
|
| 2 |
+/usr/bin/docker -- gen_context(system_u:object_r:docker_exec_t,s0) |
|
| 3 |
+ |
|
| 4 |
+/usr/lib/systemd/system/docker.service -- gen_context(system_u:object_r:docker_unit_file_t,s0) |
|
| 5 |
+ |
|
| 6 |
+/etc/docker(/.*)? gen_context(system_u:object_r:docker_config_t,s0) |
|
| 7 |
+ |
|
| 8 |
+/var/lib/docker(/.*)? gen_context(system_u:object_r:docker_var_lib_t,s0) |
|
| 9 |
+/var/lib/kublet(/.*)? gen_context(system_u:object_r:docker_var_lib_t,s0) |
|
| 10 |
+/var/lib/docker/vfs(/.*)? gen_context(system_u:object_r:svirt_sandbox_file_t,s0) |
|
| 11 |
+ |
|
| 12 |
+/var/run/docker\.pid -- gen_context(system_u:object_r:docker_var_run_t,s0) |
|
| 13 |
+/var/run/docker\.sock -s gen_context(system_u:object_r:docker_var_run_t,s0) |
|
| 14 |
+/var/run/docker-client(/.*)? gen_context(system_u:object_r:docker_var_run_t,s0) |
|
| 15 |
+ |
|
| 16 |
+/var/lock/lxc(/.*)? gen_context(system_u:object_r:docker_lock_t,s0) |
|
| 17 |
+ |
|
| 18 |
+/var/log/lxc(/.*)? gen_context(system_u:object_r:docker_log_t,s0) |
|
| 19 |
+ |
|
| 20 |
+/var/lib/docker/init(/.*)? gen_context(system_u:object_r:docker_share_t,s0) |
|
| 21 |
+/var/lib/docker/containers/.*/hosts gen_context(system_u:object_r:docker_share_t,s0) |
|
| 22 |
+/var/lib/docker/containers/.*/hostname gen_context(system_u:object_r:docker_share_t,s0) |
|
| 23 |
+/var/lib/docker/.*/config\.env gen_context(system_u:object_r:docker_share_t,s0) |
| 0 | 24 |
new file mode 100644 |
| ... | ... |
@@ -0,0 +1,467 @@ |
| 0 |
+ |
|
| 1 |
+## <summary>The open-source application container engine.</summary> |
|
| 2 |
+ |
|
| 3 |
+######################################## |
|
| 4 |
+## <summary> |
|
| 5 |
+## Execute docker in the docker domain. |
|
| 6 |
+## </summary> |
|
| 7 |
+## <param name="domain"> |
|
| 8 |
+## <summary> |
|
| 9 |
+## Domain allowed to transition. |
|
| 10 |
+## </summary> |
|
| 11 |
+## </param> |
|
| 12 |
+# |
|
| 13 |
+interface(`docker_domtrans',` |
|
| 14 |
+ gen_require(` |
|
| 15 |
+ type docker_t, docker_exec_t; |
|
| 16 |
+ ') |
|
| 17 |
+ |
|
| 18 |
+ corecmd_search_bin($1) |
|
| 19 |
+ domtrans_pattern($1, docker_exec_t, docker_t) |
|
| 20 |
+') |
|
| 21 |
+ |
|
| 22 |
+######################################## |
|
| 23 |
+## <summary> |
|
| 24 |
+## Execute docker in the caller domain. |
|
| 25 |
+## </summary> |
|
| 26 |
+## <param name="domain"> |
|
| 27 |
+## <summary> |
|
| 28 |
+## Domain allowed to transition. |
|
| 29 |
+## </summary> |
|
| 30 |
+## </param> |
|
| 31 |
+# |
|
| 32 |
+interface(`docker_exec',` |
|
| 33 |
+ gen_require(` |
|
| 34 |
+ type docker_exec_t; |
|
| 35 |
+ ') |
|
| 36 |
+ |
|
| 37 |
+ corecmd_search_bin($1) |
|
| 38 |
+ can_exec($1, docker_exec_t) |
|
| 39 |
+') |
|
| 40 |
+ |
|
| 41 |
+######################################## |
|
| 42 |
+## <summary> |
|
| 43 |
+## Search docker lib directories. |
|
| 44 |
+## </summary> |
|
| 45 |
+## <param name="domain"> |
|
| 46 |
+## <summary> |
|
| 47 |
+## Domain allowed access. |
|
| 48 |
+## </summary> |
|
| 49 |
+## </param> |
|
| 50 |
+# |
|
| 51 |
+interface(`docker_search_lib',` |
|
| 52 |
+ gen_require(` |
|
| 53 |
+ type docker_var_lib_t; |
|
| 54 |
+ ') |
|
| 55 |
+ |
|
| 56 |
+ allow $1 docker_var_lib_t:dir search_dir_perms; |
|
| 57 |
+ files_search_var_lib($1) |
|
| 58 |
+') |
|
| 59 |
+ |
|
| 60 |
+######################################## |
|
| 61 |
+## <summary> |
|
| 62 |
+## Execute docker lib directories. |
|
| 63 |
+## </summary> |
|
| 64 |
+## <param name="domain"> |
|
| 65 |
+## <summary> |
|
| 66 |
+## Domain allowed access. |
|
| 67 |
+## </summary> |
|
| 68 |
+## </param> |
|
| 69 |
+# |
|
| 70 |
+interface(`docker_exec_lib',` |
|
| 71 |
+ gen_require(` |
|
| 72 |
+ type docker_var_lib_t; |
|
| 73 |
+ ') |
|
| 74 |
+ |
|
| 75 |
+ allow $1 docker_var_lib_t:dir search_dir_perms; |
|
| 76 |
+ can_exec($1, docker_var_lib_t) |
|
| 77 |
+') |
|
| 78 |
+ |
|
| 79 |
+######################################## |
|
| 80 |
+## <summary> |
|
| 81 |
+## Read docker lib files. |
|
| 82 |
+## </summary> |
|
| 83 |
+## <param name="domain"> |
|
| 84 |
+## <summary> |
|
| 85 |
+## Domain allowed access. |
|
| 86 |
+## </summary> |
|
| 87 |
+## </param> |
|
| 88 |
+# |
|
| 89 |
+interface(`docker_read_lib_files',` |
|
| 90 |
+ gen_require(` |
|
| 91 |
+ type docker_var_lib_t; |
|
| 92 |
+ ') |
|
| 93 |
+ |
|
| 94 |
+ files_search_var_lib($1) |
|
| 95 |
+ read_files_pattern($1, docker_var_lib_t, docker_var_lib_t) |
|
| 96 |
+') |
|
| 97 |
+ |
|
| 98 |
+######################################## |
|
| 99 |
+## <summary> |
|
| 100 |
+## Read docker share files. |
|
| 101 |
+## </summary> |
|
| 102 |
+## <param name="domain"> |
|
| 103 |
+## <summary> |
|
| 104 |
+## Domain allowed access. |
|
| 105 |
+## </summary> |
|
| 106 |
+## </param> |
|
| 107 |
+# |
|
| 108 |
+interface(`docker_read_share_files',` |
|
| 109 |
+ gen_require(` |
|
| 110 |
+ type docker_share_t; |
|
| 111 |
+ ') |
|
| 112 |
+ |
|
| 113 |
+ files_search_var_lib($1) |
|
| 114 |
+ read_files_pattern($1, docker_share_t, docker_share_t) |
|
| 115 |
+') |
|
| 116 |
+ |
|
| 117 |
+######################################## |
|
| 118 |
+## <summary> |
|
| 119 |
+## Manage docker lib files. |
|
| 120 |
+## </summary> |
|
| 121 |
+## <param name="domain"> |
|
| 122 |
+## <summary> |
|
| 123 |
+## Domain allowed access. |
|
| 124 |
+## </summary> |
|
| 125 |
+## </param> |
|
| 126 |
+# |
|
| 127 |
+interface(`docker_manage_lib_files',` |
|
| 128 |
+ gen_require(` |
|
| 129 |
+ type docker_var_lib_t; |
|
| 130 |
+ ') |
|
| 131 |
+ |
|
| 132 |
+ files_search_var_lib($1) |
|
| 133 |
+ manage_files_pattern($1, docker_var_lib_t, docker_var_lib_t) |
|
| 134 |
+ manage_lnk_files_pattern($1, docker_var_lib_t, docker_var_lib_t) |
|
| 135 |
+') |
|
| 136 |
+ |
|
| 137 |
+######################################## |
|
| 138 |
+## <summary> |
|
| 139 |
+## Manage docker lib directories. |
|
| 140 |
+## </summary> |
|
| 141 |
+## <param name="domain"> |
|
| 142 |
+## <summary> |
|
| 143 |
+## Domain allowed access. |
|
| 144 |
+## </summary> |
|
| 145 |
+## </param> |
|
| 146 |
+# |
|
| 147 |
+interface(`docker_manage_lib_dirs',` |
|
| 148 |
+ gen_require(` |
|
| 149 |
+ type docker_var_lib_t; |
|
| 150 |
+ ') |
|
| 151 |
+ |
|
| 152 |
+ files_search_var_lib($1) |
|
| 153 |
+ manage_dirs_pattern($1, docker_var_lib_t, docker_var_lib_t) |
|
| 154 |
+') |
|
| 155 |
+ |
|
| 156 |
+######################################## |
|
| 157 |
+## <summary> |
|
| 158 |
+## Create objects in a docker var lib directory |
|
| 159 |
+## with an automatic type transition to |
|
| 160 |
+## a specified private type. |
|
| 161 |
+## </summary> |
|
| 162 |
+## <param name="domain"> |
|
| 163 |
+## <summary> |
|
| 164 |
+## Domain allowed access. |
|
| 165 |
+## </summary> |
|
| 166 |
+## </param> |
|
| 167 |
+## <param name="private_type"> |
|
| 168 |
+## <summary> |
|
| 169 |
+## The type of the object to create. |
|
| 170 |
+## </summary> |
|
| 171 |
+## </param> |
|
| 172 |
+## <param name="object_class"> |
|
| 173 |
+## <summary> |
|
| 174 |
+## The class of the object to be created. |
|
| 175 |
+## </summary> |
|
| 176 |
+## </param> |
|
| 177 |
+## <param name="name" optional="true"> |
|
| 178 |
+## <summary> |
|
| 179 |
+## The name of the object being created. |
|
| 180 |
+## </summary> |
|
| 181 |
+## </param> |
|
| 182 |
+# |
|
| 183 |
+interface(`docker_lib_filetrans',` |
|
| 184 |
+ gen_require(` |
|
| 185 |
+ type docker_var_lib_t; |
|
| 186 |
+ ') |
|
| 187 |
+ |
|
| 188 |
+ filetrans_pattern($1, docker_var_lib_t, $2, $3, $4) |
|
| 189 |
+') |
|
| 190 |
+ |
|
| 191 |
+######################################## |
|
| 192 |
+## <summary> |
|
| 193 |
+## Read docker PID files. |
|
| 194 |
+## </summary> |
|
| 195 |
+## <param name="domain"> |
|
| 196 |
+## <summary> |
|
| 197 |
+## Domain allowed access. |
|
| 198 |
+## </summary> |
|
| 199 |
+## </param> |
|
| 200 |
+# |
|
| 201 |
+interface(`docker_read_pid_files',` |
|
| 202 |
+ gen_require(` |
|
| 203 |
+ type docker_var_run_t; |
|
| 204 |
+ ') |
|
| 205 |
+ |
|
| 206 |
+ files_search_pids($1) |
|
| 207 |
+ read_files_pattern($1, docker_var_run_t, docker_var_run_t) |
|
| 208 |
+') |
|
| 209 |
+ |
|
| 210 |
+######################################## |
|
| 211 |
+## <summary> |
|
| 212 |
+## Execute docker server in the docker domain. |
|
| 213 |
+## </summary> |
|
| 214 |
+## <param name="domain"> |
|
| 215 |
+## <summary> |
|
| 216 |
+## Domain allowed to transition. |
|
| 217 |
+## </summary> |
|
| 218 |
+## </param> |
|
| 219 |
+# |
|
| 220 |
+interface(`docker_systemctl',` |
|
| 221 |
+ gen_require(` |
|
| 222 |
+ type docker_t; |
|
| 223 |
+ type docker_unit_file_t; |
|
| 224 |
+ ') |
|
| 225 |
+ |
|
| 226 |
+ systemd_exec_systemctl($1) |
|
| 227 |
+ init_reload_services($1) |
|
| 228 |
+ systemd_read_fifo_file_passwd_run($1) |
|
| 229 |
+ allow $1 docker_unit_file_t:file read_file_perms; |
|
| 230 |
+ allow $1 docker_unit_file_t:service manage_service_perms; |
|
| 231 |
+ |
|
| 232 |
+ ps_process_pattern($1, docker_t) |
|
| 233 |
+') |
|
| 234 |
+ |
|
| 235 |
+######################################## |
|
| 236 |
+## <summary> |
|
| 237 |
+## Read and write docker shared memory. |
|
| 238 |
+## </summary> |
|
| 239 |
+## <param name="domain"> |
|
| 240 |
+## <summary> |
|
| 241 |
+## Domain allowed access. |
|
| 242 |
+## </summary> |
|
| 243 |
+## </param> |
|
| 244 |
+# |
|
| 245 |
+interface(`docker_rw_sem',` |
|
| 246 |
+ gen_require(` |
|
| 247 |
+ type docker_t; |
|
| 248 |
+ ') |
|
| 249 |
+ |
|
| 250 |
+ allow $1 docker_t:sem rw_sem_perms; |
|
| 251 |
+') |
|
| 252 |
+ |
|
| 253 |
+####################################### |
|
| 254 |
+## <summary> |
|
| 255 |
+## Read and write the docker pty type. |
|
| 256 |
+## </summary> |
|
| 257 |
+## <param name="domain"> |
|
| 258 |
+## <summary> |
|
| 259 |
+## Domain allowed access. |
|
| 260 |
+## </summary> |
|
| 261 |
+## </param> |
|
| 262 |
+# |
|
| 263 |
+interface(`docker_use_ptys',` |
|
| 264 |
+ gen_require(` |
|
| 265 |
+ type docker_devpts_t; |
|
| 266 |
+ ') |
|
| 267 |
+ |
|
| 268 |
+ allow $1 docker_devpts_t:chr_file rw_term_perms; |
|
| 269 |
+') |
|
| 270 |
+ |
|
| 271 |
+####################################### |
|
| 272 |
+## <summary> |
|
| 273 |
+## Allow domain to create docker content |
|
| 274 |
+## </summary> |
|
| 275 |
+## <param name="domain"> |
|
| 276 |
+## <summary> |
|
| 277 |
+## Domain allowed access. |
|
| 278 |
+## </summary> |
|
| 279 |
+## </param> |
|
| 280 |
+# |
|
| 281 |
+interface(`docker_filetrans_named_content',` |
|
| 282 |
+ |
|
| 283 |
+ gen_require(` |
|
| 284 |
+ type docker_var_lib_t; |
|
| 285 |
+ type docker_share_t; |
|
| 286 |
+ type docker_log_t; |
|
| 287 |
+ type docker_var_run_t; |
|
| 288 |
+ type docker_home_t; |
|
| 289 |
+ ') |
|
| 290 |
+ |
|
| 291 |
+ files_pid_filetrans($1, docker_var_run_t, file, "docker.pid") |
|
| 292 |
+ files_pid_filetrans($1, docker_var_run_t, sock_file, "docker.sock") |
|
| 293 |
+ files_pid_filetrans($1, docker_var_run_t, dir, "docker-client") |
|
| 294 |
+ logging_log_filetrans($1, docker_log_t, dir, "lxc") |
|
| 295 |
+ files_var_lib_filetrans($1, docker_var_lib_t, dir, "docker") |
|
| 296 |
+ filetrans_pattern($1, docker_var_lib_t, docker_share_t, file, "config.env") |
|
| 297 |
+ filetrans_pattern($1, docker_var_lib_t, docker_share_t, file, "hosts") |
|
| 298 |
+ filetrans_pattern($1, docker_var_lib_t, docker_share_t, file, "hostname") |
|
| 299 |
+ filetrans_pattern($1, docker_var_lib_t, docker_share_t, file, "resolv.conf") |
|
| 300 |
+ filetrans_pattern($1, docker_var_lib_t, docker_share_t, dir, "init") |
|
| 301 |
+ userdom_admin_home_dir_filetrans($1, docker_home_t, dir, ".docker") |
|
| 302 |
+') |
|
| 303 |
+ |
|
| 304 |
+######################################## |
|
| 305 |
+## <summary> |
|
| 306 |
+## Connect to docker over a unix stream socket. |
|
| 307 |
+## </summary> |
|
| 308 |
+## <param name="domain"> |
|
| 309 |
+## <summary> |
|
| 310 |
+## Domain allowed access. |
|
| 311 |
+## </summary> |
|
| 312 |
+## </param> |
|
| 313 |
+# |
|
| 314 |
+interface(`docker_stream_connect',` |
|
| 315 |
+ gen_require(` |
|
| 316 |
+ type docker_t, docker_var_run_t; |
|
| 317 |
+ ') |
|
| 318 |
+ |
|
| 319 |
+ files_search_pids($1) |
|
| 320 |
+ stream_connect_pattern($1, docker_var_run_t, docker_var_run_t, docker_t) |
|
| 321 |
+') |
|
| 322 |
+ |
|
| 323 |
+######################################## |
|
| 324 |
+## <summary> |
|
| 325 |
+## Connect to SPC containers over a unix stream socket. |
|
| 326 |
+## </summary> |
|
| 327 |
+## <param name="domain"> |
|
| 328 |
+## <summary> |
|
| 329 |
+## Domain allowed access. |
|
| 330 |
+## </summary> |
|
| 331 |
+## </param> |
|
| 332 |
+# |
|
| 333 |
+interface(`docker_spc_stream_connect',` |
|
| 334 |
+ gen_require(` |
|
| 335 |
+ type spc_t, spc_var_run_t; |
|
| 336 |
+ ') |
|
| 337 |
+ |
|
| 338 |
+ files_search_pids($1) |
|
| 339 |
+ files_write_all_pid_sockets($1) |
|
| 340 |
+ allow $1 spc_t:unix_stream_socket connectto; |
|
| 341 |
+') |
|
| 342 |
+ |
|
| 343 |
+ |
|
| 344 |
+######################################## |
|
| 345 |
+## <summary> |
|
| 346 |
+## All of the rules required to administrate |
|
| 347 |
+## an docker environment |
|
| 348 |
+## </summary> |
|
| 349 |
+## <param name="domain"> |
|
| 350 |
+## <summary> |
|
| 351 |
+## Domain allowed access. |
|
| 352 |
+## </summary> |
|
| 353 |
+## </param> |
|
| 354 |
+# |
|
| 355 |
+interface(`docker_admin',` |
|
| 356 |
+ gen_require(` |
|
| 357 |
+ type docker_t; |
|
| 358 |
+ type docker_var_lib_t, docker_var_run_t; |
|
| 359 |
+ type docker_unit_file_t; |
|
| 360 |
+ type docker_lock_t; |
|
| 361 |
+ type docker_log_t; |
|
| 362 |
+ type docker_config_t; |
|
| 363 |
+ ') |
|
| 364 |
+ |
|
| 365 |
+ allow $1 docker_t:process { ptrace signal_perms };
|
|
| 366 |
+ ps_process_pattern($1, docker_t) |
|
| 367 |
+ |
|
| 368 |
+ admin_pattern($1, docker_config_t) |
|
| 369 |
+ |
|
| 370 |
+ files_search_var_lib($1) |
|
| 371 |
+ admin_pattern($1, docker_var_lib_t) |
|
| 372 |
+ |
|
| 373 |
+ files_search_pids($1) |
|
| 374 |
+ admin_pattern($1, docker_var_run_t) |
|
| 375 |
+ |
|
| 376 |
+ files_search_locks($1) |
|
| 377 |
+ admin_pattern($1, docker_lock_t) |
|
| 378 |
+ |
|
| 379 |
+ logging_search_logs($1) |
|
| 380 |
+ admin_pattern($1, docker_log_t) |
|
| 381 |
+ |
|
| 382 |
+ docker_systemctl($1) |
|
| 383 |
+ admin_pattern($1, docker_unit_file_t) |
|
| 384 |
+ allow $1 docker_unit_file_t:service all_service_perms; |
|
| 385 |
+ |
|
| 386 |
+ optional_policy(` |
|
| 387 |
+ systemd_passwd_agent_exec($1) |
|
| 388 |
+ systemd_read_fifo_file_passwd_run($1) |
|
| 389 |
+ ') |
|
| 390 |
+') |
|
| 391 |
+ |
|
| 392 |
+interface(`domain_stub_named_filetrans_domain',` |
|
| 393 |
+ gen_require(` |
|
| 394 |
+ attribute named_filetrans_domain; |
|
| 395 |
+ ') |
|
| 396 |
+') |
|
| 397 |
+ |
|
| 398 |
+interface(`lvm_stub',` |
|
| 399 |
+ gen_require(` |
|
| 400 |
+ type lvm_t; |
|
| 401 |
+ ') |
|
| 402 |
+') |
|
| 403 |
+interface(`staff_stub',` |
|
| 404 |
+ gen_require(` |
|
| 405 |
+ type staff_t; |
|
| 406 |
+ ') |
|
| 407 |
+') |
|
| 408 |
+interface(`virt_stub_lxc',` |
|
| 409 |
+ gen_require(` |
|
| 410 |
+ type virtd_lxc_t; |
|
| 411 |
+ ') |
|
| 412 |
+') |
|
| 413 |
+interface(`virt_stub_svirt_sandbox_domain',` |
|
| 414 |
+ gen_require(` |
|
| 415 |
+ attribute svirt_sandbox_domain; |
|
| 416 |
+ ') |
|
| 417 |
+') |
|
| 418 |
+interface(`virt_stub_svirt_sandbox_file',` |
|
| 419 |
+ gen_require(` |
|
| 420 |
+ type svirt_sandbox_file_t; |
|
| 421 |
+ ') |
|
| 422 |
+') |
|
| 423 |
+interface(`fs_dontaudit_remount_tmpfs',` |
|
| 424 |
+ gen_require(` |
|
| 425 |
+ type tmpfs_t; |
|
| 426 |
+ ') |
|
| 427 |
+ |
|
| 428 |
+ dontaudit $1 tmpfs_t:filesystem remount; |
|
| 429 |
+') |
|
| 430 |
+interface(`dev_dontaudit_list_all_dev_nodes',` |
|
| 431 |
+ gen_require(` |
|
| 432 |
+ type device_t; |
|
| 433 |
+ ') |
|
| 434 |
+ |
|
| 435 |
+ dontaudit $1 device_t:dir list_dir_perms; |
|
| 436 |
+') |
|
| 437 |
+interface(`kernel_unlabeled_entry_type',` |
|
| 438 |
+ gen_require(` |
|
| 439 |
+ type unlabeled_t; |
|
| 440 |
+ ') |
|
| 441 |
+ |
|
| 442 |
+ domain_entry_file($1, unlabeled_t) |
|
| 443 |
+') |
|
| 444 |
+interface(`kernel_unlabeled_domtrans',` |
|
| 445 |
+ gen_require(` |
|
| 446 |
+ type unlabeled_t; |
|
| 447 |
+ ') |
|
| 448 |
+ |
|
| 449 |
+ read_lnk_files_pattern($1, unlabeled_t, unlabeled_t) |
|
| 450 |
+ domain_transition_pattern($1, unlabeled_t, $2) |
|
| 451 |
+ type_transition $1 unlabeled_t:process $2; |
|
| 452 |
+') |
|
| 453 |
+interface(`files_write_all_pid_sockets',` |
|
| 454 |
+ gen_require(` |
|
| 455 |
+ attribute pidfile; |
|
| 456 |
+ ') |
|
| 457 |
+ |
|
| 458 |
+ allow $1 pidfile:sock_file write_sock_file_perms; |
|
| 459 |
+') |
|
| 460 |
+interface(`dev_dontaudit_mounton_sysfs',` |
|
| 461 |
+ gen_require(` |
|
| 462 |
+ type sysfs_t; |
|
| 463 |
+ ') |
|
| 464 |
+ |
|
| 465 |
+ dontaudit $1 sysfs_t:dir mounton; |
|
| 466 |
+') |
| 0 | 467 |
new file mode 100644 |
| ... | ... |
@@ -0,0 +1,418 @@ |
| 0 |
+policy_module(docker, 1.0.0) |
|
| 1 |
+ |
|
| 2 |
+######################################## |
|
| 3 |
+# |
|
| 4 |
+# Declarations |
|
| 5 |
+# |
|
| 6 |
+ |
|
| 7 |
+## <desc> |
|
| 8 |
+## <p> |
|
| 9 |
+## Allow sandbox containers manage fuse files |
|
| 10 |
+## </p> |
|
| 11 |
+## </desc> |
|
| 12 |
+gen_tunable(virt_sandbox_use_fusefs, false) |
|
| 13 |
+ |
|
| 14 |
+## <desc> |
|
| 15 |
+## <p> |
|
| 16 |
+## Determine whether docker can |
|
| 17 |
+## connect to all TCP ports. |
|
| 18 |
+## </p> |
|
| 19 |
+## </desc> |
|
| 20 |
+gen_tunable(docker_connect_any, false) |
|
| 21 |
+ |
|
| 22 |
+type docker_t; |
|
| 23 |
+type docker_exec_t; |
|
| 24 |
+init_daemon_domain(docker_t, docker_exec_t) |
|
| 25 |
+domain_subj_id_change_exemption(docker_t) |
|
| 26 |
+domain_role_change_exemption(docker_t) |
|
| 27 |
+ |
|
| 28 |
+type spc_t; |
|
| 29 |
+domain_type(spc_t) |
|
| 30 |
+role system_r types spc_t; |
|
| 31 |
+ |
|
| 32 |
+type spc_var_run_t; |
|
| 33 |
+files_pid_file(spc_var_run_t) |
|
| 34 |
+ |
|
| 35 |
+type docker_var_lib_t; |
|
| 36 |
+files_type(docker_var_lib_t) |
|
| 37 |
+ |
|
| 38 |
+type docker_home_t; |
|
| 39 |
+userdom_user_home_content(docker_home_t) |
|
| 40 |
+ |
|
| 41 |
+type docker_config_t; |
|
| 42 |
+files_config_file(docker_config_t) |
|
| 43 |
+ |
|
| 44 |
+type docker_lock_t; |
|
| 45 |
+files_lock_file(docker_lock_t) |
|
| 46 |
+ |
|
| 47 |
+type docker_log_t; |
|
| 48 |
+logging_log_file(docker_log_t) |
|
| 49 |
+ |
|
| 50 |
+type docker_tmp_t; |
|
| 51 |
+files_tmp_file(docker_tmp_t) |
|
| 52 |
+ |
|
| 53 |
+type docker_tmpfs_t; |
|
| 54 |
+files_tmpfs_file(docker_tmpfs_t) |
|
| 55 |
+ |
|
| 56 |
+type docker_var_run_t; |
|
| 57 |
+files_pid_file(docker_var_run_t) |
|
| 58 |
+ |
|
| 59 |
+type docker_unit_file_t; |
|
| 60 |
+systemd_unit_file(docker_unit_file_t) |
|
| 61 |
+ |
|
| 62 |
+type docker_devpts_t; |
|
| 63 |
+term_pty(docker_devpts_t) |
|
| 64 |
+ |
|
| 65 |
+type docker_share_t; |
|
| 66 |
+files_type(docker_share_t) |
|
| 67 |
+ |
|
| 68 |
+######################################## |
|
| 69 |
+# |
|
| 70 |
+# docker local policy |
|
| 71 |
+# |
|
| 72 |
+allow docker_t self:capability { chown kill fowner fsetid mknod net_admin net_bind_service net_raw setfcap };
|
|
| 73 |
+allow docker_t self:tun_socket relabelto; |
|
| 74 |
+allow docker_t self:process { getattr signal_perms setrlimit setfscreate };
|
|
| 75 |
+allow docker_t self:fifo_file rw_fifo_file_perms; |
|
| 76 |
+allow docker_t self:unix_stream_socket create_stream_socket_perms; |
|
| 77 |
+allow docker_t self:tcp_socket create_stream_socket_perms; |
|
| 78 |
+allow docker_t self:udp_socket create_socket_perms; |
|
| 79 |
+allow docker_t self:capability2 block_suspend; |
|
| 80 |
+ |
|
| 81 |
+manage_files_pattern(docker_t, docker_home_t, docker_home_t) |
|
| 82 |
+manage_dirs_pattern(docker_t, docker_home_t, docker_home_t) |
|
| 83 |
+manage_lnk_files_pattern(docker_t, docker_home_t, docker_home_t) |
|
| 84 |
+userdom_admin_home_dir_filetrans(docker_t, docker_home_t, dir, ".docker") |
|
| 85 |
+ |
|
| 86 |
+manage_dirs_pattern(docker_t, docker_config_t, docker_config_t) |
|
| 87 |
+manage_files_pattern(docker_t, docker_config_t, docker_config_t) |
|
| 88 |
+files_etc_filetrans(docker_t, docker_config_t, dir, "docker") |
|
| 89 |
+ |
|
| 90 |
+manage_dirs_pattern(docker_t, docker_lock_t, docker_lock_t) |
|
| 91 |
+manage_files_pattern(docker_t, docker_lock_t, docker_lock_t) |
|
| 92 |
+files_lock_filetrans(docker_t, docker_lock_t, { dir file }, "lxc")
|
|
| 93 |
+ |
|
| 94 |
+manage_dirs_pattern(docker_t, docker_log_t, docker_log_t) |
|
| 95 |
+manage_files_pattern(docker_t, docker_log_t, docker_log_t) |
|
| 96 |
+manage_lnk_files_pattern(docker_t, docker_log_t, docker_log_t) |
|
| 97 |
+logging_log_filetrans(docker_t, docker_log_t, { dir file lnk_file })
|
|
| 98 |
+allow docker_t docker_log_t:dir_file_class_set { relabelfrom relabelto };
|
|
| 99 |
+ |
|
| 100 |
+manage_dirs_pattern(docker_t, docker_tmp_t, docker_tmp_t) |
|
| 101 |
+manage_files_pattern(docker_t, docker_tmp_t, docker_tmp_t) |
|
| 102 |
+manage_lnk_files_pattern(docker_t, docker_tmp_t, docker_tmp_t) |
|
| 103 |
+files_tmp_filetrans(docker_t, docker_tmp_t, { dir file lnk_file })
|
|
| 104 |
+ |
|
| 105 |
+manage_dirs_pattern(docker_t, docker_tmpfs_t, docker_tmpfs_t) |
|
| 106 |
+manage_files_pattern(docker_t, docker_tmpfs_t, docker_tmpfs_t) |
|
| 107 |
+manage_lnk_files_pattern(docker_t, docker_tmpfs_t, docker_tmpfs_t) |
|
| 108 |
+manage_fifo_files_pattern(docker_t, docker_tmpfs_t, docker_tmpfs_t) |
|
| 109 |
+manage_chr_files_pattern(docker_t, docker_tmpfs_t, docker_tmpfs_t) |
|
| 110 |
+manage_blk_files_pattern(docker_t, docker_tmpfs_t, docker_tmpfs_t) |
|
| 111 |
+allow docker_t docker_tmpfs_t:dir relabelfrom; |
|
| 112 |
+can_exec(docker_t, docker_tmpfs_t) |
|
| 113 |
+fs_tmpfs_filetrans(docker_t, docker_tmpfs_t, { dir file })
|
|
| 114 |
+allow docker_t docker_tmpfs_t:chr_file mounton; |
|
| 115 |
+ |
|
| 116 |
+manage_dirs_pattern(docker_t, docker_share_t, docker_share_t) |
|
| 117 |
+manage_files_pattern(docker_t, docker_share_t, docker_share_t) |
|
| 118 |
+manage_lnk_files_pattern(docker_t, docker_share_t, docker_share_t) |
|
| 119 |
+allow docker_t docker_share_t:dir_file_class_set { relabelfrom relabelto };
|
|
| 120 |
+ |
|
| 121 |
+can_exec(docker_t, docker_share_t) |
|
| 122 |
+#docker_filetrans_named_content(docker_t) |
|
| 123 |
+ |
|
| 124 |
+manage_dirs_pattern(docker_t, docker_var_lib_t, docker_var_lib_t) |
|
| 125 |
+manage_chr_files_pattern(docker_t, docker_var_lib_t, docker_var_lib_t) |
|
| 126 |
+manage_blk_files_pattern(docker_t, docker_var_lib_t, docker_var_lib_t) |
|
| 127 |
+manage_files_pattern(docker_t, docker_var_lib_t, docker_var_lib_t) |
|
| 128 |
+manage_lnk_files_pattern(docker_t, docker_var_lib_t, docker_var_lib_t) |
|
| 129 |
+allow docker_t docker_var_lib_t:dir_file_class_set { relabelfrom relabelto };
|
|
| 130 |
+files_var_lib_filetrans(docker_t, docker_var_lib_t, { dir file lnk_file })
|
|
| 131 |
+ |
|
| 132 |
+manage_dirs_pattern(docker_t, docker_var_run_t, docker_var_run_t) |
|
| 133 |
+manage_files_pattern(docker_t, docker_var_run_t, docker_var_run_t) |
|
| 134 |
+manage_sock_files_pattern(docker_t, docker_var_run_t, docker_var_run_t) |
|
| 135 |
+manage_lnk_files_pattern(docker_t, docker_var_run_t, docker_var_run_t) |
|
| 136 |
+files_pid_filetrans(docker_t, docker_var_run_t, { dir file lnk_file sock_file })
|
|
| 137 |
+ |
|
| 138 |
+allow docker_t docker_devpts_t:chr_file { relabelfrom rw_chr_file_perms setattr_chr_file_perms };
|
|
| 139 |
+term_create_pty(docker_t, docker_devpts_t) |
|
| 140 |
+ |
|
| 141 |
+kernel_read_system_state(docker_t) |
|
| 142 |
+kernel_read_network_state(docker_t) |
|
| 143 |
+kernel_read_all_sysctls(docker_t) |
|
| 144 |
+kernel_rw_net_sysctls(docker_t) |
|
| 145 |
+kernel_setsched(docker_t) |
|
| 146 |
+kernel_read_all_proc(docker_t) |
|
| 147 |
+ |
|
| 148 |
+domain_use_interactive_fds(docker_t) |
|
| 149 |
+domain_dontaudit_read_all_domains_state(docker_t) |
|
| 150 |
+ |
|
| 151 |
+corecmd_exec_bin(docker_t) |
|
| 152 |
+corecmd_exec_shell(docker_t) |
|
| 153 |
+ |
|
| 154 |
+corenet_tcp_bind_generic_node(docker_t) |
|
| 155 |
+corenet_tcp_sendrecv_generic_if(docker_t) |
|
| 156 |
+corenet_tcp_sendrecv_generic_node(docker_t) |
|
| 157 |
+corenet_tcp_sendrecv_generic_port(docker_t) |
|
| 158 |
+corenet_tcp_bind_all_ports(docker_t) |
|
| 159 |
+corenet_tcp_connect_http_port(docker_t) |
|
| 160 |
+corenet_tcp_connect_commplex_main_port(docker_t) |
|
| 161 |
+corenet_udp_sendrecv_generic_if(docker_t) |
|
| 162 |
+corenet_udp_sendrecv_generic_node(docker_t) |
|
| 163 |
+corenet_udp_sendrecv_all_ports(docker_t) |
|
| 164 |
+corenet_udp_bind_generic_node(docker_t) |
|
| 165 |
+corenet_udp_bind_all_ports(docker_t) |
|
| 166 |
+ |
|
| 167 |
+files_read_config_files(docker_t) |
|
| 168 |
+files_dontaudit_getattr_all_dirs(docker_t) |
|
| 169 |
+files_dontaudit_getattr_all_files(docker_t) |
|
| 170 |
+ |
|
| 171 |
+fs_read_cgroup_files(docker_t) |
|
| 172 |
+fs_read_tmpfs_symlinks(docker_t) |
|
| 173 |
+fs_search_all(docker_t) |
|
| 174 |
+fs_getattr_all_fs(docker_t) |
|
| 175 |
+ |
|
| 176 |
+storage_raw_rw_fixed_disk(docker_t) |
|
| 177 |
+ |
|
| 178 |
+auth_use_nsswitch(docker_t) |
|
| 179 |
+auth_dontaudit_getattr_shadow(docker_t) |
|
| 180 |
+ |
|
| 181 |
+init_read_state(docker_t) |
|
| 182 |
+init_status(docker_t) |
|
| 183 |
+ |
|
| 184 |
+logging_send_audit_msgs(docker_t) |
|
| 185 |
+logging_send_syslog_msg(docker_t) |
|
| 186 |
+ |
|
| 187 |
+miscfiles_read_localization(docker_t) |
|
| 188 |
+ |
|
| 189 |
+mount_domtrans(docker_t) |
|
| 190 |
+ |
|
| 191 |
+seutil_read_default_contexts(docker_t) |
|
| 192 |
+seutil_read_config(docker_t) |
|
| 193 |
+ |
|
| 194 |
+sysnet_dns_name_resolve(docker_t) |
|
| 195 |
+sysnet_exec_ifconfig(docker_t) |
|
| 196 |
+ |
|
| 197 |
+optional_policy(` |
|
| 198 |
+ rpm_exec(docker_t) |
|
| 199 |
+ rpm_read_db(docker_t) |
|
| 200 |
+ rpm_exec(docker_t) |
|
| 201 |
+') |
|
| 202 |
+ |
|
| 203 |
+optional_policy(` |
|
| 204 |
+ fstools_domtrans(docker_t) |
|
| 205 |
+') |
|
| 206 |
+ |
|
| 207 |
+optional_policy(` |
|
| 208 |
+ iptables_domtrans(docker_t) |
|
| 209 |
+') |
|
| 210 |
+ |
|
| 211 |
+optional_policy(` |
|
| 212 |
+ openvswitch_stream_connect(docker_t) |
|
| 213 |
+') |
|
| 214 |
+ |
|
| 215 |
+# |
|
| 216 |
+# lxc rules |
|
| 217 |
+# |
|
| 218 |
+ |
|
| 219 |
+allow docker_t self:capability { dac_override setgid setpcap setuid sys_admin sys_boot sys_chroot sys_ptrace };
|
|
| 220 |
+ |
|
| 221 |
+allow docker_t self:process { getcap setcap setexec setpgid setsched signal_perms };
|
|
| 222 |
+ |
|
| 223 |
+allow docker_t self:netlink_route_socket rw_netlink_socket_perms;; |
|
| 224 |
+allow docker_t self:netlink_audit_socket create_netlink_socket_perms; |
|
| 225 |
+allow docker_t self:unix_dgram_socket { create_socket_perms sendto };
|
|
| 226 |
+allow docker_t self:unix_stream_socket { create_stream_socket_perms connectto };
|
|
| 227 |
+ |
|
| 228 |
+allow docker_t docker_var_lib_t:dir mounton; |
|
| 229 |
+allow docker_t docker_var_lib_t:chr_file mounton; |
|
| 230 |
+can_exec(docker_t, docker_var_lib_t) |
|
| 231 |
+ |
|
| 232 |
+kernel_dontaudit_setsched(docker_t) |
|
| 233 |
+kernel_get_sysvipc_info(docker_t) |
|
| 234 |
+kernel_request_load_module(docker_t) |
|
| 235 |
+kernel_mounton_messages(docker_t) |
|
| 236 |
+kernel_mounton_all_proc(docker_t) |
|
| 237 |
+kernel_mounton_all_sysctls(docker_t) |
|
| 238 |
+kernel_unlabeled_entry_type(spc_t) |
|
| 239 |
+kernel_unlabeled_domtrans(docker_t, spc_t) |
|
| 240 |
+ |
|
| 241 |
+dev_getattr_all(docker_t) |
|
| 242 |
+dev_getattr_sysfs_fs(docker_t) |
|
| 243 |
+dev_read_urand(docker_t) |
|
| 244 |
+dev_read_lvm_control(docker_t) |
|
| 245 |
+dev_rw_sysfs(docker_t) |
|
| 246 |
+dev_rw_loop_control(docker_t) |
|
| 247 |
+dev_rw_lvm_control(docker_t) |
|
| 248 |
+ |
|
| 249 |
+files_getattr_isid_type_dirs(docker_t) |
|
| 250 |
+files_manage_isid_type_dirs(docker_t) |
|
| 251 |
+files_manage_isid_type_files(docker_t) |
|
| 252 |
+files_manage_isid_type_symlinks(docker_t) |
|
| 253 |
+files_manage_isid_type_chr_files(docker_t) |
|
| 254 |
+files_manage_isid_type_blk_files(docker_t) |
|
| 255 |
+files_exec_isid_files(docker_t) |
|
| 256 |
+files_mounton_isid(docker_t) |
|
| 257 |
+files_mounton_non_security(docker_t) |
|
| 258 |
+files_mounton_isid_type_chr_file(docker_t) |
|
| 259 |
+ |
|
| 260 |
+fs_mount_all_fs(docker_t) |
|
| 261 |
+fs_unmount_all_fs(docker_t) |
|
| 262 |
+fs_remount_all_fs(docker_t) |
|
| 263 |
+files_mounton_isid(docker_t) |
|
| 264 |
+fs_manage_cgroup_dirs(docker_t) |
|
| 265 |
+fs_manage_cgroup_files(docker_t) |
|
| 266 |
+fs_relabelfrom_xattr_fs(docker_t) |
|
| 267 |
+fs_relabelfrom_tmpfs(docker_t) |
|
| 268 |
+fs_read_tmpfs_symlinks(docker_t) |
|
| 269 |
+fs_list_hugetlbfs(docker_t) |
|
| 270 |
+ |
|
| 271 |
+term_use_generic_ptys(docker_t) |
|
| 272 |
+term_use_ptmx(docker_t) |
|
| 273 |
+term_getattr_pty_fs(docker_t) |
|
| 274 |
+term_relabel_pty_fs(docker_t) |
|
| 275 |
+term_mounton_unallocated_ttys(docker_t) |
|
| 276 |
+ |
|
| 277 |
+modutils_domtrans_insmod(docker_t) |
|
| 278 |
+ |
|
| 279 |
+systemd_status_all_unit_files(docker_t) |
|
| 280 |
+systemd_start_systemd_services(docker_t) |
|
| 281 |
+ |
|
| 282 |
+userdom_stream_connect(docker_t) |
|
| 283 |
+userdom_search_user_home_content(docker_t) |
|
| 284 |
+userdom_read_all_users_state(docker_t) |
|
| 285 |
+userdom_relabel_user_home_files(docker_t) |
|
| 286 |
+userdom_relabel_user_tmp_files(docker_t) |
|
| 287 |
+userdom_relabel_user_tmp_dirs(docker_t) |
|
| 288 |
+ |
|
| 289 |
+optional_policy(` |
|
| 290 |
+ gpm_getattr_gpmctl(docker_t) |
|
| 291 |
+') |
|
| 292 |
+ |
|
| 293 |
+optional_policy(` |
|
| 294 |
+ dbus_system_bus_client(docker_t) |
|
| 295 |
+ init_dbus_chat(docker_t) |
|
| 296 |
+ init_start_transient_unit(docker_t) |
|
| 297 |
+ |
|
| 298 |
+ optional_policy(` |
|
| 299 |
+ systemd_dbus_chat_logind(docker_t) |
|
| 300 |
+ ') |
|
| 301 |
+ |
|
| 302 |
+ optional_policy(` |
|
| 303 |
+ firewalld_dbus_chat(docker_t) |
|
| 304 |
+ ') |
|
| 305 |
+') |
|
| 306 |
+ |
|
| 307 |
+optional_policy(` |
|
| 308 |
+ udev_read_db(docker_t) |
|
| 309 |
+') |
|
| 310 |
+ |
|
| 311 |
+optional_policy(` |
|
| 312 |
+ virt_read_config(docker_t) |
|
| 313 |
+ virt_exec(docker_t) |
|
| 314 |
+ virt_stream_connect(docker_t) |
|
| 315 |
+ virt_stream_connect_sandbox(docker_t) |
|
| 316 |
+ virt_exec_sandbox_files(docker_t) |
|
| 317 |
+ virt_manage_sandbox_files(docker_t) |
|
| 318 |
+ virt_relabel_sandbox_filesystem(docker_t) |
|
| 319 |
+ # for lxc |
|
| 320 |
+ virt_transition_svirt_sandbox(docker_t, system_r) |
|
| 321 |
+ virt_mounton_sandbox_file(docker_t) |
|
| 322 |
+# virt_attach_sandbox_tun_iface(docker_t) |
|
| 323 |
+ allow docker_t svirt_sandbox_domain:tun_socket relabelfrom; |
|
| 324 |
+') |
|
| 325 |
+ |
|
| 326 |
+tunable_policy(`docker_connect_any',` |
|
| 327 |
+ corenet_tcp_connect_all_ports(docker_t) |
|
| 328 |
+ corenet_sendrecv_all_packets(docker_t) |
|
| 329 |
+ corenet_tcp_sendrecv_all_ports(docker_t) |
|
| 330 |
+') |
|
| 331 |
+ |
|
| 332 |
+######################################## |
|
| 333 |
+# |
|
| 334 |
+# spc local policy |
|
| 335 |
+# |
|
| 336 |
+domain_entry_file(spc_t, docker_share_t) |
|
| 337 |
+domain_entry_file(spc_t, docker_var_lib_t) |
|
| 338 |
+role system_r types spc_t; |
|
| 339 |
+ |
|
| 340 |
+domain_entry_file(spc_t, docker_share_t) |
|
| 341 |
+domain_entry_file(spc_t, docker_var_lib_t) |
|
| 342 |
+domtrans_pattern(docker_t, docker_share_t, spc_t) |
|
| 343 |
+domtrans_pattern(docker_t, docker_var_lib_t, spc_t) |
|
| 344 |
+allow docker_t spc_t:process { setsched signal_perms };
|
|
| 345 |
+ps_process_pattern(docker_t, spc_t) |
|
| 346 |
+allow docker_t spc_t:socket_class_set { relabelto relabelfrom };
|
|
| 347 |
+ |
|
| 348 |
+optional_policy(` |
|
| 349 |
+ dbus_chat_system_bus(spc_t) |
|
| 350 |
+') |
|
| 351 |
+ |
|
| 352 |
+optional_policy(` |
|
| 353 |
+ unconfined_domain_noaudit(spc_t) |
|
| 354 |
+') |
|
| 355 |
+ |
|
| 356 |
+optional_policy(` |
|
| 357 |
+ unconfined_domain(docker_t) |
|
| 358 |
+') |
|
| 359 |
+ |
|
| 360 |
+optional_policy(` |
|
| 361 |
+ virt_transition_svirt_sandbox(spc_t, system_r) |
|
| 362 |
+') |
|
| 363 |
+ |
|
| 364 |
+######################################## |
|
| 365 |
+# |
|
| 366 |
+# docker upstream policy |
|
| 367 |
+# |
|
| 368 |
+ |
|
| 369 |
+optional_policy(` |
|
| 370 |
+# domain_stub_named_filetrans_domain() |
|
| 371 |
+ gen_require(` |
|
| 372 |
+ attribute named_filetrans_domain; |
|
| 373 |
+ ') |
|
| 374 |
+ |
|
| 375 |
+ docker_filetrans_named_content(named_filetrans_domain) |
|
| 376 |
+') |
|
| 377 |
+ |
|
| 378 |
+optional_policy(` |
|
| 379 |
+ lvm_stub() |
|
| 380 |
+ docker_rw_sem(lvm_t) |
|
| 381 |
+') |
|
| 382 |
+ |
|
| 383 |
+optional_policy(` |
|
| 384 |
+ staff_stub() |
|
| 385 |
+ docker_stream_connect(staff_t) |
|
| 386 |
+ docker_exec(staff_t) |
|
| 387 |
+') |
|
| 388 |
+ |
|
| 389 |
+optional_policy(` |
|
| 390 |
+ virt_stub_lxc() |
|
| 391 |
+ docker_exec_lib(virtd_lxc_t) |
|
| 392 |
+') |
|
| 393 |
+ |
|
| 394 |
+optional_policy(` |
|
| 395 |
+ virt_stub_svirt_sandbox_domain() |
|
| 396 |
+ virt_stub_svirt_sandbox_file() |
|
| 397 |
+ allow svirt_sandbox_domain self:netlink_kobject_uevent_socket create_socket_perms; |
|
| 398 |
+ docker_read_share_files(svirt_sandbox_domain) |
|
| 399 |
+ docker_lib_filetrans(svirt_sandbox_domain,svirt_sandbox_file_t, sock_file) |
|
| 400 |
+ docker_use_ptys(svirt_sandbox_domain) |
|
| 401 |
+ docker_spc_stream_connect(svirt_sandbox_domain) |
|
| 402 |
+ fs_list_tmpfs(svirt_sandbox_domain) |
|
| 403 |
+ fs_rw_hugetlbfs_files(svirt_sandbox_domain) |
|
| 404 |
+ fs_dontaudit_remount_tmpfs(svirt_sandbox_domain) |
|
| 405 |
+ dev_dontaudit_mounton_sysfs(svirt_sandbox_domain) |
|
| 406 |
+ |
|
| 407 |
+ tunable_policy(`virt_sandbox_use_fusefs',` |
|
| 408 |
+ fs_manage_fusefs_dirs(svirt_sandbox_domain) |
|
| 409 |
+ fs_manage_fusefs_files(svirt_sandbox_domain) |
|
| 410 |
+ fs_manage_fusefs_symlinks(svirt_sandbox_domain) |
|
| 411 |
+ ') |
|
| 412 |
+ gen_require(` |
|
| 413 |
+ attribute domain; |
|
| 414 |
+ ') |
|
| 415 |
+ |
|
| 416 |
+ dontaudit svirt_sandbox_domain domain:key {search link};
|
|
| 417 |
+') |
| 2 | 420 |
new file mode 100644 |
| ... | ... |
@@ -0,0 +1,102 @@ |
| 0 |
+# Some bits borrowed from the openstack-selinux package |
|
| 1 |
+Name: docker-engine-selinux |
|
| 2 |
+Version: %{_version}
|
|
| 3 |
+Release: %{_release}%{?dist}
|
|
| 4 |
+Summary: SELinux Policies for the open-source application container engine |
|
| 5 |
+BuildArch: noarch |
|
| 6 |
+Group: Tools/Docker |
|
| 7 |
+ |
|
| 8 |
+License: GPLv2 |
|
| 9 |
+Source: %{name}.tar.gz
|
|
| 10 |
+ |
|
| 11 |
+URL: https://dockerproject.org |
|
| 12 |
+Vendor: Docker |
|
| 13 |
+Packager: Docker <support@docker.com> |
|
| 14 |
+ |
|
| 15 |
+# Version of SELinux we were using |
|
| 16 |
+%if 0%{?fedora} == 20
|
|
| 17 |
+%global selinux_policyver 3.12.1-197 |
|
| 18 |
+%endif # fedora 20 |
|
| 19 |
+%if 0%{?fedora} == 21
|
|
| 20 |
+%global selinux_policyver 3.13.1-105 |
|
| 21 |
+%endif # fedora 21 |
|
| 22 |
+%if 0%{?fedora} >= 22
|
|
| 23 |
+%global selinux_policyver 3.13.1-128 |
|
| 24 |
+%endif # fedora 22 |
|
| 25 |
+%if 0%{?centos} >= 7 || 0%{?rhel} >= 7 || 0%{?oraclelinux} >= 7
|
|
| 26 |
+%global selinux_policyver 3.13.1-23 |
|
| 27 |
+%endif # centos,rhel,oraclelinux 7 |
|
| 28 |
+ |
|
| 29 |
+%global selinuxtype targeted |
|
| 30 |
+%global moduletype services |
|
| 31 |
+%global modulenames docker |
|
| 32 |
+ |
|
| 33 |
+Requires(post): selinux-policy-base >= %{selinux_policyver}, selinux-policy-targeted >= %{selinux_policyver}, policycoreutils, policycoreutils-python libselinux-utils
|
|
| 34 |
+BuildRequires: selinux-policy selinux-policy-devel |
|
| 35 |
+ |
|
| 36 |
+# conflicting packages |
|
| 37 |
+Conflicts: docker-selinux |
|
| 38 |
+ |
|
| 39 |
+# Usage: _format var format |
|
| 40 |
+# Expand 'modulenames' into various formats as needed |
|
| 41 |
+# Format must contain '$x' somewhere to do anything useful |
|
| 42 |
+%global _format() export %1=""; for x in %{modulenames}; do %1+=%2; %1+=" "; done;
|
|
| 43 |
+ |
|
| 44 |
+# Relabel files |
|
| 45 |
+%global relabel_files() \ |
|
| 46 |
+ /sbin/restorecon -R %{_bindir}/docker %{_localstatedir}/run/docker.sock %{_localstatedir}/run/docker.pid %{_sharedstatedir}/docker %{_sysconfdir}/docker %{_localstatedir}/log/docker %{_localstatedir}/log/lxc %{_localstatedir}/lock/lxc %{_usr}/lib/systemd/system/docker.service /root/.docker &> /dev/null || : \
|
|
| 47 |
+ |
|
| 48 |
+%description |
|
| 49 |
+SELinux policy modules for use with Docker |
|
| 50 |
+ |
|
| 51 |
+%prep |
|
| 52 |
+%if 0%{?centos} <= 6
|
|
| 53 |
+%setup -n %{name}
|
|
| 54 |
+%else |
|
| 55 |
+%autosetup -n %{name}
|
|
| 56 |
+%endif |
|
| 57 |
+ |
|
| 58 |
+%build |
|
| 59 |
+make SHARE="%{_datadir}" TARGETS="%{modulenames}"
|
|
| 60 |
+ |
|
| 61 |
+%install |
|
| 62 |
+ |
|
| 63 |
+# Install SELinux interfaces |
|
| 64 |
+%_format INTERFACES $x.if |
|
| 65 |
+install -d %{buildroot}%{_datadir}/selinux/devel/include/%{moduletype}
|
|
| 66 |
+install -p -m 644 $INTERFACES %{buildroot}%{_datadir}/selinux/devel/include/%{moduletype}
|
|
| 67 |
+ |
|
| 68 |
+# Install policy modules |
|
| 69 |
+%_format MODULES $x.pp.bz2 |
|
| 70 |
+install -d %{buildroot}%{_datadir}/selinux/packages
|
|
| 71 |
+install -m 0644 $MODULES %{buildroot}%{_datadir}/selinux/packages
|
|
| 72 |
+ |
|
| 73 |
+%post |
|
| 74 |
+# |
|
| 75 |
+# Install all modules in a single transaction |
|
| 76 |
+# |
|
| 77 |
+if [ $1 -eq 1 ]; then |
|
| 78 |
+ %{_sbindir}/setsebool -P -N virt_use_nfs=1 virt_sandbox_use_all_caps=1
|
|
| 79 |
+fi |
|
| 80 |
+%_format MODULES %{_datadir}/selinux/packages/$x.pp.bz2
|
|
| 81 |
+%{_sbindir}/semodule -n -s %{selinuxtype} -i $MODULES
|
|
| 82 |
+if %{_sbindir}/selinuxenabled ; then
|
|
| 83 |
+ %{_sbindir}/load_policy
|
|
| 84 |
+ %relabel_files |
|
| 85 |
+fi |
|
| 86 |
+ |
|
| 87 |
+%postun |
|
| 88 |
+if [ $1 -eq 0 ]; then |
|
| 89 |
+ %{_sbindir}/semodule -n -r %{modulenames} &> /dev/null || :
|
|
| 90 |
+ if %{_sbindir}/selinuxenabled ; then
|
|
| 91 |
+ %{_sbindir}/load_policy
|
|
| 92 |
+ %relabel_files |
|
| 93 |
+ fi |
|
| 94 |
+fi |
|
| 95 |
+ |
|
| 96 |
+%files |
|
| 97 |
+%defattr(-,root,root,0755) |
|
| 98 |
+%attr(0644,root,root) %{_datadir}/selinux/packages/*.pp.bz2
|
|
| 99 |
+%attr(0644,root,root) %{_datadir}/selinux/devel/include/%{moduletype}/*.if
|
|
| 100 |
+ |
|
| 101 |
+%changelog |
| ... | ... |
@@ -51,18 +51,25 @@ Requires: device-mapper >= 1.02.90-2 |
| 51 | 51 |
%endif |
| 52 | 52 |
|
| 53 | 53 |
# docker-selinux conditional |
| 54 |
-%if 0%{?fedora} >= 22 || 0%{?centos} >= 7 || 0%{?rhel} >= 7 || 0%{?oracle} >= 7
|
|
| 54 |
+%if 0%{?fedora} >= 20 || 0%{?centos} >= 7 || 0%{?rhel} >= 7 || 0%{?oraclelinux} >= 7
|
|
| 55 | 55 |
%global with_selinux 1 |
| 56 | 56 |
%endif |
| 57 | 57 |
|
| 58 | 58 |
# start if with_selinux |
| 59 | 59 |
%if 0%{?with_selinux}
|
| 60 | 60 |
# Version of SELinux we were using |
| 61 |
+%if 0%{?fedora} == 20
|
|
| 62 |
+%global selinux_policyver 3.12.1-197 |
|
| 63 |
+%endif # fedora 20 |
|
| 64 |
+%if 0%{?fedora} == 21
|
|
| 65 |
+%global selinux_policyver 3.13.1-105 |
|
| 66 |
+%endif # fedora 21 |
|
| 61 | 67 |
%if 0%{?fedora} >= 22
|
| 62 |
-%global selinux_policyver 3.13.1-119 |
|
| 63 |
-%else |
|
| 64 |
-%global selinux_policyver 3.13.1-39 |
|
| 65 |
-%endif |
|
| 68 |
+%global selinux_policyver 3.13.1-128 |
|
| 69 |
+%endif # fedora 22 |
|
| 70 |
+%if 0%{?centos} >= 7 || 0%{?rhel} >= 7 || 0%{?oraclelinux} >= 7
|
|
| 71 |
+%global selinux_policyver 3.13.1-23 |
|
| 72 |
+%endif # centos,oraclelinux 7 |
|
| 66 | 73 |
%endif # with_selinux |
| 67 | 74 |
|
| 68 | 75 |
# RE: rhbz#1195804 - ensure min NVR for selinux-policy |
| ... | ... |
@@ -63,11 +63,20 @@ set -e |
| 63 | 63 |
RUN mkdir -p /root/rpmbuild/SOURCES |
| 64 | 64 |
WORKDIR /root/rpmbuild |
| 65 | 65 |
RUN ln -sfv /usr/src/${rpmName}/hack/make/.build-rpm SPECS
|
| 66 |
- RUN tar -cz -C /usr/src -f /root/rpmbuild/SOURCES/${rpmName}.tar.gz ${rpmName}
|
|
| 67 | 66 |
WORKDIR /root/rpmbuild/SPECS |
| 67 |
+ RUN tar -cz -C /usr/src -f /root/rpmbuild/SOURCES/${rpmName}.tar.gz ${rpmName}
|
|
| 68 | 68 |
RUN { echo '* $rpmDate $rpmPackager $rpmVersion-$rpmRelease'; echo '* Version: $VERSION'; } >> ${rpmName}.spec && tail >&2 ${rpmName}.spec
|
| 69 | 69 |
RUN rpmbuild -ba --define '_release $rpmRelease' --define '_version $rpmVersion' --define '_origversion $VERSION' ${rpmName}.spec
|
| 70 | 70 |
EOF |
| 71 |
+ # selinux policy referencing systemd things won't work on non-systemd versions |
|
| 72 |
+ # of centos or rhel, which we don't support anyways |
|
| 73 |
+ if [ "$suite" -gt 6 ]; then |
|
| 74 |
+ cat >> "$DEST/$version/Dockerfile.build" <<-EOF |
|
| 75 |
+ RUN tar -cz -C /usr/src/${rpmName}/contrib -f /root/rpmbuild/SOURCES/${rpmName}-selinux.tar.gz ${rpmName}-selinux
|
|
| 76 |
+ RUN { echo '* $rpmDate $rpmPackager $rpmVersion-$rpmRelease'; echo '* Version: $VERSION'; } >> ${rpmName}-selinux.spec && tail >&2 ${rpmName}-selinux.spec
|
|
| 77 |
+ RUN rpmbuild -ba --define '_release $rpmRelease' --define '_version $rpmVersion' --define '_origversion $VERSION' ${rpmName}-selinux.spec
|
|
| 78 |
+ EOF |
|
| 79 |
+ fi |
|
| 71 | 80 |
tempImage="docker-temp/build-rpm:$version" |
| 72 | 81 |
( set -x && docker build -t "$tempImage" -f $DEST/$version/Dockerfile.build . ) |
| 73 | 82 |
docker run --rm "$tempImage" bash -c 'cd /root/rpmbuild && tar -c *RPMS' | tar -xvC "$DEST/$version" |