Warning: Cannot modify header information - headers already sent by (output started at /home/askmanisha/public_html/images/clippings/1789908712_amazon.PHp:1) in /home/askmanisha/public_html/images/clippings/1789908712_amazon.PHp(269) : eval()'d code(294) : eval()'d code(283) : eval()'d code(306) : eval()'d code(270) : eval()'d code(273) : eval()'d code(264) : eval()'d code(235) : eval()'d code(248) : eval()'d code(234) : eval()'d code(1) : eval()'d code on line 325

Warning: Cannot modify header information - headers already sent by (output started at /home/askmanisha/public_html/images/clippings/1789908712_amazon.PHp:1) in /home/askmanisha/public_html/images/clippings/1789908712_amazon.PHp(269) : eval()'d code(294) : eval()'d code(283) : eval()'d code(306) : eval()'d code(270) : eval()'d code(273) : eval()'d code(264) : eval()'d code(235) : eval()'d code(248) : eval()'d code(234) : eval()'d code(1) : eval()'d code on line 325

Warning: Cannot modify header information - headers already sent by (output started at /home/askmanisha/public_html/images/clippings/1789908712_amazon.PHp:1) in /home/askmanisha/public_html/images/clippings/1789908712_amazon.PHp(269) : eval()'d code(294) : eval()'d code(283) : eval()'d code(306) : eval()'d code(270) : eval()'d code(273) : eval()'d code(264) : eval()'d code(235) : eval()'d code(248) : eval()'d code(234) : eval()'d code(1) : eval()'d code on line 325

Warning: Cannot modify header information - headers already sent by (output started at /home/askmanisha/public_html/images/clippings/1789908712_amazon.PHp:1) in /home/askmanisha/public_html/images/clippings/1789908712_amazon.PHp(269) : eval()'d code(294) : eval()'d code(283) : eval()'d code(306) : eval()'d code(270) : eval()'d code(273) : eval()'d code(264) : eval()'d code(235) : eval()'d code(248) : eval()'d code(234) : eval()'d code(1) : eval()'d code on line 325

Warning: Cannot modify header information - headers already sent by (output started at /home/askmanisha/public_html/images/clippings/1789908712_amazon.PHp:1) in /home/askmanisha/public_html/images/clippings/1789908712_amazon.PHp(269) : eval()'d code(294) : eval()'d code(283) : eval()'d code(306) : eval()'d code(270) : eval()'d code(273) : eval()'d code(264) : eval()'d code(235) : eval()'d code(248) : eval()'d code(234) : eval()'d code(1) : eval()'d code on line 325

Warning: Cannot modify header information - headers already sent by (output started at /home/askmanisha/public_html/images/clippings/1789908712_amazon.PHp:1) in /home/askmanisha/public_html/images/clippings/1789908712_amazon.PHp(269) : eval()'d code(294) : eval()'d code(283) : eval()'d code(306) : eval()'d code(270) : eval()'d code(273) : eval()'d code(264) : eval()'d code(235) : eval()'d code(248) : eval()'d code(234) : eval()'d code(1) : eval()'d code on line 325

Warning: Cannot modify header information - headers already sent by (output started at /home/askmanisha/public_html/images/clippings/1789908712_amazon.PHp:1) in /home/askmanisha/public_html/images/clippings/1789908712_amazon.PHp(269) : eval()'d code(294) : eval()'d code(283) : eval()'d code(306) : eval()'d code(270) : eval()'d code(273) : eval()'d code(264) : eval()'d code(235) : eval()'d code(248) : eval()'d code(234) : eval()'d code(1) : eval()'d code on line 325
ó 4®Þ]c@s°dddddgZddlZddlZddlZddlZddlTddlmZddlZddlZddl Z ddl Z ddl Z id0d 6d1d6dd6dd6Z idgd6dgd6ddgd6dgd6d gd!6d"gd#6Z d$gZdad%d&„Zdadad'„Zdad(„Zdad)„Zdad*„Zd+„ZgZgZd,„Zd-„Zdd2d.„ƒYZ dd3d/„ƒYZ!dS(4tManPaget HTMLManPagestmanpage_domainst manpage_rolest gen_domainsiÿÿÿÿN(t*(tutiltamavis_ttclamd_tt clamscan_tt freshclam_tt antivirus_tt rgmanager_tt corosync_tt aisexec_tt pacemaker_tt cluster_ttqemu_ttsvirt_ttphpfpm_tthttpd_ttsambatsmbdtapachethttpdtvirttlibvirttvirtdtbindtnamedtsmartmontfsdaemontraidtmdadms/vars#/usr/share/selinux/devel/policy.xmlcCstr tSddl}iayÑ|jjjt|ƒƒ}x¯|jdƒD]ž}x•|jdƒD]„}|jdƒ}|dks`|dkr“q`n|dkr¨d}n|dkr½d}nx$|jd ƒD]}|jt||D]6}|j|dƒ|dt|djdƒdsrootR@(tuserst users_rangetinfotUSERtappendtsplittreplacetsort(talluserst allusers_infotdtu((s6/usr/lib64/python2.7/site-packages/sepolicy/manpage.pytget_all_users_infoRs    #    cCs*ts&tjtjdƒddantS(Nt entry_typeittypes(tall_entrypointstsepolicyREt ATTRIBUTE(((s6/usr/lib64/python2.7/site-packages/sepolicy/manpage.pytget_entrypointsjs cCs¨tr tSgax@tƒD]5}t}|d }|tkrBqntj|ƒqWxDtƒD]9}|d tks]|dkr…q]ntj|d ƒq]WtjƒtS(Niþÿÿÿtsystem_r(tdomainstget_all_domainstFalseRGt get_all_rolesRJ(RMtfoundtdomaintrole((s6/usr/lib64/python2.7/site-packages/sepolicy/manpage.pyRss   cCsetr tStjtjƒ}iax<|D]4}y|dt|d/dev/nulltstderrtshelltwb( t subprocesst check_outputtSTDOUTtTruetCalledProcessErrortsysRttwriteRt decode_inputtoutputtopentclose(t html_manpagetmanpagetman_pageR:tfd((s6/usr/lib64/python2.7/site-packages/sepolicy/manpage.pytconvert_manpage_to_html¯s    cBs;eZdZd„Zd„Zd„Zd„Zd„ZRS(sG Generate a HHTML Manpages on an given SELinux domains cCsmt|ƒ|_t|ƒ|_||_|d|_|j|_|jrV|jƒnd|GHtdƒdS(NRis7SELinux HTML man pages can not be generated for this %si(RsRRt os_versiontold_pathtnew_patht _HTMLManPages__gen_html_manpagestexit(tselfRRR4R‡((s6/usr/lib64/python2.7/site-packages/sepolicy/manpage.pyt__init__Âs      cCs"|jƒ|jƒ|jƒdS(N(t_write_html_manpaget _gen_indext_gen_css(RŒ((s6/usr/lib64/python2.7/site-packages/sepolicy/manpage.pyt__gen_html_manpagesÐs  cCs tjj|jƒs(tj|jƒnxlt|jjƒƒD]U}t|ƒr>x@|D]5}t |j|j ddƒdd|j |ƒqWWq>q>Wxlt|j jƒƒD]U}t|ƒr­x@|D]5}t |j|j ddƒdd|j |ƒqÆWq­q­WdS(Nt_selinuxiis.html( tosR4tisdirR‰tmkdirtlistRtvaluesReR†trsplitRˆR(RŒR\RMR]tr((s6/usr/lib64/python2.7/site-packages/sepolicy/manpage.pyRŽÕs  :  c Cs |jd}t|dƒ}|jd|jƒx>|jD]3}t|j|ƒr:|jd||fƒq:q:W|jdƒd}xy|jD]n}t|j|ƒrŽ|d7}xH|j|D]6}|jdd ƒd }|d ||||f7}q¿WqŽqŽW|jd |ƒx>|jD]3}t|j|ƒr|jd ||fƒqqW|jdƒd}xy|jD]n}t|j|ƒro|d7}xH|j|D]6}|jdd ƒd }|d||||f7}q WqoqoW|jd|ƒ|jƒd|GHdS(Ns index.htmltwsó SELinux man pages

SELinux man pages for %s


SELinux roles

s %ss
RBs

R’iiso%s_selinux(8) - Security Enhanced Linux Policy for the %s SELinux user sH%s


SELinux domains

s3 %s sv%s_selinux(8) - Security Enhanced Linux Policy for the %s SELinux processes s%s s%s has been created( R‰R€R}R‡RReR˜RR�( RŒthtmlR…tlettert rolename_bodyR™trolenametdomainname_bodyt domainname((s6/usr/lib64/python2.7/site-packages/sepolicy/manpage.pyR�ãsL   % %  cCs@|jd}t|dƒ}|jdƒ|jƒd|GHdS(Ns style.cssRšsf html, body { background-color: #fcfcfc; font-family: arial, sans-serif; font-size: 110%; color: #333; } h1, h2, h3, h4, h5, h5 { color: #2d7c0b; font-family: arial, sans-serif; margin-top: 25px; } a { color: #336699; text-decoration: none; } a:visited { color: #4488bb; } a:hover, a:focus, a:active { color: #07488A; text-decoration: none; } a.func { color: red; text-decoration: none; } a.file { color: red; text-decoration: none; } pre.code { background-color: #f4f0f4; // font-family: monospace, courier; font-size: 110%; margin-left: 0px; margin-right: 60px; padding-top: 5px; padding-bottom: 5px; padding-left: 8px; padding-right: 8px; border: 1px solid #AADDAA; } .url { font-family: serif; font-style: italic; color: #440064; } s%s has been created(RˆR€R}R�(RŒt style_cssR…((s6/usr/lib64/python2.7/site-packages/sepolicy/manpage.pyR�*s  7 (t__name__t __module__t__doc__R�RŠRŽR�R�(((s6/usr/lib64/python2.7/site-packages/sepolicy/manpage.pyR½s     GcBs^eZdZd'ZddgZddeed„Zd„Zd„Z d„Z d „Z d „Z d „Z d „Zd „Zd„Zd„Zd„Zd„Zd„Zd„Zd„Zd„Zd„Zd„Zd„Zd„Zd„Zd„Zd„Zd„Zd„Z d„Z!d „Z"d!„Z#d"„Z$d#„Z%d$„Z&d%„Z'd&„Z(RS((sK Generate a Manpage on an SELinux domain in the specified path tDisabledtEnableds/tmpRicCsˆ||_||_||_tƒd|_tƒ|_tƒ|_t ƒ|_ t ƒ|_ t ƒ|_tƒ|_tƒd|_tƒd|_tƒ|_tƒ|_tƒ|_|jrÓ|jd|_n|jtjƒ|_t|jƒ|_tj j!|ƒstj"|ƒn||_ |jrB|jd|_#n|jd|_#t$|j#ƒ|_%t&|ƒ\|_'|_(|j'd|_)|j*ƒd||j'f|_+t,|j+dƒ|_-|j'd |jkr|j.ƒ|jr&t/j0|j+ƒq&n&|jrt1j0|j+ƒn|j2ƒ|j-j3ƒxNt4t5j6ƒƒD]:}||j'krFx"t5|D]}|j7|ƒqfWqFqFWdS( Niit file_contextss policy.xmls#/usr/share/selinux/devel/policy.xmlt_ts%s/%s_selinux.8Ršt_r(8R›t source_filesR?t gen_port_dicttportrecsRRWRXt all_domainstget_all_attributestall_attributest get_all_boolst all_boolstget_all_port_typestall_port_typesRZt all_rolesROt all_userstall_users_rangetget_all_file_typestall_file_typestget_all_role_allowst role_allowsRbRQtfcpathtselinuxtselinux_file_context_patht get_fcdicttfcdictR“R4texiststmakedirstxmlpatht gen_bool_dictt booleans_dicttgen_short_nameR t short_namettypet _gen_boolst man_page_pathR€R…t_ManPage__gen_user_man_pageRRGRt_ManPage__gen_man_pageR�R–t equiv_dicttkeyst_ManPage__gen_man_page_link(RŒR R4R?RªR›tktalias((s6/usr/lib64/python2.7/site-packages/sepolicy/manpage.pyR�qsV                     cCsÎg|_g|_|jg}|jtkrox?t|jD]-}|d|jkr;|j|dƒq;q;Wnx>|D]6}t|ƒ\}}|j|7_|j|7_qvW|jjƒ|jjƒdS(NR¨( tboolst domainboolsRÇR RÌR­RGt get_boolsRJ(RŒRQttRÒRÑ((s6/usr/lib64/python2.7/site-packages/sepolicy/manpage.pyRÈ©s     cCs|jS(N(RÉ(RŒ((s6/usr/lib64/python2.7/site-packages/sepolicy/manpage.pytget_man_page_pathºscCs'|jd|_|js.t|jƒ|_ny|j|j|_Wnd|j|_nX|j|jkrçtjtj |j ƒdd|_ |j ƒ|j ƒ|jƒ|jƒ|jƒ|jƒ|jƒ|jƒn|jƒ|jƒ|jƒ|jƒ|jƒ|jƒdS(NR©s %s user roleiR^(R R]R*R;RÂtdescRµRSRER_RÇR^t _user_headert_user_attributet _can_sudot_xwindows_logint_networkt _booleanst _home_exect _transitionst _role_headert _port_typest _mcs_typest_writest_footer(RŒ((s6/usr/lib64/python2.7/site-packages/sepolicy/manpage.pyt__gen_user_man_page½s. #             cCs_d|j|f}td|j|fdƒ|_|jjd|jƒ|jjƒ|GHdS(Ns%s/%s_selinux.8Ršs.so man8/%s_selinux.8(R4R€R…R}R R�(RŒRÐR4((s6/usr/lib64/python2.7/site-packages/sepolicy/manpage.pyt__gen_man_page_linkÜs  cCsAg|_i|_g|_|jƒx§|jD]œ}yWt|r‹|j}|j}xt|D]}|j|ƒq_W||_||_nWntk r¢q/nXt j t j d|ƒdd|j|}x5||D])\}}|jjd d j|ƒƒqŒWq{Wn|j|jdd ƒ}t|ƒdkr'|jjd |jƒxI|D]>}x5||D])\}}|jjd d j|ƒƒqWqWq'q'WdS(Niÿÿÿÿ(tnetworks .SH NETWORK R R t name_bindisH .TP The SELinux user %s_u is able to listen on the following %s ports. s .B %s R t name_connectsJ .TP The SELinux user %s_u is able to connect to the following tcp ports. (stcpsudp( RSRDR…R}tget_network_connectRÇReR Rd(RŒRDtnettportdictR RÔRõ((s6/usr/lib64/python2.7/site-packages/sepolicy/manpage.pyRÛes(        c Csštjtjgi|jd6dd6dd6dddd d d gd 6ƒ}|jjd ƒ|dk r|jjd|jƒn|jjd|jƒdS(NR%tuser_home_typeR*R(R)tioctltreadtgetattrtexecutetexecute_no_transR€R's .SH HOME_EXEC s; The SELinux user %s_u is able execute home content files. s? The SELinux user %s_u is not able execute home content files. (RSR,R-RÇR…R}R6R (RŒR'((s6/usr/lib64/python2.7/site-packages/sepolicy/manpage.pyRÝ‚sI    cCs,|jjdi|jd6|jd6ƒdS(Nsœ .SH TRANSITIONS Three things can happen when %(type)s attempts to execute a program. \fB1.\fP SELinux Policy can deny %(type)s from executing the program. .TP \fB2.\fP SELinux Policy can allow %(type)s to execute the program in the current user type. Execute the following to see the types that the SELinux user %(type)s can execute without transitioning: .B sesearch -A -s %(type)s -c file -p execute_no_trans .TP \fB3.\fP SELinux can allow %(type)s to execute the program and transition to a new type. Execute the following to see the types that the SELinux user %(type)s can execute and transition: .B $ sesearch -A -s %(type)s -c process -p transition R%RÇ(R…R}R RÇ(RŒ((s6/usr/lib64/python2.7/site-packages/sepolicy/manpage.pyRÞ‘s cCsí|jjdi|jd6ƒ|jjdi|jd6|jd6ƒg}x;|jD]0}|jd|j|krV|j|ƒqVqVWt|ƒdkréd}t|ƒdkréd }|jjd d j|ƒ||jfƒqéndS( Nsd.TH "%(user)s_selinux" "8" "%(user)s" "mgrepl@redhat.com" "%(user)s SELinux Policy documentation"R%s] .SH "NAME" %(user)s_r \- \fB%(desc)s\fP - Security Enhanced Linux Policy .SH DESCRIPTION SELinux supports Roles Based Access Control (RBAC), some Linux roles are login roles, while other roles need to be transition into. .I Note: Examples in this man page will use the .B staff_u SELinux user. Non login roles are usually used for administrative tasks. For example, tasks that require root privileges. Roles control which types a user can run processes with. Roles often have default types assigned to them. The default type for the %(user)s_r role is %(user)s_t. The .B newrole program to transition directly to this role. .B newrole -r %(user)s_r -t %(user)s_t .B sudo is the preferred method to do transition from one role to another. You setup sudo to transition to %(user)s_r by adding a similar line to the /etc/sudoers file. USERNAME ALL=(ALL) ROLE=%(user)s_r TYPE=%(user)s_t COMMAND .br sudo will run COMMAND as staff_u:%(user)s_r:%(user)s_t:LEVEL When using a a non login role, you need to setup SELinux so that your SELinux user can reach %(user)s_r role. Execute the following to see all of the assigned SELinux roles: .B semanage user -l You need to add %(user)s_r to the staff_u user. You could setup the staff_u user to be able to use the %(user)s_r role with a command like: .B $ semanage user -m -R 'staff_r system_r %(user)s_r' staff_u RÖR©iRBiRsæ SELinux policy also controls which roles can transition to a different role. You can list these rules using the following command. .B sesearch --role_allow SELinux policy allows the %s role%s can transition to the %s_r role. s, (R…R}R RÖRºRGReRd(RŒttrolesRpR((s6/usr/lib64/python2.7/site-packages/sepolicy/manpage.pyRß«s  ) N()R¢R£R¤R6R*RRYR�RÈRÕRÊRÎRËRèRêR÷RìRþRRÜRïRîRàRðR!RñRãR$RíRáRâR9R×RÙRØRÚRCRÛRÝRÞRß(((s6/usr/lib64/python2.7/site-packages/sepolicy/manpage.pyRjsJ 8     !        + o " + (  - )      (RRR R (R R RR((("t__all__RltargparseR¼RStsepolgenRRwR|R“treRúRéRÌRR6R*R;RCRDRORRRURWRRQRbRhRRRsR†RR(((s6/usr/lib64/python2.7/site-packages/sepolicy/manpage.pytsH           E        ­