## Aide filesystem integrity checker. ######################################## ## ## Execute aide in the aide domain. ## ## ## ## Domain allowed to transition. ## ## # interface(`aide_domtrans',` gen_require(` type aide_t, aide_exec_t; ') corecmd_search_bin($1) domtrans_pattern($1, aide_exec_t, aide_t) ') ######################################## ## ## Execute aide programs in the AIDE ## domain and allow the specified role ## the AIDE domain. ## ## ## ## Domain allowed to transition. ## ## ## ## ## Role allowed access. ## ## # interface(`aide_run',` gen_require(` attribute_role aide_roles; ') aide_domtrans($1) roleattribute $2 aide_roles; ') ######################################## ## ## All of the rules required to ## administrate an aide environment. ## ## ## ## Domain allowed access. ## ## ## ## ## Role allowed access. ## ## ## # interface(`aide_admin',` gen_require(` type aide_t, aide_db_t, aide_log_t; ') allow $1 aide_t:process signal_perms; ps_process_pattern($1, aide_t) tunable_policy(`deny_ptrace',`',` allow $1 aide_t:process ptrace; ') aide_run($1, $2) files_list_etc($1) admin_pattern($1, aide_db_t) logging_list_logs($1) admin_pattern($1, aide_log_t) ')