From d2e73c5d91ff4698334a95a3fc47c4f503c18011 Mon Sep 17 00:00:00 2001 From: Pierre-Yves Chibon Date: Wed, 28 Jan 2015 12:22:10 +0100 Subject: [PATCH] Add our own SELinux policy for upload.cgi Many thanks to tfirg on #selinux for helping out making this policy --- roles/distgit/files/upload_cgi.pp | Bin 0 -> 65035 bytes roles/distgit/files/upload_cgi.te | 25 +++++++++++++++++++++++++ roles/distgit/tasks/main.yml | 13 +++++++++++++ 3 files changed, 38 insertions(+) create mode 100644 roles/distgit/files/upload_cgi.pp create mode 100644 roles/distgit/files/upload_cgi.te diff --git a/roles/distgit/files/upload_cgi.pp b/roles/distgit/files/upload_cgi.pp new file mode 100644 index 0000000000000000000000000000000000000000..2b472f7aab7528d7644f8748686e26673455c161 GIT binary patch literal 65035 zcmeI51(@8%{ruoYg1-sW@ct) zW@ct)2LGRT-ktBR?!M>PiJklldY-fQ9sInb(aZ=|`{;cq|Mg6rPUrtRoz8_jozBTW z>U18t@8rLpuhZ$AaKrA+i_v6n_t>&O85ktFK&R6|@^f^!ZR>P8lkuR;`n`OmIBTcV zS=_a-YvH=n==sg>bnG8$!FI(?r*o<4AGVQc2E}N1FPrp>rdOBwZquBr)9G9Saf4yK z(yPoMTR&T;V{6UEV>9ZXrPJvk(NZz$pS{!RoV(NM2%hr zqA@Uss#$E)tg})S1Y@XY$qbgOa)@m3TacO*(cs?)O9l-+|O(LdN0@BwbXO*=tT?tc#= zx!r?hpSu)oV0WHbLlNLUJ$4-Wt?iNMT2uDZWoM!iY^WTq>2~F?UO5SkgZ9Yky3C8L zvE3L)!|aek``8|iwCGclQL)$d31mc9?3=o&%5_K_e{+2rRZsggK4M3qGa)4?%;=1W7@ zU4#J&1tG~~1l8(ZNP^D8Aq<_eu8|Zys4~NHkLh6tqjKb%YYP-QZ3}l~X8pcR4b9PF zoKbae6TKMrE(5vXR}N8+tX4hf{28H^5wGI`m-p!B&j(GiFFcv$n@T*BuZ#e?SdJ z|2v=#?0~}Ij16Pw<)(kw##M=78-ph%h!xZ1*%-=>dRDn{qAphIrW|9`M+xJm%5u}o zSBrt2#L$iEVkKW4^l=2(wb*J_*?o8EX?I;U*%*5la~KMrR2bsjoKc%*x#on0O3)u` z)9g0u43h!ASSd!U82B;y^w&qW_ZLl3+O--S&O$IcVOU-+tKFy>b*-4DHg!EskNz|& zv!*urq_UG0^3=u3?qV>2chp-KE2GIkmc+GbszEUpwfFn;{wl+tsI&rRyYlHqMrcLD8&xz{Tz~<8rW;?KTs;|IwnuEboFm8)Cy%Um(^NU^?T*So+H58@}OLUc3lN$ zE%=ODF`EMv^e$^L!oEPwa>js?k;N88_t4RFI~hPm4qV{%inJU;@JU zWk$1^qvb)la(J(V{1**&*#FqBwqah| zZS2KCJ7I3V=7&Cjp0uYhYxs-?!wEc+WADygiQqiP;TlP6djgHa5nFe<&ca#?o7>4v zKJFLU8M>R%L+!;Yd%5(#;mRXM5o}oZ&0h<$SBvVVGTHF(9(Nc9Q1Pk00*U@-_u1)t z!4ds>zMmhKE5%suVOyA1h6=H95!`d57v|UN-Z;zi2B&Q(9JEVSnf3FmZcr-55*t{Ikl7BGSiEA;L+(+LTa8N?&`rV1 z{urT_Ytt0=$`g*u;qFmsyA|5HHqA;Qms4ufOqdWCm?{* zb7(XkEX8m*X|kn(UBhFHw&v^=F%*RBW6YbEqoyhcaDfugZa7R~-(CbmW1G61RJpxp ziy0taE!ReF+`rNm<9;!Ymejtx!iu5auvm+ofr zrZ+Kr%*Z{Ug%&`^Kg7@V{1-JlS`Qm61CUlpM0p zJ-3Evtn_C0{h-i~Hr$xAWeiKZPQ+TvJ^_NX>~A9NMc0v)m|n5pTE0EZ2Z zq`JwPiG4l=iTg#3Gbco%EHi>aHgs#8N8&SL@tiIGhpr5i>-cq(RrVAXo0}-zWVzd{ zpOFhc5ZiNYxp#tv5bmA)8$SGs2FC_N^TYMXG{rIkkl?i3zd~!F9J5lH+IA6)x5dax z^cD=v`@6Y?F4VfYWxH5Dy&Z;=acsE$;Q9$RJ{0i3ZelM1o%S&Sdl1`^(~H=cTCoic zp5$muZf8+D;SRHL@9w55-Bnav%fUXzpUqOQ;CM$`96__WIXA@~d$|SM;`Hppoe4IR z(ZA2m#0e6>v!==N)t-Is7d~+;=?}@`D8co;GxQ;NY&ew!x@&iPoB6-+(g(UImyCz; z6dR3=?T8J7S2i9GOp^_E|NC_L|IfR(o96JP9gI9~{2Eu~-gP$|;gU8EU2GUP=Z}Nw z0~!B25)RMBCU@!eD$~^-aC_CBB47{Bo^L@@9O5tF zVC@2k*&S0l27Y=ix~Wx(!AT-b3qE=A_B=`6)Q54DQ+C6MFF6iH}|K z+7lnw29r_WEEgkVpXh>V+$t(Y%O!H6Z-eAVQ;?QJo$x4|tj_`^Yq@XDNo^&*1d&y_j7^n$9mD#IBwp&fjWqV)%e?UeIw(0f1YW~ZeTYYxhd_2lR znb_EKSQgT_I$ZpGzWL8?n-9a(gFmzc?4vAqP$3=uHkOa8YrSTDY_Oz2rAXis%@;oV za%-;{j(heQY3z-y()SG>X<<6_g#Dx&H+4@gpl+28Uq|T40kc)Adc9t*dkrqBV{aqb zRxN-yZ0>*<6u6p;robSNPPV_?ZvTwRQO_M3_Ev^10sRr(dSeN08#n8?Cx>L%VOu3@ zn9LnA8E$wR4jQhP6d>uKjigCjh20l`6 z)xz^_lueq|S^J=O;*fWBZel|ZL-8p3K&ohlWA}VAdjG~OZtIuBtQa}vHb>!j>ji|& zx0QuG%j^KbmM;JfliTh2_O#fri z#Qm*k;{IJUanFjjx788%e4>ea3DLyeE}FQw^K0|7x+7h*Puy5Eajz$uxHl8c{3nVg zZcj9E3(>@_MHBa)qKW%p(Zt0WoW*7Fk9E-jai1=lxGxk<+*gYx?psB(y!VSH?k7bP z_sgP*`(4q*{kdr3;xx$OvbaCG=#aSkL=*R%(?co`iF+Z@#J!AY;$B5G%U={t+-ry? z?hQo~_ZFgwdo72{?6-H(5pi?T#2tzz?wV-g-d8knA1<1>PZZ7io-LZVFBMJP*NZ0Z zjT|nMztcs>#Qm^n;(k^%albB_xIYw4++T|(?q5X{_sni6idp}8L=*R7qKSJ;hs)^8 zyXb_tR})R#P&9F`BbvB35l!3^L=*SUqKUgAnz$#4CeJ-Y6Zeh|H?;%T16_1V+((Nh z?o&k*_xYlU`%2NoeY0rdzE?DHKQ5ZMUldK;Z;MVBuw$k>r;{&YBKet%U0hgL#7wj7 z+$=8G1b>(%ShNBEngw`^_>2V+wtUeRFrG=P?=IT2`T?SSs~;sgu=**YL#v-BIqKjyTzU~%0|o18dbkZ9t5OElwuBAU3r6HVNIh$imY+)(8a_xz%X zdr8s6y`pI1?sD2Et~|`i>Jy13?)60z_vWIR{x+hCdsorKy_;y_Hlm4pFVVz(h-l(I z&gp=-_%0;2oYg%;qKW$=(Zqd?XyU$2H1mHzG;u#Anz&yPP2BH^Chjjp6ZcO}hr|sW zE{k^uM;;P)n;XeO;$B!ZaW5;HxI09%JWn)nuPK_i$A~8G@uG=)2d5+AUfbcaxV}Ua zcO;s)dqorXexix{2+_oSl4zFy9MQymnP}p^K{RpS<#bHk8#`QP|A<5r_j96&`wh{= z{gG(m{zf!$|0bHaXK^D_%=*qNnz$DiP24Luoe=j{4wuPyN;GjJ(Zs#3XyV>fG;wb& znz(lnP25${#H~cL{*y%$_d!ml#J!WlW%Oetnz&CBP23lVChn_56Zb8miTgg$#QlV5 z;(kdqala!vwe!T!onBm6@G#Zl-zz$`2lf=VliS#jyI60*>Mx2Wyt{#w z6ZYE@P5o2Rg#W#0!v9k=;m__yGLP^V5KZ_?i6;D&M5h+->Q4K_O+^zIU$w-R6XymJ zP26KeGyb-siJOTg?rzb&L$h7On2olByLdlAvZy_{&`9wD0f zebL0dmT2PMNHlS8DVn%6o}56;0fmI9wL@d5I?OH$@Zo$D)b*ThYY*yJ+H`)s0gz%RirJ z;$A{Dako325cf#Y#67{`GJ7o1#J!$q;@(U&aZeOY+@5IS7NUt;i)MZI6iwU*JDn2u zv7(84XNSw=PnT%ozECuAUoD!rZxv14_lqX(Cq)zY%c6<+_lm*Yn#Ix!gEG}4GiC(n&WYM0F!f>4#Th8bQ&7@8K7}0^%PZJ$l{Q}XE z)vppATm2T%iPi5Dom%|~r#<3+Ni=!BBbvB)mK$46w?CUnTihQ+6Zc=DiF*z=c6r3T zplIS=S~PL5EIPI05Ly^pZfmpGJgp-9Q7*Ml_@hM=9?!Tkz0H1{L{r~RG~t&-6Mi6? z@OwlP{yw4!|1i;P>nAuJ5cgT4iTe`K#Kl*0EG}_gC(*=xhiJxsNHlRjBbvBh6HVM7 zh$il@L=*QfPKU((KQ~l`#67oY;zkaa)n8PiiQ5%T+^dRa`am>suPvImHx^CYTZty_ zot%z{yDXZxW6{KQ*UEENcXx>ePS z?iWN8_ol9OS^T#onz%m^P2As!Chk8(6ZdRxAd6Yv`9%}=lA?)wMW++u?h;MhL^N@4 z?QmJ#^(C6PHy2IZ+lVIaT}2c3Zla0Xh-Ufs5>4EPIGqyraiWR)4AI2Bi^FC17fCd6 zUn82hZxc=24~Qo2r$iI?E24?}J<+M1MSkh@;=)3JdFIcvfW-iVUf}>27p$&DGya~U zJsbaE(SCrkaN84G&g74sNt^uXqC=}+C_1wG)uLmo-zqw>`u(C)t3T5=X67rN8AgEChlcK6Za~jiM!~uPuy#WChiSIljjzq ziHmQeW6OPucYBE@ZZ4X*L(#-t6HVOviYD&EMW=R@L=Umm+1j4yVgtfITQuQcDw^=G z7fpCP=E~A+aqpC9>JN)1{AWcI{_CO%|3lG)|FvkgwS8kX+A1XOncc_~68Ai!iF+~8 z#EnVY$%%7$i6-vVL^D1VP2B5U6Za(1#Jz`T;$F|;vib)~ zG;tp-nz&CD&GgR~P25+CChnU>6ZgGN$He`(XySfRG;zNznz%P}xUBA{5>4FSize}s%YYVUvz3` zkzYBzxUdjn(D=(NU@^qBayJLGxL|c7n(_A%?b-N;i1w|1oan&bDsvC{=FI*Ki4JY@ z7m1FnevRnZ>bHqbtp0%L)ap+;?Gg7YqFLYfL=*QHqKW$_(Zt2$`q*+Nw@+12+UmBs zq01xgg+&whvZ9H*Lo{(cr+wmHQ#5gp5zYFK7fswdh$b%Hx^MXy-Ir+Mjzkl8uV~`l zPc(5KA)2^PaylUHb3_yOWul4u2GQhsmuTYR#nKixu&wzKi6-vnL=*QLqKW$>(Zv0Y z=+qACc-+YrZ%hB1iwy~X7B@15gg>un!e3l8;jbW?@QIXei{B~H)RAbyUsp8YZz`Jb zw-(K|zKhclaaTnXw-QaTSOE0eNM;3 z{e)=Zen~WOzayHsKNC&dn>$=q{|AXC?!QD6_Z)8Aikbd`qKSKH(Zs#7(+P3yLqRyO z6XG5v@x(n^G;xm;P2Af!Tvm5Gi6-unXyOh;6L*hj=D&|<;y%pjl(AT{@$WJ8~;$zzSWNx9a#NL(V@Llh6fO_wmXs;(k;#aq+%qi_7TGOEhu6DVn%H7ERpWiYD&goeqh6RyP)f#66#A;$A{Dakq;m z&yk{un>yUk_Pto5iF-ZK#J!nl;+`lvwQ~@jIK`IR(t0j7B77m5@U>{d-%~Wi zj}=Y$8%S-ox~EGt^$SH4{?(!h|5nj#>-Rey6Zey%iTh>I#Qm;l;{IGTasMcqxW_tN z;_Q=X;-1ruTQTD=B$~LF5l!5yIGqsJKJ&wA#Wu$^B%Zi86iwV)h$imsMHBb74wu#E z5>4EpXyUGkX8QYzCho(XPKobf+7Gg{*f13p?#+X(HuENCytM`az{Cz}wHvVCveXE}!Id!ds5%+7NS>6vs6Zco5iTfAP#Qi@vGI_*3 zw`k(xRdLvI7I#sJCT>?Wajzk(P22~FChns|6Za`j2gH4zXyU#?G;!Y~n)SU$G;u#Bnz&yOOb?P% z+uR>;u`%I4C7SSG5l#5-i6;CnL=*l`q6zPw&dFoKALrl+yUmSTG4+K-6aKQI+15Lp zPKaxtN8+?%?OaphiF=G_;vO%WxOWguT=$OGJR$Dw94>L(ml*SexO*i#;++T|(?q5X{_sni&@`!sL(Zs!&XyUqejpZ!<@)Awl ztBEFV=(JDV>xd@qO+>T26GRjD&Z3FCBAU1-i6-tnL=zX^vc{IPxCcr!aUU(3xKDLD zAnx-;6Ze&(iTh^JEdRZtiTiQU#QmaZ;(l8+aq%t?i_7dkm1yGrUNmw4>2yfkv%8@x zB<=-76ZcZ0iF+l{tnccgiJOWh?hQl}_ZkkD$&Zz2;@(y?aWkhQ;_enr+=*!7-di+r zA1a!-j~C7QpDCKSFBVPQ8#-J@zgD7&`*zX9{h-q^aX&4ZxL*}b-0zDf?k`0X_s^n< zdnPv&#pF4cXyV?&;l}pJzlcN=_j00BJN@HpgxGSM`Un@B5Z*p+#A(IGUrXW%eOPKo4Efh$imqL=*QIhs)&ekZ9t5$my84pAk*muZbq^4@499SE7mg7tzH1 zKQ|P`tpD7iiF;Ae#68~OGP*0##J#H1332TMMVv_N$Z>6nC+>|!6Zcl4iF+r}#9bCm z+_7l#++8$r@8EC~Tm1thI<>16ym|mzZet(iVpGCDMKs}`Cz|lD5KZ_ui6;DeL=*mF zq6z;6(S-k&Xu|h}&f@(K9fSj3;x?tk|rquVy7oA!=P>5v~c zQSW`(^S8=6HFdZX@Qo~}1DB|8+qsQA9I%n^Kz;154)}o2`La%p57$^*`8a>)_cBofp>x{%?*8gP-#y$uuxxj4Gr@Lhj}P~B{8sz?kodsL zcH^5yrpMiXiVy7bLvnmfcf?`cAE!{qe}a!g)~}}Dci(D%9Fn%0J^`oIfrW{CyOBGF zkj~9n?*EN>q36@N1RK*K{~;T%riE`+$02E}Q>f#Rj92@q7LWt>X7a8>AlVU z)iJ+5LOR!<-2WT%LeHn$-|^vmY~1F{+*sZ|yPbVg`22cwzW#qsU&XVrOt)<;zvb&J zJhrg0-hKO!-hD>%xzBiuhx?2|+-F=uaG&vAF83LC3f*VGyU%#$&wa)jrTdJp_PEcu zRpdV7Oa1OM9szToaZ2Gn<7Gt~eeRond1F)fzJ2yVs!icrr?+36*pz;H4zekHAHSQs zIh;FcWBC03K%CS2ra&9hZ(TkOY)*f$;al=!m{iK=b7`CF-6GtUqLg#c?YR}_R^fX4 zZ`q#H9kJ2Z6mwJfmi$}!+M@h@>~5ROKj`o++rb|18+~or4*Ry+?*~`T^zb@}dUbyH z6y!$!t-`lzH+P(EEN83mt;*lBKWx?iZR>AthxvNl1~#{C{0!~#%+C#O+nC;M^WleT z!}yB}nEwg(`84pq z+t}w(T`=Cj<@R0sN4;GN{ExHk&A&1|p8{XYZ~xNqeC#~j{BIV|rvY5OYQO5|g6HAd zKUC{d;D25X2XvP&L_jJ!w%iF>+sa|rr&Ox z&xt1kTm|Ycj?E{A&Drl{&Bx$*2v^M9&rfZYWbXHn=98euPk+T{J{Z-`ep6>Y1~>8S zFTuO=cn2!gt zeXIX`pnYX@wpNUlVGF&(y^y>p?H7hzR`ht+>YI;e+nY^mH`xQ<{>Ygt0{>$GaxWL2 z565tVIQJrIXcuqu*phm!@zA{(T3-06l;mbtXOLY*?~S)tfh*zRI!#S z)>6e=N4HBYhTDb_s2ny*+> z@O;IZuUPZ7yoxnnvF0n*e8rltSo0NYfnrTT2^4FAVl7at1zLHEwLq~JDAoeSTA)}9 z6>Cbhp<*pmtc8lTP_Y(jbtu+C#agIX3l(dTVoj+cQmjRawMelRDb^yzTBOyhSc?>E zkzy@YtSQCCinUm=7Aw|b#agUbixq3J#-dn@6>EuNP05-l))K{9qF755Yl&hlQLH73 zwM64ntfh)IEtz61Rjj3owN$Z|D%MiPTB=w}6>Djm+0FQ^tI=+DZv{@50j)4MMSo0NY3bLEWFEl{i}c!6Rq zP^<-7Ud39VSPK+ufnqICtc8lTP_d?FhlEmEvSiZ!L$ zNU;_v)*{7Pq*#lzIuvV>Vl7gv#fr69v8GfJE7oGgTC7-$6>G6#E!OH)ti_78M6s4A z)|BEB#ag0ROB8E~Vl7duC5p8~V^OT7inUa+re#&ErHZvwv6d>jI@XUkMA8uuut$l(1L{OO&v5bC{=C^Au)J zvDOZv#ag6Tixg`LN~Bne6l;-UEz-(UtVN2oNU;_x)?&q4tXNa3jTLLL zVl7sz#fr69t3$CCE7lUlTB2A>6l+QqiDE5LtR;%IM6s4A))K8=#agOZOBHLWVofVf zv6d>YeJ|C4)YXip2FuT);z_UmQ1ncDb_s2nx|Ov6lE zkzy@Yti_78Sg{r>))bUju@)=VV#Qjlm8V#X6>EuNEm5o`inT&9sbVcvtfh*zRI!$}>vhw;eP7td>An@nxwxH>VOly* z$?Gd&K`V?)fL0Kz2$ir%35%7mLFYi%~Py-iZxHM z<}22G#hS11`HD4Pv8E+ctoe#HU$N#Z)_lcUpjZnOYk^`dP?!V7T06*g$Uw0cDAoeS zTA)}9+Scq!W^)$}6|Ekzy@Yti_78Sg{r>)?&q)f)^{+V#Qjl6e%OiSk}d3_};P{P7i7?%L8AXXbGVX+dHC}HX5Fi)}ODfN1aHBYhT zDb_s2npT`*%~Py-iZxHM<}22G#hS0M_=+`OvF0n*w5*CXU$N#Z)_lcUpjZnOYk^`d zQ1}AHTA*0dk}1{##af_P3lwXiVl7mxg^IOMu@)-Kp<=BaWRJB_u@)-ULd9Cxwq{o{ zn~%OoF&imnBgJf_n2i*(QQMgvSQKNC7N(eu6thv=tZlqlu@)=VV#QjlSc?^Fv0_a@ zjumUMmQJx2E7lUlTB2A>6l;lMEm5o`iZulDj`JU89PZmP%s)4;`6Am`Y2LWXJSJSDHMgat}isDwqWFfIXFK}3m_ zutW(=N4HBYhTDb_s2npTBk%~Py-iZx%c<}22GrCwjL<}22G#hR~J z(~489`HD4Pu@)%S0>xUOSPK-EK(Q7m)&j+vmQ}G9DAoeSTBukH6>FhlEmW+93SX#L z3l(cxGR0b`SPK@X53)*{7P)V5|6e<+Rp2y`$U`WTY;QU+X)$_rSp`$z7iHF zVWAQhDPeIdj7xx45b+WvEZrRDDb_rtJWsLaDb_s2nx|Ov6lE#hR~J z^OZV$#hR~J^A&5pV$D~qX;moJe8pOzSPK+ufnqIC>J1cYfnqICtObfStvJP6pjZnP zYoTH-RIG)HwNPOR6>FhlEmW*&Sru!cVl7gvMT)gZu@))TBE?#y@I{KXNU^3RQ>;ab zwOFwhE7oGgTC7-$6>G6#EmoLg#acVaj*zipEpA)0E1At>W}=u)6tjt9Hc`wbirGXl zn>ktZmjdN~%~(6>F(tEmf?ginUa+mMYd##hQk!SWDaK+;rdi2?KX_ z-wNd1*-pqXEuE+2^_8$d2@935NC}ITu%s2nB|s~P$nBqOuwkBJ%~SGviZxHM<|)=Z z#hRyB^Au~IVogI)toe#HU$N#Z<@t&=U$N#Z)_ld9uUPXHYg)C6wLq~JDAoeSTAE zkzy@UtVIe-q*#j-Yms72%c@w56>G6#Emo|>inUm=7Aw|bg)dgD#fmj8nPM$btR;%I zM6s4A))K{9qF755Yl*^~DAw9RcA!t%*6d1V^AwRPW>dv%s+dg`v#DY>Rm`S}*;Fx` zww>9Tu5HYkReqf4G5b#b>-KHiyGIw5$(yoT?~b#kG1aKtMy9g4Ske(L-rv>jOYzLJZGRi8yp>s*46>?= zcSg=3K^`h5Tl4|oY_mWotPhvUL6LU{#c1~&k$X$;=}Uzs+HvCOh*35){qFI_*wj}) z<|fD7Vh&7R+j~Zm@eQQ)9G1M2_VmO;b6tN>=DWLmm1q~QDV~FJZ)-k1nb@svu$om_ z-k53&GWWjd)1T}Z9CH;sCl_s+-iUY{T^|F4yHyt;2aBSGwFDhi-IWlYZ z|9p_u^$t@XvGb0|hmLz^m|`=`iaOQBSR}mH*o{u?d-KSs>;SiI+q>JgcTbp%$7R)Y zhgn{gb$7X}y0vNQZn@m$3vj#EmZ`hhsNWr%YFN~DQI6O?w_Yu3jxzOXIT`f3(`#U~c#YrycmF z;IaphY*dbpoQ>4;$#zM)Xl3dO$y}RkOqW+CYmgLs`am;H z)6F;U!PaqF^4gd0A8duKOq*I7O{O%(bhjTsJF-bOq_@SEV^d`q4eM^Rnl;^F*)NvY zyLFQ_WE7h{8`u%SZ3lSVY`6RAII}i)px6-=h2f~0EkoVvbHj#2 zt+k;n3AGKW+Y7hWdab=7v9_kFQOEQr5IAGCwsy7?*e$#5bxwOjj!mnPy4zZXY}k-R zT`JVw))HaEc2K+Jgt5tsY_Qd?Ik7g~9hJ%Yc4S$ripCt#Z7{f@YZ=IL?}4sTdT^`cc*>s=MB#DTi58A>5YUkb9492FKt{YtI)~m&GGuknl40jHSy4kgB z7nhMX97~HXg1e*1u-g2K9Po)E^Wh)9cx0>`#WnbuwZqEJn4dnr_w|nKh)^)$LAd)3<}{w(VV0 zRpY7{H9Na?X<_q0S!2~+nNhQ9u;{_EXbGpF#i(yajp=vuvcl=-VEtex^ljU*wi=g% zwX7QL7@E4yR;H_NOVQ1`h{2#ajb!gQz|Hz+1*WRh@<(u7R<8J6U1{5G+q=VTx9Mi1 z^=1_W%ULlv6$V$#s5hxiwFCcP1-`R8uFP_=cW1XM2c}n>W@mResC#|0oJ|JJ!0a&t zhE&;T#q8|fahTV=JZsEKSrw*sEBFK4Y$E^ymkZ3^X2*7S@CHBhey8SxFZ+cgmchUpgA{HF>7N}cWYZqZENYS70oI}&|;L0Fg$mQ zQMVXj1!dQrqsh=zMcyr|zNwhFUg!?WHB;mGWErc)%Brawdt6{UXlC2r>K(`JJeEyE z-CeHA;gog`cGe50?X~0BQ`ubC&uU!PL1*t`4^L0@xYikzYj(neIp^%4jLn}VtQAde z58x%!tQj-v*5#ziO?QkdOE}NN>TFPEeRR}mDAt#gf$7#f7qw&iem8rR9aC1_tZ$cx z80TFXSfdWji2G>2rOb+%)P}vGG1YRGn|ddDXF0|aI2#PsXXAKfPMQ>z>Dt+X!((@q z6Vvi!lq18=Ze8H)br^Kl%2Crbd<16Kr(53I%UbJhs zrFENDdU07{KO%d%$5d6(H`83x>mWuGav__pVR2kOUV KWqY;u*#83`h@;&A literal 0 HcmV?d00001 diff --git a/roles/distgit/files/upload_cgi.te b/roles/distgit/files/upload_cgi.te new file mode 100644 index 0000000000..f58050d1dc --- /dev/null +++ b/roles/distgit/files/upload_cgi.te @@ -0,0 +1,25 @@ +policy_module(upload_cgi,1.0.0) + + +gen_require(` type httpd_git_script_t ; ') +type upload_cgi_tmp_t; +files_tmp_file(upload_cgi_tmp_t); +allow httpd_git_script_t upload_cgi_tmp_t:file manage_file_perms; +files_tmp_filetrans(httpd_git_script_t, upload_cgi_tmp_t, file); + + +# Do not audit attempts to read the process state (/proc/pid) of all domains. +domain_read_all_domains_state(httpd_git_script_t); + +# List the contents of the sysfs directories. +dev_list_sysfs(httpd_git_script_t); + +# Allow sending logs to syslog +logging_send_syslog_msg(httpd_git_script_t); + +# Get the attributes of all pty device nodes. +term_getattr_all_ptys(httpd_git_script_t); +# Get the attributes of all tty device nodes. +term_getattr_all_ttys(httpd_git_script_t); +# Do not audit attempts to get the attributes of generic pty devices. +term_dontaudit_getattr_generic_ptys(httpd_git_script_t); diff --git a/roles/distgit/tasks/main.yml b/roles/distgit/tasks/main.yml index c2e4a16b35..e372d1143a 100644 --- a/roles/distgit/tasks/main.yml +++ b/roles/distgit/tasks/main.yml @@ -295,3 +295,16 @@ - config - lookaside - selinux + +# Three tasks for handling our selinux policy for upload.cgi +- name: ensure a directory exists for our SELinux policy + file: dest=/usr/local/share/selinux/ state=directory + +- name: copy over our custom selinux policy + copy: src=upload_cgi.pp dest=/usr/local/share/selinux/upload_cgi.pp + register: selinux_module + +- name: install our custom selinux policy + command: semodule -i /usr/local/share/selinux/upload_cgi.pp + when: selinux_module|changed +