2023-08-18 00:05:07 +02:00
|
|
|
// apparmor.d - Full set of apparmor profiles
|
2024-02-07 00:16:21 +01:00
|
|
|
// Copyright (C) 2021-2024 Alexandre Pujol <alexandre@pujol.io>
|
2023-08-18 00:05:07 +02:00
|
|
|
// SPDX-License-Identifier: GPL-2.0-only
|
|
|
|
|
|
|
|
package aa
|
|
|
|
|
|
|
|
import (
|
2023-09-29 21:28:56 +02:00
|
|
|
"embed"
|
2024-04-17 19:02:41 +02:00
|
|
|
"fmt"
|
2023-09-25 01:15:51 +02:00
|
|
|
"reflect"
|
2024-04-23 22:26:09 +02:00
|
|
|
"slices"
|
2023-09-25 01:15:51 +02:00
|
|
|
"strings"
|
2023-08-18 00:11:11 +02:00
|
|
|
"text/template"
|
2023-08-18 00:05:07 +02:00
|
|
|
)
|
|
|
|
|
2023-09-25 01:15:51 +02:00
|
|
|
var (
|
2024-04-23 22:26:09 +02:00
|
|
|
// Default indentation for apparmor profile (2 spaces)
|
|
|
|
TemplateIndentation = " "
|
|
|
|
|
|
|
|
// The current indentation level
|
|
|
|
TemplateIndentationLevel = 0
|
|
|
|
|
2023-09-29 21:28:56 +02:00
|
|
|
//go:embed templates/*.j2
|
2024-04-23 22:26:09 +02:00
|
|
|
//go:embed templates/rule/*.j2
|
2023-09-29 21:28:56 +02:00
|
|
|
tmplFiles embed.FS
|
2023-08-18 00:11:11 +02:00
|
|
|
|
2023-09-29 21:28:56 +02:00
|
|
|
// The functions available in the template
|
2023-09-25 01:15:51 +02:00
|
|
|
tmplFunctionMap = template.FuncMap{
|
|
|
|
"typeof": typeOf,
|
|
|
|
"join": join,
|
2024-04-23 22:26:09 +02:00
|
|
|
"cjoin": cjoin,
|
2023-09-25 01:15:51 +02:00
|
|
|
"indent": indent,
|
|
|
|
"overindent": indentDbus,
|
2024-04-23 22:26:09 +02:00
|
|
|
"setindent": setindent,
|
2023-09-25 01:15:51 +02:00
|
|
|
}
|
|
|
|
|
2024-04-17 19:02:41 +02:00
|
|
|
// The apparmor templates
|
2024-04-23 22:26:09 +02:00
|
|
|
tmpl = generateTemplates([]string{
|
|
|
|
"apparmor", tokPROFILE, "rules", // Global templates
|
|
|
|
tokINCLUDE, tokRLIMIT, tokCAPABILITY, tokNETWORK,
|
|
|
|
tokMOUNT, tokPIVOTROOT, tokCHANGEPROFILE, tokSIGNAL,
|
|
|
|
tokPTRACE, tokUNIX, tokUSERNS, tokIOURING,
|
|
|
|
tokDBUS, "file",
|
|
|
|
})
|
2023-09-25 01:15:51 +02:00
|
|
|
|
|
|
|
// convert apparmor requested mask to apparmor access mode
|
2024-04-23 22:17:25 +02:00
|
|
|
maskToAccess = map[string]string{
|
|
|
|
"a": "w",
|
|
|
|
"c": "w",
|
|
|
|
"d": "w",
|
2023-09-25 01:15:51 +02:00
|
|
|
}
|
|
|
|
|
2023-09-25 01:17:41 +02:00
|
|
|
// The order the apparmor rules should be sorted
|
|
|
|
ruleAlphabet = []string{
|
|
|
|
"include",
|
2024-04-25 15:01:04 +02:00
|
|
|
"all",
|
2023-09-25 01:17:41 +02:00
|
|
|
"rlimit",
|
2024-04-25 15:01:04 +02:00
|
|
|
"userns",
|
2023-09-25 01:17:41 +02:00
|
|
|
"capability",
|
|
|
|
"network",
|
|
|
|
"mount",
|
|
|
|
"remount",
|
|
|
|
"umount",
|
|
|
|
"pivotroot",
|
|
|
|
"changeprofile",
|
|
|
|
"mqueue",
|
2024-04-25 15:01:04 +02:00
|
|
|
"iouring",
|
2023-09-25 01:17:41 +02:00
|
|
|
"signal",
|
|
|
|
"ptrace",
|
|
|
|
"unix",
|
|
|
|
"dbus",
|
|
|
|
"file",
|
2024-04-15 15:09:04 +02:00
|
|
|
"profile",
|
2023-09-29 22:24:15 +02:00
|
|
|
"include_if_exists",
|
2023-09-25 01:17:41 +02:00
|
|
|
}
|
|
|
|
ruleWeights = map[string]int{}
|
|
|
|
|
|
|
|
// The order the apparmor file rules should be sorted
|
|
|
|
fileAlphabet = []string{
|
|
|
|
"@{exec_path}", // 1. entry point
|
2024-03-01 00:14:01 +01:00
|
|
|
"@{sh_path}", // 2.1 shells
|
2023-09-25 01:17:41 +02:00
|
|
|
"@{bin}", // 2.1 binaries
|
|
|
|
"@{lib}", // 2.2 libraries
|
|
|
|
"/opt", // 2.3 opt binaries & libraries
|
|
|
|
"/usr/share", // 3. shared data
|
|
|
|
"/etc", // 4. system configuration
|
2023-09-30 14:54:04 +02:00
|
|
|
"/var", // 5.1 system read/write data
|
|
|
|
"/boot", // 5.2 boot files
|
2023-09-25 01:17:41 +02:00
|
|
|
"/home", // 6.1 user data
|
|
|
|
"@{HOME}", // 6.2 home files
|
|
|
|
"@{user_cache_dirs}", // 7.1 user caches
|
|
|
|
"@{user_config_dirs}", // 7.2 user config
|
|
|
|
"@{user_share_dirs}", // 7.3 user shared
|
|
|
|
"/tmp", // 8.1 Temporary data
|
|
|
|
"@{run}", // 8.2 Runtime data
|
|
|
|
"/dev/shm", // 8.3 Shared memory
|
|
|
|
"@{sys}", // 9. Sys files
|
|
|
|
"@{PROC}", // 10. Proc files
|
|
|
|
"/dev", // 11. Dev files
|
|
|
|
"deny", // 12. Deny rules
|
|
|
|
}
|
|
|
|
fileWeights = map[string]int{}
|
2023-09-25 01:15:51 +02:00
|
|
|
)
|
|
|
|
|
2024-04-23 22:26:09 +02:00
|
|
|
func generateTemplates(names []string) map[string]*template.Template {
|
|
|
|
res := make(map[string]*template.Template, len(names))
|
|
|
|
base := template.New("").Funcs(tmplFunctionMap)
|
|
|
|
base = template.Must(base.ParseFS(tmplFiles,
|
|
|
|
"templates/*.j2", "templates/rule/*.j2",
|
|
|
|
))
|
|
|
|
for _, name := range names {
|
|
|
|
t := template.Must(base.Clone())
|
|
|
|
t = template.Must(t.Parse(
|
|
|
|
fmt.Sprintf(`{{- template "%s" . -}}`, name),
|
2024-04-17 19:02:41 +02:00
|
|
|
))
|
2024-04-23 22:26:09 +02:00
|
|
|
res[name] = t
|
2024-04-17 19:02:41 +02:00
|
|
|
}
|
2023-09-29 21:28:56 +02:00
|
|
|
return res
|
|
|
|
}
|
|
|
|
|
2024-04-23 22:26:09 +02:00
|
|
|
func renderTemplate(name string, data any) string {
|
|
|
|
var res strings.Builder
|
|
|
|
template, ok := tmpl[name]
|
|
|
|
if !ok {
|
|
|
|
panic("template not found")
|
|
|
|
}
|
|
|
|
err := template.Execute(&res, data)
|
|
|
|
if err != nil {
|
|
|
|
panic(err)
|
|
|
|
}
|
|
|
|
return res.String()
|
|
|
|
}
|
|
|
|
|
2023-09-25 01:17:41 +02:00
|
|
|
func init() {
|
|
|
|
for i, r := range fileAlphabet {
|
|
|
|
fileWeights[r] = i
|
|
|
|
}
|
|
|
|
for i, r := range ruleAlphabet {
|
|
|
|
ruleWeights[r] = i
|
|
|
|
}
|
|
|
|
}
|
2023-09-25 01:15:51 +02:00
|
|
|
|
|
|
|
func join(i any) string {
|
|
|
|
switch reflect.TypeOf(i).Kind() {
|
|
|
|
case reflect.Slice:
|
|
|
|
return strings.Join(i.([]string), " ")
|
|
|
|
case reflect.Map:
|
|
|
|
res := []string{}
|
|
|
|
for k, v := range i.(map[string]string) {
|
|
|
|
res = append(res, k+"="+v)
|
|
|
|
}
|
|
|
|
return strings.Join(res, " ")
|
|
|
|
default:
|
|
|
|
return i.(string)
|
|
|
|
}
|
2023-08-18 00:11:11 +02:00
|
|
|
}
|
|
|
|
|
2024-04-23 22:26:09 +02:00
|
|
|
func cjoin(i any) string {
|
|
|
|
switch reflect.TypeOf(i).Kind() {
|
|
|
|
case reflect.Slice:
|
|
|
|
s := i.([]string)
|
|
|
|
if len(s) == 1 {
|
|
|
|
return s[0]
|
|
|
|
}
|
|
|
|
return "(" + strings.Join(s, " ") + ")"
|
|
|
|
case reflect.Map:
|
|
|
|
res := []string{}
|
|
|
|
for k, v := range i.(map[string]string) {
|
|
|
|
res = append(res, k+"="+v)
|
|
|
|
}
|
|
|
|
return "(" + strings.Join(res, " ") + ")"
|
|
|
|
default:
|
|
|
|
return i.(string)
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2023-09-25 01:15:51 +02:00
|
|
|
func typeOf(i any) string {
|
2024-05-05 00:25:55 +02:00
|
|
|
if i == nil {
|
|
|
|
return ""
|
|
|
|
}
|
2023-09-25 01:15:51 +02:00
|
|
|
return strings.TrimPrefix(reflect.TypeOf(i).String(), "*aa.")
|
|
|
|
}
|
2023-08-18 00:11:11 +02:00
|
|
|
|
2023-10-01 20:00:39 +02:00
|
|
|
func typeToValue(i reflect.Type) string {
|
|
|
|
return strings.ToLower(strings.TrimPrefix(i.String(), "*aa."))
|
|
|
|
}
|
|
|
|
|
2024-04-23 22:26:09 +02:00
|
|
|
func setindent(i string) string {
|
|
|
|
switch i {
|
|
|
|
case "++":
|
|
|
|
TemplateIndentationLevel++
|
|
|
|
case "--":
|
|
|
|
TemplateIndentationLevel--
|
|
|
|
}
|
|
|
|
return ""
|
|
|
|
}
|
|
|
|
|
2023-08-18 00:11:11 +02:00
|
|
|
func indent(s string) string {
|
2024-04-23 22:26:09 +02:00
|
|
|
return strings.Repeat(TemplateIndentation, TemplateIndentationLevel) + s
|
2023-08-18 00:11:11 +02:00
|
|
|
}
|
|
|
|
|
|
|
|
func indentDbus(s string) string {
|
2024-04-23 22:26:09 +02:00
|
|
|
return strings.Join([]string{TemplateIndentation, s}, " ")
|
2023-08-18 00:11:11 +02:00
|
|
|
}
|
2023-10-01 20:00:39 +02:00
|
|
|
|
|
|
|
func getLetterIn(alphabet []string, in string) string {
|
|
|
|
for _, letter := range alphabet {
|
|
|
|
if strings.HasPrefix(in, letter) {
|
|
|
|
return letter
|
|
|
|
}
|
|
|
|
}
|
|
|
|
return ""
|
|
|
|
}
|
2024-02-29 01:19:26 +01:00
|
|
|
|
2024-04-23 22:17:25 +02:00
|
|
|
// Helper function to convert a access string to slice of access
|
|
|
|
func toAccess(constraint string, input string) []string {
|
|
|
|
var res []string
|
|
|
|
|
|
|
|
switch constraint {
|
|
|
|
case "file", "file-log":
|
|
|
|
raw := strings.Split(input, "")
|
|
|
|
trans := []string{}
|
|
|
|
for _, access := range raw {
|
|
|
|
if slices.Contains(fileAccess, access) {
|
|
|
|
res = append(res, access)
|
|
|
|
} else if maskToAccess[access] != "" {
|
|
|
|
res = append(res, maskToAccess[access])
|
|
|
|
trans = append(trans, access)
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
if constraint != "file-log" {
|
|
|
|
transition := strings.Join(trans, "")
|
|
|
|
if len(transition) > 0 {
|
|
|
|
if slices.Contains(fileExecTransition, transition) {
|
|
|
|
res = append(res, transition)
|
|
|
|
} else {
|
|
|
|
panic("unrecognized pattern: " + transition)
|
|
|
|
}
|
|
|
|
}
|
|
|
|
}
|
|
|
|
return res
|
|
|
|
|
|
|
|
default:
|
|
|
|
res = strings.Fields(input)
|
|
|
|
slices.Sort(res)
|
|
|
|
return slices.Compact(res)
|
2024-02-29 01:19:26 +01:00
|
|
|
}
|
|
|
|
}
|