HEX
Server: Apache/2.4.62 (Unix) OpenSSL/1.1.1k
System: Linux ns565604.ip-54-39-133.net 4.18.0-553.50.1.el8_10.x86_64 #1 SMP Tue Apr 15 08:09:22 EDT 2025 x86_64
User: greer489 (1034)
PHP: 8.3.19
Disabled: NONE
Upload Files
File: //usr/share/setroubleshoot/plugins/__pycache__/allow_ftpd_use_cifs.cpython-36.pyc
3

nm�a�
�@sDddlZejddd�ZejZddlTddlmZGdd�de�ZdS)	�Nzsetroubleshoot-pluginsT)Zfallback)�*)�Pluginc@sXeZdZed�Zed�Zed�ZdZed�ZdZ	ed�Z
ed�ZdZd	d
�Z
dd�Zd
S)�pluginzZ
    SELinux prevented the ftp daemon from $ACCESS files stored on a CIFS filesystem.
    a�
    SELinux prevented the ftp daemon from $ACCESS files stored on a CIFS filesystem.
    CIFS (Comment Internet File System) is a network filesystem similar to
    SMB (<a href="http://www.microsoft.com/mind/1196/cifs.asp">http://www.microsoft.com/mind/1196/cifs.asp</a>)
    The ftp daemon attempted to read one or more files or directories from
    a mounted filesystem of this type.  As CIFS filesystems do not support
    fine-grained SELinux labeling, all files and directories in the
    filesystem will have the same security context.

    If you have not configured the ftp daemon to read files from a CIFS filesystem
    this access attempt could signal an intrusion attempt.
    zh
    Changing the "$BOOLEAN" boolean to true will allow this access:
    "setsebool -P $BOOLEAN=1."
    z8/usr/sbin/setsebool -P ftpd_use_cifs=1 ftpd_anon_write=1a� Changing the "$BOOLEAN" and
    "$WRITE_BOOLEAN" booleans to true will allow this access:
    "setsebool -P $BOOLEAN=1 $WRITE_BOOLEAN=1".
    warning: setting the "$WRITE_BOOLEAN" boolean to true will
    allow the ftp daemon to write to all public content (files and
    directories with type public_content_t) in addition to writing to
    files and directories on CIFS filesystems.  z7If you want to allow ftpd to write to cifs file systemsz you must tell SELinux about thisz0# setsebool -P ftpd_use_cifs=1 ftpd_anon_write=1cCs tj|t�d|_td�|_dS)NTzEnable booleans)r�__init__�__name__Zfixable�_Zbutton_text)�self�r	�8/usr/share/setroubleshoot/plugins/allow_ftpd_use_cifs.pyrBszplugin.__init__cCsR|jdg�rJ|jdg�rJ|jddg�rJ|j|j|j�rD|jdd�SdSndSdS)	NZftpd_tZcifs_t�file�dir�
ftpd_use_cifs�ftpd_anon_write)�args)r
r)Zmatches_source_typesZmatches_target_typesZ
has_tclass_inZall_accesses_are_inZcreate_file_permsZrw_dir_permsZreport)rZavcr	r	r
�analyzeGszplugin.analyzeN)r�
__module__�__qualname__rZsummaryZproblem_descriptionZfix_descriptionZfix_cmdZrw_fix_descriptionZ
rw_fix_cmdZif_textZ	then_textZdo_textrrr	r	r	r
rsr)�gettextZtranslationrZsetroubleshoot.utilZsetroubleshoot.Pluginrrr	r	r	r
�<module>s