Level 4

Booleans Deep Dive

Difficulty: Intermediate | Reward: +200 XP | Prerequisites: Level 3 - Custom Policy Modules

Mission Briefing

A developer reports that the company's internal web application works perfectly in permissive mode but throws 500 errors in enforcing mode. The application needs to send email, connect to a PostgreSQL database on a remote host, and serve content from user home directories. You need to find the right combination of booleans to make it work - without opening any access that is not strictly required.

What Booleans Actually Are

SELinux booleans are not just on/off switches. Each boolean controls conditional policy rules compiled into the loaded policy. When you toggle a boolean, the kernel activates or deactivates those rules in real time without reloading the entire policy. The rules already exist in memory, gated behind the boolean's state.

Examine the conditional rules tied to a specific boolean:

[root@gamehost ~]# sesearch --bool httpd_can_sendmail -A
allow httpd_t system_mail_t:unix_stream_socket connectto;
allow httpd_t sendmail_exec_t:file { read getattr open execute };
allow httpd_t postfix_master_t:unix_stream_socket connectto;

Those rules exist in the policy at all times. When httpd_can_sendmail is off, the kernel skips them. Set it to on and they become active - no policy reload, no relabeling.

Querying Boolean State

The basic commands are straightforward, but each gives you different information:

[root@gamehost ~]# getsebool httpd_can_sendmail
httpd_can_sendmail --> off

[root@gamehost ~]# getsebool -a | wc -l
338

[root@gamehost ~]# semanage boolean -l | grep httpd_can_sendmail
httpd_can_sendmail (off , off) Allow httpd to can sendmail

The semanage boolean -l output shows two values in parentheses. The first is the current runtime state. The second is the persistent (on-disk) default. When these differ, it means someone used setsebool without the -P flag - the change will revert on reboot.

Setting Booleans

Always use the -P flag to make changes persistent:

[root@gamehost ~]# setsebool -P httpd_can_sendmail on
[root@gamehost ~]# setsebool -P httpd_can_network_connect_db on
[root@gamehost ~]# setsebool -P httpd_enable_homedirs on

Without -P, the change is runtime-only and disappears after reboot. This is a frequent source of "it worked yesterday" tickets.

Auditing Boolean Changes

Every boolean change is logged in the audit trail. You can search for them:

[root@gamehost ~]# ausearch -m MAC_CONFIG_CHANGE -ts today
type=MAC_CONFIG_CHANGE msg=audit(1710100000.456:789):
bool=httpd_can_sendmail val=1 old_val=0 auid=1000 ses=3

This log entry shows exactly which boolean changed, its old and new values, and which user (auid 1000) made the change. In a compliance environment, these audit records prove that policy changes were intentional and traceable.

Creating Custom Booleans

You can define booleans in your own policy modules. In the .te file, declare the boolean and wrap rules in a conditional block:

bool vaultsyncd_can_connect_remote true;

if (vaultsyncd_can_connect_remote) {
corenet_tcp_connect_http_port(vaultsyncd_t)
corenet_tcp_connect_all_unreserved_ports(vaultsyncd_t)
}

After loading the module, your custom boolean appears in getsebool -a and works like any built-in boolean. Ship the policy with rules present but gated - administrators enable features as needed.

Common Boolean Misconfigurations

Some booleans are dangerously broad. Knowing which ones to avoid is as important as knowing which ones to enable:

Challenge: Fix the Web Application

The internal web app has three features that fail in enforcing mode. The audit log shows these denials:

  1. httpd cannot connect to TCP port 5432 (PostgreSQL)
  2. httpd cannot execute /usr/sbin/sendmail
  3. httpd cannot read files in /home/*/public_html

Your tasks:

  1. Use sesearch to identify the boolean controlling each access
  2. Enable only the three specific booleans needed - not broad alternatives
  3. Verify persistence by checking semanage boolean -l output
  4. Confirm zero AVC denials remain with ausearch -m AVC -ts recent

Bonus objective: Find one boolean in the httpd policy that you should never enable in production, and explain why using sesearch to show what rules it activates.

Key Commands Reference

# List all booleans and their states
$ getsebool -a
$ semanage boolean -l

# Set a boolean persistently
# setsebool -P httpd_can_sendmail on

# Show rules gated by a boolean
$ sesearch --bool httpd_can_sendmail -A

# Audit boolean changes
$ ausearch -m MAC_CONFIG_CHANGE -ts today
ACHIEVEMENT UNLOCKED

Boolean Master

You understand how booleans work at the policy level and can diagnose misconfiguration without guessing. +200 XP

Next: Level 5 - Container Security with SELinux