From: "Christopher J. PeBenito" <cpebenito@tresys.com>
To: SELinux Mail List <selinux@tycho.nsa.gov>
Cc: joe@nall.com
Subject: MLS directory write constraints
Date: Mon, 20 Aug 2007 08:34:57 -0400 [thread overview]
Message-ID: <1187613297.27524.10.camel@gorn> (raw)
After doing some work on some MLS systems last week, I observed some
constraint denials like this:
type=AVC msg=audit(1187122358.679:120): avc: denied { write } for
pid=2829 comm="foo" name="run" dev=dm-0 ino=3309608
scontext=system_u:system_r:foo_t:s15:c0.c1023
tcontext=system_u:object_r:var_run_t:s0-s15:c0.c1023
tclass=dir
Where a daemon has TE rules for creating it's PID file in /var/run, but
gets denied by this MLS constraint:
mlsconstrain { file ... dir ... } { write create setattr relabelfrom append unlink link rename mounton }
(( l1 eq l2 ) or
(( t1 == mlsfilewritetoclr ) and ( h1 dom l2 ) and ( l1 domby l2 )) or
(( t2 == mlsfilewriteinrange ) and ( l1 dom l2 ) and ( h1 domby h2 )) or
( t1 == mlsfilewrite ) or
( t2 == mlstrustedobject ));
It seems like it should be able to create a file in the directory, since
the daemon's level is within the range of the directory. The
constraints for the other dir-specific permissions seems to confirm
this:
mlsconstrain dir { add_name remove_name reparent rmdir }
((( l1 dom l2 ) and ( l1 domby h2 )) or
(( t1 == mlsfilewritetoclr ) and ( h1 dom l2 ) and ( l1 domby l2 )) or
( t1 == mlsfilewrite ) or
( t2 == mlstrustedobject ));
But since creating or deleting a file in a directory requires write and
add_name or remove_name, respectively, you still must have equality in
level to create a file in /var/run. Because of this, I believe there
potentially are superfluous write downs for daemons that don't run in
system low. I think the constraints should be changed to this:
# single level "write"
mlsconstrain { file ... } { write create setattr relabelfrom append unlink link rename mounton }
(( l1 eq l2 ) or
(( t1 == mlsfilewritetoclr ) and ( h1 dom l2 ) and ( l1 domby l2 )) or
(( t2 == mlsfilewriteinrange ) and ( l1 dom l2 ) and ( h1 domby h2 )) or
( t1 == mlsfilewrite ) or
( t2 == mlstrustedobject ));
mlsconstrain dir { create setattr relabelfrom append unlink link rename mounton reparent rmdir }
(( l1 eq l2 ) or
(( t1 == mlsfilewritetoclr ) and ( h1 dom l2 ) and ( l1 domby l2 )) or
(( t2 == mlsfilewriteinrange ) and ( l1 dom l2 ) and ( h1 domby h2 )) or
( t1 == mlsfilewrite ) or
( t2 == mlstrustedobject ));
# ranged "write" for adding and removing directory entries
mlsconstrain dir { write add_name remove_name }
((( l1 dom l2 ) and ( l1 domby h2 )) or
(( t1 == mlsfilewritetoclr ) and ( h1 dom l2 ) and ( l1 domby l2 )) or
( t1 == mlsfilewrite ) or
( t2 == mlstrustedobject ));
Comments?
--
Chris PeBenito
Tresys Technology, LLC
(410) 290-1411 x150
--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.
next reply other threads:[~2007-08-20 12:35 UTC|newest]
Thread overview: 6+ messages / expand[flat|nested] mbox.gz Atom feed top
2007-08-20 12:34 Christopher J. PeBenito [this message]
2007-08-20 20:52 ` MLS directory write constraints Klaus Weidner
2007-08-21 13:10 ` Christopher J. PeBenito
2007-08-23 23:05 ` Klaus Weidner
2007-08-24 14:10 ` Christopher J. PeBenito
2007-08-20 21:02 ` Klaus Weidner
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=1187613297.27524.10.camel@gorn \
--to=cpebenito@tresys.com \
--cc=joe@nall.com \
--cc=selinux@tycho.nsa.gov \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.