All of lore.kernel.org
 help / color / mirror / Atom feed
* MLS directory write constraints
@ 2007-08-20 12:34 Christopher J. PeBenito
  2007-08-20 20:52 ` Klaus Weidner
  2007-08-20 21:02 ` Klaus Weidner
  0 siblings, 2 replies; 6+ messages in thread
From: Christopher J. PeBenito @ 2007-08-20 12:34 UTC (permalink / raw)
  To: SELinux Mail List; +Cc: joe

After doing some work on some MLS systems last week, I observed some
constraint denials like this:

type=AVC msg=audit(1187122358.679:120): avc:  denied  { write } for
pid=2829 comm="foo" name="run" dev=dm-0 ino=3309608
scontext=system_u:system_r:foo_t:s15:c0.c1023
tcontext=system_u:object_r:var_run_t:s0-s15:c0.c1023
tclass=dir

Where a daemon has TE rules for creating it's PID file in /var/run, but
gets denied by this MLS constraint:

mlsconstrain { file ... dir ... } { write create setattr relabelfrom append unlink link rename mounton }
	(( l1 eq l2 ) or
	 (( t1 == mlsfilewritetoclr ) and ( h1 dom l2 ) and ( l1 domby l2 )) or
	 (( t2 == mlsfilewriteinrange ) and ( l1 dom l2 ) and ( h1 domby h2 )) or
	 ( t1 == mlsfilewrite ) or
	 ( t2 == mlstrustedobject ));

It seems like it should be able to create a file in the directory, since
the daemon's level is within the range of the directory.  The
constraints for the other dir-specific permissions seems to confirm
this:

mlsconstrain dir { add_name remove_name reparent rmdir }
	((( l1 dom l2 ) and ( l1 domby h2 )) or
	 (( t1 == mlsfilewritetoclr ) and ( h1 dom l2 ) and ( l1 domby l2 )) or
	 ( t1 == mlsfilewrite ) or
	 ( t2 == mlstrustedobject ));

But since creating or deleting a file in a directory requires write and
add_name or remove_name, respectively, you still must have equality in
level to create a file in /var/run.  Because of this, I believe there
potentially are superfluous write downs for daemons that don't run in
system low.  I think the constraints should be changed to this:

# single level "write"
mlsconstrain { file ... } { write create setattr relabelfrom append unlink link rename mounton }
	(( l1 eq l2 ) or
	 (( t1 == mlsfilewritetoclr ) and ( h1 dom l2 ) and ( l1 domby l2 )) or
	 (( t2 == mlsfilewriteinrange ) and ( l1 dom l2 ) and ( h1 domby h2 )) or
	 ( t1 == mlsfilewrite ) or
	 ( t2 == mlstrustedobject ));

mlsconstrain dir { create setattr relabelfrom append unlink link rename mounton reparent rmdir }
	(( l1 eq l2 ) or
	 (( t1 == mlsfilewritetoclr ) and ( h1 dom l2 ) and ( l1 domby l2 )) or
	 (( t2 == mlsfilewriteinrange ) and ( l1 dom l2 ) and ( h1 domby h2 )) or
	 ( t1 == mlsfilewrite ) or
	 ( t2 == mlstrustedobject ));

# ranged "write" for adding and removing directory entries
mlsconstrain dir { write add_name remove_name }
	((( l1 dom l2 ) and ( l1 domby h2 )) or
	 (( t1 == mlsfilewritetoclr ) and ( h1 dom l2 ) and ( l1 domby l2 )) or
	 ( t1 == mlsfilewrite ) or
	 ( t2 == mlstrustedobject ));

Comments?

-- 
Chris PeBenito
Tresys Technology, LLC
(410) 290-1411 x150


--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.

^ permalink raw reply	[flat|nested] 6+ messages in thread

end of thread, other threads:[~2007-08-24 14:11 UTC | newest]

Thread overview: 6+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2007-08-20 12:34 MLS directory write constraints Christopher J. PeBenito
2007-08-20 20:52 ` Klaus Weidner
2007-08-21 13:10   ` Christopher J. PeBenito
2007-08-23 23:05     ` Klaus Weidner
2007-08-24 14:10       ` Christopher J. PeBenito
2007-08-20 21:02 ` Klaus Weidner

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.