From: Luke Kenneth Casson Leighton <lkcl@lkcl.net>
To: selinux@tycho.nsa.gov
Subject: suggestion to help transition to selinux: dynamic loading of libselinux
Date: Sat, 15 May 2004 23:26:06 +0000 [thread overview]
Message-ID: <20040515232606.GA9378@lkcl.net> (raw)
dear nsa et al,
love selinux principle. it's _got_ to be made easier.
idea: make all the modifications to e.g. coreutils, login etc.
compile with the header files but not necessarily _need_
libselinux at run-time.
way to do that is the same way that libdvdcss is loaded by
libdvdread: dynamically [there are plenty of other programs
that use the same technique].
the suggestion is based on the premise that if you have a
non-selinux kernel, and no libselinux installed, the programs
(pam, coreutils, login etc.) will attempt to dynamically load
libselinux (with dlopen), find it missing, _won't care_
and will adapt and proceed knowing that there's no security
enhancements - i.e. as if they had never been patched to
deal with selinux in the first place;
whilst if they _do_ detect that libselinux is available, an
init function is called which returns a pointer to a vector
table of all the functions needed, which are then used;
and i presume that if such programs are compromised, and someone
attempts to _stop_ libselinux from being loaded, well then
those programs will not be capable of making domain transitions
etc. and they will be useless [am i right?]
the technique of having one function available from a dynamic
library, which returns a table of all functions available in
the library, and which is accessed via dlsym is very common,
i am sure you have heard of it:
/* change all functions listed in this vector table from
extern to static: they are made accessible _only_ through
the vector table, instead
*/
static libselinux_vector_table fns =
{
is_selinux_enabled,
freecon,
freeconary,
getcon,
getpidcon,
getprevcon,
getexeccon,
....
....
fsetfilecon
}
extern libselinux_vector_table *libselinux_init_fn(void);
then you do this, in every program that requires access to
libselinux functions:
void *handle = dlopen("/usr/lib/libselinux.so", blah);
void *(void) fn = dlsym(handle, "libselinux_init_fn");
libselinux_vector_table *sel = (libselinux_vector_table*)(*fn)();
then, for example, in the patch to coreutils,
http://selinux.lemuria.org/newselinux/coreutils/coreutils.diff
in coreutils-5.0.91/src/copy.c line 1444 approx, instead of
++#ifdef WITH_SELINUX
++ if (x->preserve_security_context)
++ setfscreatecon(NULL);
++#endif
you have:
if (sel != NULL && x->preserve_security_context)
sel->setfscreatecon(NULL);
yes, correct: no #ifdef WITH_SELINUX :)
i.e. you must compile always with the header files, but you must NOT
require the library libselinux to be present in order for the program
to actually work.
this is a standard programming technique, i am sure that someone could
provide better examples of how it is deployed.
the advantage of deploying it is that at present there is
completely justifiable resistance upstream in accepting
patches to the core functionality of linux useability that
makes it impossible to use the core utilities for a non-selinux
environment (!), and this suggestion makes the reason for that
resistance go away.
i hope that you will consider adapting libselinux for use in this
manner, because the sooner the dual-maintenance of the "alternate"
versions of the core utils disappears, the better.
sincerely,
l.
p.s. please ask me for clarifications if needed or even for
patches rather than go "uhn? weirdo, weird language, can't
even touch a shift key, don't talk to him". i _want_ selinux
to be adapted mainstream by debian, quickly, so talk to me.
--
--
expecting email to be received and understood is a bit like
picking up the telephone and immediately dialing without
checking for a dial-tone; speaking immediately without listening
for either an answer or ring-tone; hanging up immediately and
believing that you have actually started a conversation.
--
<a href="http://lkcl.net"> lkcl.net </a> <br />
<a href="mailto:lkcl@lkcl.net"> lkcl@lkcl.net </a> <br />
--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.
next reply other threads:[~2004-05-17 16:43 UTC|newest]
Thread overview: 18+ messages / expand[flat|nested] mbox.gz Atom feed top
2004-05-15 23:26 Luke Kenneth Casson Leighton [this message]
2004-05-17 19:10 ` suggestion to help transition to selinux: dynamic loading of libselinux Russell Coker
2004-05-17 21:56 ` Luke Kenneth Casson Leighton
2004-05-18 0:45 ` Russell Coker
2004-05-18 0:45 ` Valdis.Kletnieks
2004-05-17 22:02 ` Luke Kenneth Casson Leighton
2004-05-18 0:43 ` Russell Coker
2004-05-18 11:31 ` Stephen Smalley
2004-05-18 13:46 ` Russell Coker
2004-05-18 16:34 ` Stephen Smalley
2004-05-18 19:11 ` Luke Kenneth Casson Leighton
2004-05-18 19:52 ` Russell Coker
-- strict thread matches above, loose matches on Subject: below --
2004-05-18 6:20 Chris Babcock
2004-05-18 9:50 Les Bell
2004-05-18 11:44 ` Luke Kenneth Casson Leighton
2004-05-18 14:07 ` Russell Coker
2004-05-18 14:19 ` Chris Babcock
2004-05-18 14:49 ` Russell Coker
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20040515232606.GA9378@lkcl.net \
--to=lkcl@lkcl.net \
--cc=selinux@tycho.nsa.gov \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.