All of lore.kernel.org
 help / color / mirror / Atom feed
From: Russell Coker <russell@coker.com.au>
To: Stephen Smalley <sds@epoch.ncsc.mil>, "SE-Linux" <selinux@tycho.nsa.gov>
Subject: tun/tap and SE Linux in 2.6.32
Date: Wed, 9 Dec 2009 12:32:24 +1100	[thread overview]
Message-ID: <200912091232.26387.russell@coker.com.au> (raw)


----------  Forwarded Message  ----------

Subject: selinux permissive blocking tun/tap device creation in v2.6.32
Date: Wed, 9 Dec 2009
From: Andrew Worsley <amworsley@gmail.com>
To: luv-main@luv.asn.au

I upgraded to the v2.6.32 kernel and I found tunctl would fail with
the  ioctl TUNSETIFF rejected with an EINVAL. A real pain when running
vpn and kvms which use these.

I don't know where to go from this - so directions as to where to post
/ look would be appreciated but at least I can now create tap
interfaces.

I am looking for suggestions where I should post this to find a fix or
other better work around than merely commenting out this code...

   Andrew

I eventually traced this via recompiling the tun module with tracing
to this code:


            printk(KERN_INFO "tun: tun_set_iff () 10\n");
                if (!capable(CAP_NET_ADMIN))
                        return -EPERM;
            printk(KERN_INFO "tun: tun_set_iff () 11\n");
#if 0
                err = security_tun_dev_create();
                if (err < 0)
                        return err;
#endif

            printk(KERN_INFO "tun: tun_set_iff () 12\n");
                /* Set dev type */
                if (ifr->ifr_flags & IFF_TUN) {
                        /* TUN device */

in drivers/net/tun.c (commenting out the above allows the tunctl
command to work!)

Tracing this back a bit I think it's this code:

int avc_has_perm(u32 ssid, u32 tsid, u16 tclass,
                 u32 requested, struct common_audit_data *auditdata)
{
        struct av_decision avd;
        int rc;

        rc = avc_has_perm_noaudit(ssid, tsid, tclass, requested, 0, &avd);
        avc_audit(ssid, tsid, tclass, requested, &avd, rc, auditdata);
        return rc;
}

in security/selinux/avc.c which doesn't check for permissive mode or
sellinux disabled as other code in the same file appears to.

I believe this is called from:

static int selinux_tun_dev_create(void)
{
        u32 sid = current_sid();

        /* we aren't taking into account the "sockcreate" SID since the socket
         * that is being created here is not a socket in the traditional 
sense,
         * instead it is a private sock, accessible only to the kernel, and
         * representing a wide range of network traffic spanning multiple
         * connections unlike traditional sockets - check the TUN driver to
         * get a better understanding of why this socket is special */

        return avc_has_perm(sid, sid, SECCLASS_TUN_SOCKET, TUN_SOCKET__CREATE,
                            NULL);
}
 in security/selinux/hooks.c

-------------------------------------------------------

-- 
russell@coker.com.au
http://etbe.coker.com.au/          My Main Blog
http://doc.coker.com.au/           My Documents Blog

--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.

             reply	other threads:[~2009-12-09  1:32 UTC|newest]

Thread overview: 5+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2009-12-09  1:32 Russell Coker [this message]
2009-12-09 20:48 ` tun/tap and SE Linux in 2.6.32 Paul Moore
2009-12-09 20:56   ` Russell Coker
2009-12-09 21:26     ` Stephen Smalley
2009-12-09 21:45     ` Paul Moore

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=200912091232.26387.russell@coker.com.au \
    --to=russell@coker.com.au \
    --cc=sds@epoch.ncsc.mil \
    --cc=selinux@tycho.nsa.gov \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.