From: Russell Coker <russell@coker.com.au>
To: selinux-refpolicy@vger.kernel.org
Subject: lockdown class
Date: Fri, 11 Dec 2020 18:01:58 +1100 [thread overview]
Message-ID: <2911391.mirxchbQ87@liv> (raw)
allow systemd_modules_load_t systemd_modules_load_t:lockdown integrity;
allow udev_t udev_t:lockdown confidentiality;
I've seen access that caused the above to be generated from audit2allow.
/var/log/audit/audit.log.1:type=AVC msg=audit(1607515838.132:56): avc: denied
{ confidentiality } for pid=253 comm="systemd-udevd" lockdown_reason="use of
tracefs" scontext=system_u:system_r:udev_t:s0-s0:c0.c1023
tcontext=system_u:system_r:udev_t:s0-s0:c0.c1023 tclass=lockdown permissive=1
Above is the only log entry I've got for that from my previous testing (I
haven't been able to reproduce whatever it was that caused the
systemd_modules_load_t to get that audited).
https://www.paul-moore.com/blog/d/2020/03/linux_v56.html
I've read the above blog post and I'm still not sure exactly how we are to use
it. Do I allow this for systemd_modules_load_t because loading modules is an
integrity issue? Do I allow it for udev_t because changing device names etc
allows universal MITM attacks?
--
My Main Blog http://etbe.coker.com.au/
My Documents Blog http://doc.coker.com.au/
next reply other threads:[~2020-12-11 7:04 UTC|newest]
Thread overview: 2+ messages / expand[flat|nested] mbox.gz Atom feed top
2020-12-11 7:01 Russell Coker [this message]
2020-12-14 15:13 ` lockdown class Chris PeBenito
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=2911391.mirxchbQ87@liv \
--to=russell@coker.com.au \
--cc=selinux-refpolicy@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.