All of lore.kernel.org
 help / color / mirror / Atom feed
From: Chris PeBenito <chpebeni@linux.microsoft.com>
To: SELinux mailing list <selinux@vger.kernel.org>
Cc: bluca@debian.org
Subject: RFC: Adding a dyntrans in systemd pid1's forking
Date: Wed, 6 Nov 2024 10:21:12 -0500	[thread overview]
Message-ID: <34e77b6f-2c76-4bf9-8e3f-ac01047c952d@linux.microsoft.com> (raw)

I've recently become aware of systemd's credentials feature[1].  In a 
nutshell, the intent is to reduce privilege in units by systemd itself 
copying the credentials (crypto materials, passwords, though in practice 
it could be anything) and placing it in /run/credentials, with access 
managed by namespacing.  This is intended to eliminate the need for the 
daemon in the unit directly accessing the data.  My concern is the 
possibility of inadvertently leaking credentials or abuse.  i.e. putting in

LoadCredential=foobar:/etc/shadow

This illustrative, as systemd can't read shadow if it's confined, but 
you could replace shadow with a private key or any other highly 
confidential data systemd needs to access.  The common response to my 
concern is systemd units should be protected at high integrity; only 
root can modify them, etc.  However, I think we can do better to reduce 
the possibility of errors.

I've discussed this with one of the systemd maintainers, and I'm 
proposing this change:

1. pid1 forks (to pidN) to run the unit, as usual.
2. pidN does security_compute_create() using the current domain and the 
label of the unit to get a new domain.
3. pidN does setcon() to the new domain.
4. pidN runs the unit as per usual (including the credentials stuff)

Then we'd need to add something like this to the policy:

allow init_t httpd_initrc_t:process dyntransition;
type_transition init_t httpd_unit_t:process httpd_initrc_t;

I have not yet prototyped this, but based on my discussion with the 
systemd maintainers, this should be doable.  I believe the added benefit 
is we can decompose initrc_t's privilege and maybe even reduce init_t's 
privilege.

What are your thoughts?


[1] https://systemd.io/CREDENTIALS/

--
Chris

             reply	other threads:[~2024-11-06 15:21 UTC|newest]

Thread overview: 4+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2024-11-06 15:21 Chris PeBenito [this message]
2024-11-13 16:07 ` RFC: Adding a dyntrans in systemd pid1's forking Chris PeBenito
2024-11-13 18:07   ` Kenton Groombridge
2024-11-13 19:29     ` Chris PeBenito

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=34e77b6f-2c76-4bf9-8e3f-ac01047c952d@linux.microsoft.com \
    --to=chpebeni@linux.microsoft.com \
    --cc=bluca@debian.org \
    --cc=selinux@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.