From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-qv1-f44.google.com (mail-qv1-f44.google.com [209.85.219.44]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id A0B3F1DDC11 for ; Mon, 7 Oct 2024 19:36:01 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.219.44 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1728329766; cv=none; b=V9OZMM+Q3JCfIY0Hpv3qqTT/Lnynsv2Z5Zk2nzcx7rmJR4QfgKifaFukaHFc7aIs6gi+IOBc1BEhihNKaX0d5BTz6wp/n+Wp0iVuuPSVRKj26nF5A/KmVQorl87hj5q2WULBMUQjgD2YLrHXZE68QqWrbEUFK4DAXkmz0LEtMQA= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1728329766; c=relaxed/simple; bh=3Thk8GfsbyfX5EsFk6+OY40jBkNafR2rbD2048NAVpY=; h=Message-ID:Date:MIME-Version:Subject:To:References:From: In-Reply-To:Content-Type; b=MUpgaqZM6oLUjwZpxnMG4Rdqel1Bm5laNFqLXysSwe6UPYUXq/Oe0zl2fUUppETz1ZFu+jitb4TA32aCqzOrb6Uj91rJdsCW5QCaUpekmyjWy6dI3x84/9ZRF2iCzBBWA4+hW58VWv1S7RfCbd+qm1wPuQqEgzrbmGdPg4Z+bis= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=ieee.org; spf=pass smtp.mailfrom=ieee.org; dkim=pass (1024-bit key) header.d=ieee.org header.i=@ieee.org header.b=fP0U5Fh1; arc=none smtp.client-ip=209.85.219.44 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=ieee.org Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=ieee.org Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=ieee.org header.i=@ieee.org header.b="fP0U5Fh1" Received: by mail-qv1-f44.google.com with SMTP id 6a1803df08f44-6cb2ad51162so43463076d6.3 for ; Mon, 07 Oct 2024 12:36:01 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ieee.org; s=google; t=1728329760; x=1728934560; darn=vger.kernel.org; h=content-transfer-encoding:in-reply-to:from:content-language :references:to:subject:user-agent:mime-version:date:message-id:from :to:cc:subject:date:message-id:reply-to; bh=LuhJPs3mLHhEjCf027O7jpMd6LW+aIaMR62xT1aR3ZY=; b=fP0U5Fh19AqJa6uws/DKdWaW1hZMfsncyCGrJtBUbVJ4e1UjHytmH7UZ0DmHc6o/P1 tSlpeW1+jdXWC8JMQyYZT1sJBKM1nZpb2VjbdNHRVxRN1lSmVi/kz446E2GIkr2yofNQ m31ZYpt/Wx4D7bWQSN49RGVwqwiZPlm3saL+M= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1728329760; x=1728934560; h=content-transfer-encoding:in-reply-to:from:content-language :references:to:subject:user-agent:mime-version:date:message-id :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to; bh=LuhJPs3mLHhEjCf027O7jpMd6LW+aIaMR62xT1aR3ZY=; b=J3JSYAacap7bxyV7KU8LSLAYDEOww7nzWoNozGnJDFlrcpuTEKp6IUsYN+j3HL2We+ vUC/KL13qeJsjFTNlF/cmGsPZEhZcKZQfco4Vw1MnvMEE8tYCmVSHovalyU0Oskz+2o3 CDznIxXQuizHkMr2f+NKLqyWsHwA1ilTvYuo5tWHKhleKrvO6MVyFnQ6GirFh4LwtFyw Ilw6QkkZGp9mtYsuILU7Xspi9aKZFdpbZr/St1EcjqAaPSGc9bS0qHPL5kM6kHYvSEaS pWdp5ySrG02tykEk9btVZb/p3UoQhQFQ3r5+9UAblNUKXcxYBwNX61lQ4V4MRKkHbb93 G8UA== X-Forwarded-Encrypted: i=1; AJvYcCW2vHoZxEVQBkDyuhvv4AJqhnBzbRkdGA4+s2FyNkyJsZCbRdKUvHiPQyH/tyn5SKiRkDQ30VNAOAykwZ6iarD0gw==@vger.kernel.org X-Gm-Message-State: AOJu0YwthAHdi4dCNkd1RD9HHncQ1b+rzfdGEj0UF9cjvc7iKQksyPAF +SzbMkLxOZ+uLT2ICT4Xv7HAqghJ8gFy9Cx/GtZAx2CSuyJ8JI9Y+oIbaWZ3+JLQ+9p9n2cBdhi D1Q== X-Google-Smtp-Source: AGHT+IEL9LWcIRavowse1EOKPv2cLCdKTYljCtlosexJerTpYO8xLChb5EgcUc3q4VChpQZMHwKt2w== X-Received: by 2002:a05:6214:570c:b0:6cb:7396:ee37 with SMTP id 6a1803df08f44-6cb9a466555mr230015066d6.42.1728329760523; Mon, 07 Oct 2024 12:36:00 -0700 (PDT) Received: from ?IPV6:2601:145:c200:2c70:8411:bad9:7549:e9f3? ([2601:145:c200:2c70:8411:bad9:7549:e9f3]) by smtp.gmail.com with ESMTPSA id 6a1803df08f44-6cba4773b54sm28492276d6.135.2024.10.07.12.36.00 (version=TLS1_3 cipher=TLS_AES_128_GCM_SHA256 bits=128/128); Mon, 07 Oct 2024 12:36:00 -0700 (PDT) Message-ID: <3ebc1ec3-4d2b-473b-a91d-b4772bdc55b4@ieee.org> Date: Mon, 7 Oct 2024 15:35:57 -0400 Precedence: bulk X-Mailing-List: selinux-refpolicy@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 User-Agent: Mozilla Thunderbird Subject: Re: cupsd_t and sys_admin To: Russell Coker , SELinux Reference Policy mailing list References: <22446657.EfDdHjke4D@cupcakke> Content-Language: en-US From: Chris PeBenito In-Reply-To: <22446657.EfDdHjke4D@cupcakke> Content-Type: text/plain; charset=UTF-8; format=flowed Content-Transfer-Encoding: 7bit On 10/5/2024 5:26 AM, Russell Coker wrote: > allow cupsd_t self:capability { chown dac_override dac_read_search fowner > fsetid ipc_lock kill setgid setuid sys_admin sys_rawio sys_resource > sys_tty_config }; > > From the refpolicy the above is the capabilities line for cupsd_t. Why does > it have sys_admin? I don't think it has a legitimate need to do anything that Nothing I can tell you beyond what is in the commit history. The cap has been there since it was added to refpolicy, so it probably was in the old NSA example policy. See ef5ca0fb79191e6af897c58d97977e919b34ec17 back in 2005. > needs that access. Also sys_rawio seems dubious. This came in from Dan in 2009, 8f3bddfbfdedf84838c0232a7f30b510ca673fa3. > virt_rw_all_image_chr_files(cupsd_t) > > Also what is the above about? This came while cups was in the contrib git submodule in 2012, ba518eba315d79afb9df2f19300dc2d18005e5f8. If you share a printer device, libvirt relabels it to the image file type. -- Chris PeBenito