From: Antoine Tenart <antoine.tenart@bootlin.com>
To: buildroot@busybox.net
Subject: [Buildroot] [PATCH 00/15] Improve SELinux support
Date: Fri, 31 Jul 2020 12:10:25 +0200 [thread overview]
Message-ID: <20200731101040.1723047-1-antoine.tenart@bootlin.com> (raw)
Hi all,
This series aims at providing proper SELinux support in Buildroot. Some
of the building blocks were available, such as packages for refpolicy,
policycoreutils or libselinux; but getting to a point were a generated
image could be used with a loaded SELinux policy was not
straightforward. The series also adds support for customizing the
SELinux policy through various ways.
The first missing block was the ability to generate an SELinux-ready
image. SELinux depends on files' extended attributes, set based on the
policy. Those attributes could be set from within a running system with
the restorecon utility but that meant we had to special case the first
boot. That also prevented to build an image with SELinux in enforcing
mode as the first boot would have failed. This is fixed by setting and
copying files' extended attributes when generating filesystem images.
See patches 1 to 3.
Then more control is provided over what is included in the refpolicy. By
default the refpolicy provides lots of modules and rules for many
packages. All of those packages are not necessarily part of the target
system but all are built, resulting in a large monolithic policy and
lots of unused rules. We reworked the refpolicy to only include by
default 'base' modules and a small list of always-needed others. The
result is a much smaller binary policy. See patch 4.
On top of the more minimal SELinux policy, ways are provided in patches
5 to 14 to enable or provide extra modules. That allows to:
- Enable modules provided within the refpolicy from Buildroot packages
so that the resulting policy do include all the required rules. For
example, the dbus Buildroot packages enables the 'dbus' SELinux module
available in the refpolicy.
- Provide extra SELinux modules to be built in the policy, from
Buildroot packages.
- Enable modules available in the refpolicy from the Buildroot
configuration.
- Provide extra modules in user-defined folders.
- Override the refpolicy sources location and all of the above
mechanisms, as when designing a fully custom system, one could want to
provide a fully custom SELinux policy.
Finally, the documentation is updated in patch 15 to explain how to use
SELinux within Buildroot.
Thanks!
Antoine
Antoine Tenart (15):
package/e2fsprogs: set xattrs for the root dir as well
fs/common.mk: set SELinux file security contexts
fs/common.mk: move down ROOTFS_REPRODUCIBLE for consistency
package/refpolicy: smaller monolithic policy
package/refpolicy: allow packages to select SELinux modules
package/systemd: select SELinux modules
package/dbus: select SELinux module
package/util-linux: select SELinux module
package/e2fsprogs: select SELinux module
package/refpolicy: allow providing user defined modules
package/refpolicy: allow selecting additional modules
package/refpolicy: allow to provide a custom refpolicy
package/refpolicy: allow packages to provide their own SELinux modules
package/refpolicy: fix the configure, build and install steps
docs/manual: add a section about SELinux
docs/manual/manual.txt | 2 +
docs/manual/selinux-support.txt | 66 ++++++++++++++++
fs/common.mk | 23 ++++--
package/dbus/dbus.mk | 2 +
...-xattrs-to-the-root-directory-as-wel.patch | 46 +++++++++++
package/e2fsprogs/e2fsprogs.mk | 2 +
package/pkg-generic.mk | 6 ++
package/refpolicy/Config.in | 54 +++++++++++++
package/refpolicy/refpolicy.mk | 78 +++++++++++++++++--
package/systemd/systemd.mk | 2 +
package/util-linux/util-linux.mk | 4 +
11 files changed, 274 insertions(+), 11 deletions(-)
create mode 100644 docs/manual/selinux-support.txt
create mode 100644 package/e2fsprogs/0001-create_inode-set-xattrs-to-the-root-directory-as-wel.patch
--
2.26.2
next reply other threads:[~2020-07-31 10:10 UTC|newest]
Thread overview: 33+ messages / expand[flat|nested] mbox.gz Atom feed top
2020-07-31 10:10 Antoine Tenart [this message]
2020-07-31 10:10 ` [Buildroot] [PATCH 01/15] package/e2fsprogs: set xattrs for the root dir as well Antoine Tenart
2020-07-31 10:10 ` [Buildroot] [PATCH 02/15] fs/common.mk: set SELinux file security contexts Antoine Tenart
2020-09-04 12:58 ` Thomas Petazzoni
2020-07-31 10:10 ` [Buildroot] [PATCH 03/15] fs/common.mk: move down ROOTFS_REPRODUCIBLE for consistency Antoine Tenart
2020-07-31 10:10 ` [Buildroot] [PATCH 04/15] package/refpolicy: smaller monolithic policy Antoine Tenart
2020-07-31 10:10 ` [Buildroot] [PATCH 05/15] package/refpolicy: allow packages to select SELinux modules Antoine Tenart
2020-07-31 10:10 ` [Buildroot] [PATCH 06/15] package/systemd: " Antoine Tenart
2020-07-31 10:10 ` [Buildroot] [PATCH 07/15] package/dbus: select SELinux module Antoine Tenart
2020-07-31 10:10 ` [Buildroot] [PATCH 08/15] package/util-linux: " Antoine Tenart
2020-07-31 10:10 ` [Buildroot] [PATCH 09/15] package/e2fsprogs: " Antoine Tenart
2020-07-31 10:10 ` [Buildroot] [PATCH 10/15] package/refpolicy: allow providing user defined modules Antoine Tenart
2020-09-04 13:05 ` Thomas Petazzoni
2020-09-04 15:00 ` Antoine Tenart
2020-09-04 15:10 ` Thomas Petazzoni
2020-09-04 15:28 ` Antoine Tenart
2020-07-31 10:10 ` [Buildroot] [PATCH 11/15] package/refpolicy: allow selecting additional modules Antoine Tenart
2020-07-31 10:10 ` [Buildroot] [PATCH 12/15] package/refpolicy: allow to provide a custom refpolicy Antoine Tenart
2020-07-31 10:10 ` [Buildroot] [PATCH 13/15] package/refpolicy: allow packages to provide their own SELinux modules Antoine Tenart
2020-07-31 10:10 ` [Buildroot] [PATCH 14/15] package/refpolicy: fix the configure, build and install steps Antoine Tenart
2020-09-04 13:07 ` Thomas Petazzoni
2020-07-31 10:10 ` [Buildroot] [PATCH 15/15] docs/manual: add a section about SELinux Antoine Tenart
2020-07-31 12:15 ` Matthew Weber
2020-07-31 12:52 ` Antoine Tenart
2020-07-31 13:15 ` Thomas Petazzoni
2020-07-31 13:19 ` Matthew Weber
2020-07-31 13:22 ` Antoine Tenart
2020-09-04 13:09 ` Thomas Petazzoni
2020-07-31 17:08 ` [Buildroot] [PATCH 00/15] Improve SELinux support Adam Duskett
2020-07-31 20:48 ` Adam Duskett
2020-08-01 8:12 ` Antoine Tenart
2020-08-01 8:05 ` Antoine Tenart
2020-09-04 12:56 ` Thomas Petazzoni
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20200731101040.1723047-1-antoine.tenart@bootlin.com \
--to=antoine.tenart@bootlin.com \
--cc=buildroot@busybox.net \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox