From: Antoine Tenart <antoine.tenart@bootlin.com>
To: buildroot@busybox.net
Subject: [Buildroot] [PATCH 10/15] package/refpolicy: allow providing user defined modules
Date: Fri, 31 Jul 2020 12:10:35 +0200 [thread overview]
Message-ID: <20200731101040.1723047-11-antoine.tenart@bootlin.com> (raw)
In-Reply-To: <20200731101040.1723047-1-antoine.tenart@bootlin.com>
Allow users to provide custom SELinux modules to be part of the final
policy. A new configuration variable is added, pointing to list of
directories containing the custom modules.
SELinux modules do require a metadata.xml file to be well integrated in
the refpolicy build. If this file isn't provided, it will be
automatically created.
For now, this option requires the extra modules to be directly into the
BR2_REFPOLICY_EXTRA_MODULES directory, and subfolders aren't supported.
They may never be, as having subfolders could introduce issues when two
different modules have the same name (which isn't supported by the
refpolicy).
Signed-off-by: Antoine Tenart <antoine.tenart@bootlin.com>
---
package/refpolicy/Config.in | 10 ++++++++++
package/refpolicy/refpolicy.mk | 23 ++++++++++++++++++++++-
2 files changed, 32 insertions(+), 1 deletion(-)
diff --git a/package/refpolicy/Config.in b/package/refpolicy/Config.in
index b50b2f09ff79..030b1e93c9bd 100644
--- a/package/refpolicy/Config.in
+++ b/package/refpolicy/Config.in
@@ -54,6 +54,16 @@ config BR2_PACKAGE_REFPOLICY_POLICY_STATE
default "enforcing" if BR2_PACKAGE_REFPOLICY_POLICY_STATE_ENFORCING
default "disabled" if BR2_PACKAGE_REFPOLICY_POLICY_STATE_DISABLED
+config BR2_REFPOLICY_EXTRA_MODULES_DIRS
+ string "Extra modules directories"
+ help
+ Specify directories containing SELinux modules that will be build
+ in the SELinux policy. The modules will be automatically enabled in
+ the policy.
+
+ Each of those directories must contain the SELinux policy .fc, .if
+ and .te files directly at the top-level, with no sub-directories.
+
endif
comment "refpolicy needs a toolchain w/ threads"
diff --git a/package/refpolicy/refpolicy.mk b/package/refpolicy/refpolicy.mk
index c29912a53b0b..edbb5a228f55 100644
--- a/package/refpolicy/refpolicy.mk
+++ b/package/refpolicy/refpolicy.mk
@@ -46,7 +46,26 @@ REFPOLICY_MODULES = \
sysnetwork \
unconfined \
userdomain \
- $(PACKAGES_SELINUX_MODULES)
+ $(PACKAGES_SELINUX_MODULES) \
+ $(foreach d,$(call qstrip,$(REFPOLICY_EXTRA_MODULES)),\
+ $(basename $(notdir $(wildcard $(d)/*.te))))
+
+# Allow to provide out-of-tree SELinux modules in addition to the ones in the
+# refpolicy.
+REFPOLICY_EXTRA_MODULES = $(BR2_REFPOLICY_EXTRA_MODULES_DIRS)
+$(foreach dir,$(call qstrip,$(BR2_REFPOLICY_EXTRA_MODULES_DIRS)),\
+ $(if $(wildcard $(dir)),,\
+ $(error BR2_REFPOLICY_EXTRA_MODULES_DIRS contains nonexistent directory $(dir))))
+
+define REFPOLICY_COPY_MODULES
+ mkdir -p $(@D)/policy/modules/buildroot
+ rsync -au $(addsuffix /*,$(call qstrip,$(REFPOLICY_EXTRA_MODULES))) \
+ $(@D)/policy/modules/buildroot/
+ if [ ! -f $(@D)/policy/modules/buildroot/metadata.xml ]; then \
+ echo "<summary>Buildroot extra modules</summary>" > \
+ $(@D)/policy/modules/buildroot/metadata.xml; \
+ fi
+endef
# In the context of a monolithic policy enabling a piece of the policy as
# 'base' or 'module' is equivalent, so we enable them as 'base'.
@@ -72,6 +91,8 @@ define REFPOLICY_CONFIGURE_CMDS
endef
define REFPOLICY_BUILD_CMDS
+ $(if $(call qstrip,$(REFPOLICY_EXTRA_MODULES)),\
+ $(REFPOLICY_COPY_MODULES))
$(REFPOLICY_MAKE) -C $(@D) DESTDIR=$(STAGING_DIR) bare conf
$(REFPOLICY_CONFIGURE_MODULES)
endef
--
2.26.2
next prev parent reply other threads:[~2020-07-31 10:10 UTC|newest]
Thread overview: 33+ messages / expand[flat|nested] mbox.gz Atom feed top
2020-07-31 10:10 [Buildroot] [PATCH 00/15] Improve SELinux support Antoine Tenart
2020-07-31 10:10 ` [Buildroot] [PATCH 01/15] package/e2fsprogs: set xattrs for the root dir as well Antoine Tenart
2020-07-31 10:10 ` [Buildroot] [PATCH 02/15] fs/common.mk: set SELinux file security contexts Antoine Tenart
2020-09-04 12:58 ` Thomas Petazzoni
2020-07-31 10:10 ` [Buildroot] [PATCH 03/15] fs/common.mk: move down ROOTFS_REPRODUCIBLE for consistency Antoine Tenart
2020-07-31 10:10 ` [Buildroot] [PATCH 04/15] package/refpolicy: smaller monolithic policy Antoine Tenart
2020-07-31 10:10 ` [Buildroot] [PATCH 05/15] package/refpolicy: allow packages to select SELinux modules Antoine Tenart
2020-07-31 10:10 ` [Buildroot] [PATCH 06/15] package/systemd: " Antoine Tenart
2020-07-31 10:10 ` [Buildroot] [PATCH 07/15] package/dbus: select SELinux module Antoine Tenart
2020-07-31 10:10 ` [Buildroot] [PATCH 08/15] package/util-linux: " Antoine Tenart
2020-07-31 10:10 ` [Buildroot] [PATCH 09/15] package/e2fsprogs: " Antoine Tenart
2020-07-31 10:10 ` Antoine Tenart [this message]
2020-09-04 13:05 ` [Buildroot] [PATCH 10/15] package/refpolicy: allow providing user defined modules Thomas Petazzoni
2020-09-04 15:00 ` Antoine Tenart
2020-09-04 15:10 ` Thomas Petazzoni
2020-09-04 15:28 ` Antoine Tenart
2020-07-31 10:10 ` [Buildroot] [PATCH 11/15] package/refpolicy: allow selecting additional modules Antoine Tenart
2020-07-31 10:10 ` [Buildroot] [PATCH 12/15] package/refpolicy: allow to provide a custom refpolicy Antoine Tenart
2020-07-31 10:10 ` [Buildroot] [PATCH 13/15] package/refpolicy: allow packages to provide their own SELinux modules Antoine Tenart
2020-07-31 10:10 ` [Buildroot] [PATCH 14/15] package/refpolicy: fix the configure, build and install steps Antoine Tenart
2020-09-04 13:07 ` Thomas Petazzoni
2020-07-31 10:10 ` [Buildroot] [PATCH 15/15] docs/manual: add a section about SELinux Antoine Tenart
2020-07-31 12:15 ` Matthew Weber
2020-07-31 12:52 ` Antoine Tenart
2020-07-31 13:15 ` Thomas Petazzoni
2020-07-31 13:19 ` Matthew Weber
2020-07-31 13:22 ` Antoine Tenart
2020-09-04 13:09 ` Thomas Petazzoni
2020-07-31 17:08 ` [Buildroot] [PATCH 00/15] Improve SELinux support Adam Duskett
2020-07-31 20:48 ` Adam Duskett
2020-08-01 8:12 ` Antoine Tenart
2020-08-01 8:05 ` Antoine Tenart
2020-09-04 12:56 ` Thomas Petazzoni
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20200731101040.1723047-11-antoine.tenart@bootlin.com \
--to=antoine.tenart@bootlin.com \
--cc=buildroot@busybox.net \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox