From: Chuck Lever III <chuck.lever@oracle.com>
To: Paul Moore <paul@paul-moore.com>
Cc: Scott Mayhew <smayhew@redhat.com>,
Stephen Smalley <stephen.smalley.work@gmail.com>,
"casey@schaufler-ca.com" <casey@schaufler-ca.com>,
"marek.gresko@protonmail.com" <marek.gresko@protonmail.com>,
"selinux@vger.kernel.org" <selinux@vger.kernel.org>,
"linux-security-module@vger.kernel.org"
<linux-security-module@vger.kernel.org>,
Linux NFS Mailing List <linux-nfs@vger.kernel.org>
Subject: Re: [PATCH 1/1] selinux,smack: don't bypass permissions check in inode_setsecctx hook
Date: Thu, 29 Aug 2024 14:16:30 +0000 [thread overview]
Message-ID: <288CD342-1534-4FF3-9B2D-7E824FF4AA20@oracle.com> (raw)
In-Reply-To: <CAHC9VhS3yhOxZYD1gZ-HF5XkGq0Qr8h4n+XrttUBsHL4cg0Xww@mail.gmail.com>
> On Aug 28, 2024, at 7:19 PM, Paul Moore <paul@paul-moore.com> wrote:
>
> On Wed, Aug 28, 2024 at 5:05 PM Paul Moore <paul@paul-moore.com> wrote:
>> On Wed, Aug 28, 2024 at 3:51 PM Scott Mayhew <smayhew@redhat.com> wrote:
>>>
>>> Marek Gresko reports that the root user on an NFS client is able to
>>> change the security labels on files on an NFS filesystem that is
>>> exported with root squashing enabled.
>>>
>>> The end of the kerneldoc comment for __vfs_setxattr_noperm() states:
>>>
>>> * This function requires the caller to lock the inode's i_mutex before it
>>> * is executed. It also assumes that the caller will make the appropriate
>>> * permission checks.
>>>
>>> nfsd_setattr() does do permissions checking via fh_verify() and
>>> nfsd_permission(), but those don't do all the same permissions checks
>>> that are done by security_inode_setxattr() and its related LSM hooks do.
>>>
>>> Since nfsd_setattr() is the only consumer of security_inode_setsecctx(),
>>> simplest solution appears to be to replace the call to
>>> __vfs_setxattr_noperm() with a call to __vfs_setxattr_locked(). This
>>> fixes the above issue and has the added benefit of causing nfsd to
>>> recall conflicting delegations on a file when a client tries to change
>>> its security label.
>>>
>>> Reported-by: Marek Gresko <marek.gresko@protonmail.com>
>>> Link: https://bugzilla.kernel.org/show_bug.cgi?id=218809
>>> Signed-off-by: Scott Mayhew <smayhew@redhat.com>
>>> ---
>>> security/selinux/hooks.c | 4 ++--
>>> security/smack/smack_lsm.c | 4 ++--
>>> 2 files changed, 4 insertions(+), 4 deletions(-)
>>
>> Thanks Scott, this looks good to me, but since it touches Smack too
>> I'd also like to get Casey's ACK on this patch; if for some reason we
>> don't hear from Casey after a bit I'll go ahead and merge it.
>> Speaking of merging, since this touches both SELinux and Smack I'll
>> likely pull this in via the LSM tree, with a marking for the stable
>> kernels, if anyone has any objections to that please let me know.
>
> Merged into lsm/stable-6.11 so we can get this into linux-next and the
> automated SELinux testing, assuming all goes we'll I'll send this up
> to Linus later this week. Thanks all!
Paul, may I recommend adding Cc: stable once your testing passes?
--
Chuck Lever
next prev parent reply other threads:[~2024-08-29 14:16 UTC|newest]
Thread overview: 12+ messages / expand[flat|nested] mbox.gz Atom feed top
2024-08-28 19:51 [PATCH 0/1] selinux,smack: don't bypass permissions check in inode_setsecctx hook Scott Mayhew
2024-08-28 19:51 ` [PATCH 1/1] " Scott Mayhew
2024-08-28 20:03 ` Jeff Layton
2024-08-28 21:05 ` Paul Moore
2024-08-28 21:28 ` Casey Schaufler
2024-08-28 23:08 ` Paul Moore
2024-08-28 23:19 ` Paul Moore
2024-08-29 14:16 ` Chuck Lever III [this message]
2024-08-29 14:51 ` Paul Moore
2024-08-28 21:08 ` Chuck Lever
2024-08-29 11:15 ` Jeff Layton
2024-08-29 13:03 ` Stephen Smalley
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=288CD342-1534-4FF3-9B2D-7E824FF4AA20@oracle.com \
--to=chuck.lever@oracle.com \
--cc=casey@schaufler-ca.com \
--cc=linux-nfs@vger.kernel.org \
--cc=linux-security-module@vger.kernel.org \
--cc=marek.gresko@protonmail.com \
--cc=paul@paul-moore.com \
--cc=selinux@vger.kernel.org \
--cc=smayhew@redhat.com \
--cc=stephen.smalley.work@gmail.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox