From: Jeff Layton <jlayton@kernel.org>
To: Scott Mayhew <smayhew@redhat.com>,
paul@paul-moore.com, stephen.smalley.work@gmail.com,
casey@schaufler-ca.com
Cc: chuck.lever@oracle.com, marek.gresko@protonmail.com,
selinux@vger.kernel.org, linux-security-module@vger.kernel.org,
linux-nfs@vger.kernel.org
Subject: Re: [PATCH 1/1] selinux,smack: don't bypass permissions check in inode_setsecctx hook
Date: Wed, 28 Aug 2024 16:03:38 -0400 [thread overview]
Message-ID: <8c2480c907d9312f9a238b4e182722dbbd237b31.camel@kernel.org> (raw)
In-Reply-To: <20240828195129.223395-2-smayhew@redhat.com>
On Wed, 2024-08-28 at 15:51 -0400, Scott Mayhew wrote:
> Marek Gresko reports that the root user on an NFS client is able to
> change the security labels on files on an NFS filesystem that is
> exported with root squashing enabled.
>
> The end of the kerneldoc comment for __vfs_setxattr_noperm() states:
>
> * This function requires the caller to lock the inode's i_mutex before it
> * is executed. It also assumes that the caller will make the appropriate
> * permission checks.
>
> nfsd_setattr() does do permissions checking via fh_verify() and
> nfsd_permission(), but those don't do all the same permissions checks
> that are done by security_inode_setxattr() and its related LSM hooks do.
>
> Since nfsd_setattr() is the only consumer of security_inode_setsecctx(),
> simplest solution appears to be to replace the call to
> __vfs_setxattr_noperm() with a call to __vfs_setxattr_locked(). This
> fixes the above issue and has the added benefit of causing nfsd to
> recall conflicting delegations on a file when a client tries to change
> its security label.
>
> Reported-by: Marek Gresko <marek.gresko@protonmail.com>
> Link: https://bugzilla.kernel.org/show_bug.cgi?id=218809
> Signed-off-by: Scott Mayhew <smayhew@redhat.com>
> ---
> security/selinux/hooks.c | 4 ++--
> security/smack/smack_lsm.c | 4 ++--
> 2 files changed, 4 insertions(+), 4 deletions(-)
>
> diff --git a/security/selinux/hooks.c b/security/selinux/hooks.c
> index bfa61e005aac..400eca4ad0fb 100644
> --- a/security/selinux/hooks.c
> +++ b/security/selinux/hooks.c
> @@ -6660,8 +6660,8 @@ static int selinux_inode_notifysecctx(struct inode *inode, void *ctx, u32 ctxlen
> */
> static int selinux_inode_setsecctx(struct dentry *dentry, void *ctx, u32 ctxlen)
> {
> - return __vfs_setxattr_noperm(&nop_mnt_idmap, dentry, XATTR_NAME_SELINUX,
> - ctx, ctxlen, 0);
> + return __vfs_setxattr_locked(&nop_mnt_idmap, dentry, XATTR_NAME_SELINUX,
> + ctx, ctxlen, 0, NULL);
> }
>
> static int selinux_inode_getsecctx(struct inode *inode, void **ctx, u32 *ctxlen)
> diff --git a/security/smack/smack_lsm.c b/security/smack/smack_lsm.c
> index 4164699cd4f6..002a1b9ed83a 100644
> --- a/security/smack/smack_lsm.c
> +++ b/security/smack/smack_lsm.c
> @@ -4880,8 +4880,8 @@ static int smack_inode_notifysecctx(struct inode *inode, void *ctx, u32 ctxlen)
>
> static int smack_inode_setsecctx(struct dentry *dentry, void *ctx, u32 ctxlen)
> {
> - return __vfs_setxattr_noperm(&nop_mnt_idmap, dentry, XATTR_NAME_SMACK,
> - ctx, ctxlen, 0);
> + return __vfs_setxattr_locked(&nop_mnt_idmap, dentry, XATTR_NAME_SMACK,
> + ctx, ctxlen, 0, NULL);
> }
>
> static int smack_inode_getsecctx(struct inode *inode, void **ctx, u32 *ctxlen)
Acked-by: Jeff Layton <jlayton@kernel.org>
next prev parent reply other threads:[~2024-08-28 20:03 UTC|newest]
Thread overview: 12+ messages / expand[flat|nested] mbox.gz Atom feed top
2024-08-28 19:51 [PATCH 0/1] selinux,smack: don't bypass permissions check in inode_setsecctx hook Scott Mayhew
2024-08-28 19:51 ` [PATCH 1/1] " Scott Mayhew
2024-08-28 20:03 ` Jeff Layton [this message]
2024-08-28 21:05 ` Paul Moore
2024-08-28 21:28 ` Casey Schaufler
2024-08-28 23:08 ` Paul Moore
2024-08-28 23:19 ` Paul Moore
2024-08-29 14:16 ` Chuck Lever III
2024-08-29 14:51 ` Paul Moore
2024-08-28 21:08 ` Chuck Lever
2024-08-29 11:15 ` Jeff Layton
2024-08-29 13:03 ` Stephen Smalley
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=8c2480c907d9312f9a238b4e182722dbbd237b31.camel@kernel.org \
--to=jlayton@kernel.org \
--cc=casey@schaufler-ca.com \
--cc=chuck.lever@oracle.com \
--cc=linux-nfs@vger.kernel.org \
--cc=linux-security-module@vger.kernel.org \
--cc=marek.gresko@protonmail.com \
--cc=paul@paul-moore.com \
--cc=selinux@vger.kernel.org \
--cc=smayhew@redhat.com \
--cc=stephen.smalley.work@gmail.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox