From: "Christian Göttsche" <cgzones@googlemail.com>
To: selinux@vger.kernel.org
Subject: [PATCH SYSTEMD 0/7] Re-add SELinux checks for unit install operations
Date: Thu, 5 Aug 2021 16:24:38 +0200 [thread overview]
Message-ID: <20210805142445.61725-1-cgzones@googlemail.com> (raw)
The checks (permission verbs) in question are enable for the operations
enable, reenable, link and unmask and disable for the operations disable
and mask; those SELinux permissions exist in the the reference and fedora
SELinux policy.
These checks were dropped with v225 (see [1]) due to incomplete and
missing infrastructure in the unit handling code.
In addition the operations preset and revert are checked with the (also
already existing) SELinux permission reload.
(In the future I'd like to separate them into a new permission modify?
together with calls to the standard D-Bus interfaces at
org.freedesktop.DBus.Properties.Set.)
Job actions JOB_RELOAD_OR_START and JOB_VERIFY_ACTIVE are now checked with
the permission start instead of reload.
The D-Bus filter now falls back to an instance check in case no unit can
be decoded (e.g. the job has finished or the unit does not exist).
Reduced proposal of [2]/[3]
Closes: [4]
[1]: https://github.com/systemd/systemd/pull/1044
[2]: https://github.com/systemd/systemd/pull/10023
[3]: https://lore.kernel.org/selinux/20191218142808.30433-1-cgzones@googlemail.com/
[4]: https://github.com/systemd/systemd/issues/1050
Christian Göttsche (7):
selinux: add function name to audit data
selinux: improve debug log format
selinux: mark _mac_selinux_generic_access_check with leading
underscore
core: add support for MAC checks on unit install operations
core: implement the sd-bus generic callback for SELinux
core: avoid bypasses in D-BUS SELinux filter
core: tweak job_type_to_access_method SELinux permissions
src/core/dbus-callbackdata.h | 15 +++
src/core/dbus-manager.c | 70 +++++++---
src/core/dbus.c | 44 +++----
src/core/job.c | 14 +-
src/core/manager.c | 9 +-
src/core/manager.h | 1 +
src/core/selinux-access.c | 75 +++++++++--
src/core/selinux-access.h | 17 ++-
src/shared/install.c | 160 ++++++++++++++++++++---
src/shared/install.h | 44 +++++--
src/systemctl/systemctl-add-dependency.c | 2 +-
src/systemctl/systemctl-enable.c | 16 +--
src/systemctl/systemctl-is-enabled.c | 2 +-
src/systemctl/systemctl-preset-all.c | 2 +-
src/test/test-install-root.c | 88 ++++++-------
src/test/test-install.c | 38 +++---
16 files changed, 437 insertions(+), 160 deletions(-)
create mode 100644 src/core/dbus-callbackdata.h
--
2.32.0
next reply other threads:[~2021-08-05 14:26 UTC|newest]
Thread overview: 9+ messages / expand[flat|nested] mbox.gz Atom feed top
2021-08-05 14:24 Christian Göttsche [this message]
2021-08-05 14:24 ` [PATCH SYSTEMD 1/7] selinux: add function name to audit data Christian Göttsche
2021-08-05 14:24 ` [PATCH SYSTEMD 2/7] selinux: improve debug log format Christian Göttsche
2021-08-05 14:24 ` [PATCH SYSTEMD 3/7] selinux: mark _mac_selinux_generic_access_check with leading underscore Christian Göttsche
2021-08-05 14:24 ` [PATCH SYSTEMD 4/7] core: add support for MAC checks on unit install operations Christian Göttsche
2021-08-05 14:24 ` [PATCH SYSTEMD 5/7] core: implement the sd-bus generic callback for SELinux Christian Göttsche
2021-08-05 14:24 ` [PATCH SYSTEMD 6/7] core: avoid bypasses in D-BUS SELinux filter Christian Göttsche
2021-08-05 14:24 ` [PATCH SYSTEMD 7/7] core: tweak job_type_to_access_method SELinux permissions Christian Göttsche
2021-08-05 15:08 ` [PATCH SYSTEMD 0/7] Re-add SELinux checks for unit install operations Dominick Grift
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20210805142445.61725-1-cgzones@googlemail.com \
--to=cgzones@googlemail.com \
--cc=selinux@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox