From patchwork Fri Jun 1 18:28:45 2018 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Aaron Conole X-Patchwork-Id: 924301 Return-Path: X-Original-To: incoming@patchwork.ozlabs.org Delivered-To: patchwork-incoming@bilbo.ozlabs.org Authentication-Results: ozlabs.org; spf=pass (mailfrom) smtp.mailfrom=openvswitch.org (client-ip=140.211.169.12; helo=mail.linuxfoundation.org; envelope-from=ovs-dev-bounces@openvswitch.org; receiver=) Authentication-Results: ozlabs.org; dmarc=fail (p=none dis=none) header.from=redhat.com Received: from mail.linuxfoundation.org (mail.linuxfoundation.org [140.211.169.12]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ozlabs.org (Postfix) with ESMTPS id 40yCXz3X6Gz9s1w for ; Sat, 2 Jun 2018 04:29:39 +1000 (AEST) Received: from mail.linux-foundation.org (localhost [127.0.0.1]) by mail.linuxfoundation.org (Postfix) with ESMTP id 5E916C9E; Fri, 1 Jun 2018 18:28:59 +0000 (UTC) X-Original-To: dev@openvswitch.org Delivered-To: ovs-dev@mail.linuxfoundation.org Received: from smtp1.linuxfoundation.org (smtp1.linux-foundation.org [172.17.192.35]) by mail.linuxfoundation.org (Postfix) with ESMTPS id 285886C for ; Fri, 1 Jun 2018 18:28:57 +0000 (UTC) X-Greylist: domain auto-whitelisted by SQLgrey-1.7.6 Received: from mx1.redhat.com (mx3-rdu2.redhat.com [66.187.233.73]) by smtp1.linuxfoundation.org (Postfix) with ESMTPS id 7435D6B7 for ; Fri, 1 Jun 2018 18:28:56 +0000 (UTC) Received: from smtp.corp.redhat.com (int-mx05.intmail.prod.int.rdu2.redhat.com [10.11.54.5]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by mx1.redhat.com (Postfix) with ESMTPS id B63D15B5EC; Fri, 1 Jun 2018 18:28:55 +0000 (UTC) Received: from dhcp-25.97.bos.redhat.com (unknown [10.18.25.61]) by smtp.corp.redhat.com (Postfix) with ESMTP id 571038442B; Fri, 1 Jun 2018 18:28:55 +0000 (UTC) From: Aaron Conole To: dev@openvswitch.org Date: Fri, 1 Jun 2018 14:28:45 -0400 Message-Id: <20180601182849.12984-3-aconole@redhat.com> In-Reply-To: <20180601182849.12984-1-aconole@redhat.com> References: <20180601182849.12984-1-aconole@redhat.com> X-Scanned-By: MIMEDefang 2.79 on 10.11.54.5 X-Greylist: Sender IP whitelisted, not delayed by milter-greylist-4.5.16 (mx1.redhat.com [10.11.55.2]); Fri, 01 Jun 2018 18:28:55 +0000 (UTC) X-Greylist: inspected by milter-greylist-4.5.16 (mx1.redhat.com [10.11.55.2]); Fri, 01 Jun 2018 18:28:55 +0000 (UTC) for IP:'10.11.54.5' DOMAIN:'int-mx05.intmail.prod.int.rdu2.redhat.com' HELO:'smtp.corp.redhat.com' FROM:'aconole@redhat.com' RCPT:'' X-Spam-Status: No, score=-4.2 required=5.0 tests=BAYES_00, RCVD_IN_DNSWL_MED autolearn=ham version=3.3.1 X-Spam-Checker-Version: SpamAssassin 3.3.1 (2010-03-16) on smtp1.linux-foundation.org Cc: Flavio Leitner , Ansis Atteka Subject: [ovs-dev] [PATCH v3 2/6] selinux: create a transition type for module loading X-BeenThere: ovs-dev@openvswitch.org X-Mailman-Version: 2.1.12 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , MIME-Version: 1.0 Sender: ovs-dev-bounces@openvswitch.org Errors-To: ovs-dev-bounces@openvswitch.org Defines a type 'openvswitch_load_module_t' used exclusively for loading modules. This means that the 'openvswitch_t' domain won't require access to the module loading facility - such access can only happen after transitioning through the 'openvswitch_load_module_exec_t' transition context. A future commit will instruct the selinux policy on how to label the appropriate script with extended attributes to make use of this new domain. Acked-By: Timothy Redaelli Signed-off-by: Aaron Conole Acked-by: Ansis Atteka --- selinux/openvswitch-custom.te.in | 83 +++++++++++++++++++++++++++++++++++++--- 1 file changed, 78 insertions(+), 5 deletions(-) diff --git a/selinux/openvswitch-custom.te.in b/selinux/openvswitch-custom.te.in index db3cf6d8d..556e9d6a3 100644 --- a/selinux/openvswitch-custom.te.in +++ b/selinux/openvswitch-custom.te.in @@ -1,13 +1,31 @@ module openvswitch-custom 1.0.1; require { + role system_r; + role object_r; + type openvswitch_t; type openvswitch_rw_t; type openvswitch_tmp_t; type openvswitch_var_run_t; + type bin_t; type ifconfig_exec_t; + type init_t; + type init_var_run_t; + type insmod_exec_t; type hostname_exec_t; + type modules_conf_t; + type modules_object_t; + type passwd_file_t; + type plymouth_exec_t; + type proc_t; + type shell_exec_t; + type sssd_t; + type sssd_public_t; + type sssd_var_lib_t; + type sysfs_t; + type systemd_unit_file_t; type tun_tap_device_t; @begin_dpdk@ @@ -21,18 +39,36 @@ require { class capability { dac_override audit_write }; class chr_file { write getattr read open ioctl }; - class dir { write remove_name add_name lock read }; - class file { write getattr read open execute execute_no_trans create unlink }; + class dir { write remove_name add_name lock read getattr search open }; + class fd { use }; + class file { write getattr read open execute execute_no_trans create unlink map entrypoint lock ioctl }; + class fifo_file { getattr read write append ioctl lock open }; + class filesystem getattr; + class lnk_file { read open }; class netlink_audit_socket { create nlmsg_relay audit_write read write }; class netlink_socket { setopt getopt create connect getattr write read }; - class unix_stream_socket { write getattr read connectto connect setopt getopt sendto accept bind recvfrom acceptfrom }; + class sock_file { write }; + class system module_load; + class process { sigchld signull transition noatsecure siginh rlimitinh }; + class unix_stream_socket { write getattr read connectto connect setopt getopt sendto accept bind recvfrom acceptfrom ioctl }; @begin_dpdk@ - class sock_file { read write append getattr open }; + class sock_file { read append getattr open }; class tun_socket { relabelfrom relabelto create }; @end_dpdk@ } +#============= Set up the transition domain ============= +type openvswitch_load_module_exec_t; +type openvswitch_load_module_t; + +domain_type(openvswitch_load_module_exec_t); +domain_type(openvswitch_load_module_t); +role object_r types openvswitch_load_module_exec_t; +role system_r types openvswitch_load_module_t; +domain_entry_file(openvswitch_load_module_t, openvswitch_load_module_exec_t); +domtrans_pattern(openvswitch_t, openvswitch_load_module_exec_t, openvswitch_load_module_t); + #============= openvswitch_t ============== allow openvswitch_t self:capability { dac_override audit_write }; allow openvswitch_t self:netlink_audit_socket { create nlmsg_relay audit_write read write }; @@ -41,10 +77,11 @@ allow openvswitch_t self:netlink_socket { setopt getopt create connect getattr w allow openvswitch_t hostname_exec_t:file { read getattr open execute execute_no_trans }; allow openvswitch_t ifconfig_exec_t:file { read getattr open execute execute_no_trans }; -allow openvswitch_t openvswitch_rw_t:dir { write remove_name add_name lock read }; +allow openvswitch_t openvswitch_rw_t:dir { write remove_name add_name lock read getattr open search }; allow openvswitch_t openvswitch_rw_t:file { write getattr read open execute execute_no_trans create unlink }; allow openvswitch_t openvswitch_tmp_t:file { execute execute_no_trans }; allow openvswitch_t openvswitch_tmp_t:unix_stream_socket { write getattr read connectto connect setopt getopt sendto accept bind recvfrom acceptfrom }; +allow openvswitch_t openvswitch_var_run_t:dir { getattr read open search }; allow openvswitch_t tun_tap_device_t:chr_file { read write getattr open ioctl }; @begin_dpdk@ @@ -58,3 +95,39 @@ allow openvswitch_t svirt_tmpfs_t:sock_file { read write append getattr open }; allow openvswitch_t svirt_t:unix_stream_socket { connectto read write getattr sendto recvfrom setopt }; allow openvswitch_t vfio_device_t:chr_file { read write open ioctl getattr }; @end_dpdk@ + +#============= Transition allows ============= +type_transition openvswitch_t openvswitch_load_module_exec_t:process openvswitch_load_module_t; +allow openvswitch_t openvswitch_load_module_exec_t:file { execute read open getattr }; +allow openvswitch_t openvswitch_load_module_t:process transition; + +allow openvswitch_load_module_t bin_t:file { execute execute_no_trans map }; +allow openvswitch_load_module_t init_t:unix_stream_socket { getattr ioctl read write }; +allow openvswitch_load_module_t init_var_run_t:dir { getattr read open search }; +allow openvswitch_load_module_t insmod_exec_t:file { execute execute_no_trans getattr map open read }; +allow openvswitch_load_module_t modules_conf_t:dir { getattr open read search }; +allow openvswitch_load_module_t modules_conf_t:file { getattr open read }; +allow openvswitch_load_module_t modules_object_t:file { map getattr open read }; +allow openvswitch_load_module_t modules_object_t:dir { getattr open read search }; +allow openvswitch_load_module_t openvswitch_load_module_exec_t:file { entrypoint }; +allow openvswitch_load_module_t passwd_file_t:file { getattr open read }; +allow openvswitch_load_module_t plymouth_exec_t:file { getattr read open execute execute_no_trans map }; +allow openvswitch_load_module_t proc_t:file { getattr open read }; +allow openvswitch_load_module_t self:system module_load; +allow openvswitch_load_module_t self:process { siginh noatsecure rlimitinh siginh }; +allow openvswitch_load_module_t shell_exec_t:file { map execute read open getattr }; +allow openvswitch_load_module_t sssd_public_t:dir { getattr open read search }; +allow openvswitch_load_module_t sssd_public_t:file { getattr map open read }; +allow openvswitch_load_module_t sssd_t:unix_stream_socket connectto; +allow openvswitch_load_module_t sssd_var_lib_t:dir { getattr open read search }; +allow openvswitch_load_module_t sssd_var_lib_t:sock_file write; +allow openvswitch_load_module_t sysfs_t:dir { getattr open read search }; +allow openvswitch_load_module_t sysfs_t:file { open read }; +allow openvswitch_load_module_t sysfs_t:lnk_file { read open }; +allow openvswitch_load_module_t systemd_unit_file_t:dir getattr; + +# no need to grant search permissions for this - and no need to emit +# an error, either. +dontaudit openvswitch_load_module_t openvswitch_var_run_t:dir { search }; + +kernel_load_module(openvswitch_load_module_t);