2005-04-17 06:20:36 +08:00
|
|
|
/*
|
|
|
|
* Implementation of the security services.
|
|
|
|
*
|
|
|
|
* Authors : Stephen Smalley, <sds@epoch.ncsc.mil>
|
2008-04-19 05:38:33 +08:00
|
|
|
* James Morris <jmorris@redhat.com>
|
2005-04-17 06:20:36 +08:00
|
|
|
*
|
|
|
|
* Updated: Trusted Computer Solutions, Inc. <dgoeddel@trustedcs.com>
|
|
|
|
*
|
|
|
|
* Support for enhanced MLS infrastructure.
|
2006-02-25 05:44:05 +08:00
|
|
|
* Support for context based audit filters.
|
2005-04-17 06:20:36 +08:00
|
|
|
*
|
|
|
|
* Updated: Frank Mayer <mayerf@tresys.com> and Karl MacMillan <kmacmillan@tresys.com>
|
|
|
|
*
|
2008-04-19 05:38:33 +08:00
|
|
|
* Added conditional policy language extensions
|
2005-04-17 06:20:36 +08:00
|
|
|
*
|
2006-08-05 14:17:57 +08:00
|
|
|
* Updated: Hewlett-Packard <paul.moore@hp.com>
|
|
|
|
*
|
|
|
|
* Added support for NetLabel
|
2008-01-29 21:38:19 +08:00
|
|
|
* Added support for the policy capability bitmap
|
2006-08-05 14:17:57 +08:00
|
|
|
*
|
2006-11-07 01:38:18 +08:00
|
|
|
* Updated: Chad Sellers <csellers@tresys.com>
|
|
|
|
*
|
|
|
|
* Added validation of kernel classes and permissions
|
|
|
|
*
|
2009-06-18 16:26:13 +08:00
|
|
|
* Updated: KaiGai Kohei <kaigai@ak.jp.nec.com>
|
|
|
|
*
|
|
|
|
* Added support for bounds domain and audit messaged on masked permissions
|
|
|
|
*
|
2010-02-03 23:40:20 +08:00
|
|
|
* Updated: Guido Trentalancia <guido@trentalancia.com>
|
|
|
|
*
|
|
|
|
* Added support for runtime switching of the policy type
|
|
|
|
*
|
2009-06-18 16:26:13 +08:00
|
|
|
* Copyright (C) 2008, 2009 NEC Corporation
|
2008-01-29 21:38:19 +08:00
|
|
|
* Copyright (C) 2006, 2007 Hewlett-Packard Development Company, L.P.
|
2006-02-25 05:44:05 +08:00
|
|
|
* Copyright (C) 2004-2006 Trusted Computer Solutions, Inc.
|
2006-11-07 01:38:18 +08:00
|
|
|
* Copyright (C) 2003 - 2004, 2006 Tresys Technology, LLC
|
2005-04-17 06:20:36 +08:00
|
|
|
* Copyright (C) 2003 Red Hat, Inc., James Morris <jmorris@redhat.com>
|
|
|
|
* This program is free software; you can redistribute it and/or modify
|
2008-04-19 05:38:33 +08:00
|
|
|
* it under the terms of the GNU General Public License as published by
|
2005-04-17 06:20:36 +08:00
|
|
|
* the Free Software Foundation, version 2.
|
|
|
|
*/
|
|
|
|
#include <linux/kernel.h>
|
|
|
|
#include <linux/slab.h>
|
|
|
|
#include <linux/string.h>
|
|
|
|
#include <linux/spinlock.h>
|
2006-11-18 06:38:53 +08:00
|
|
|
#include <linux/rcupdate.h>
|
2005-04-17 06:20:36 +08:00
|
|
|
#include <linux/errno.h>
|
|
|
|
#include <linux/in.h>
|
|
|
|
#include <linux/sched.h>
|
|
|
|
#include <linux/audit.h>
|
2006-03-22 16:09:14 +08:00
|
|
|
#include <linux/mutex.h>
|
2008-03-31 06:54:02 +08:00
|
|
|
#include <linux/selinux.h>
|
2010-07-30 11:02:34 +08:00
|
|
|
#include <linux/flex_array.h>
|
2006-08-05 14:17:57 +08:00
|
|
|
#include <net/netlabel.h>
|
2006-03-22 16:09:14 +08:00
|
|
|
|
2005-04-17 06:20:36 +08:00
|
|
|
#include "flask.h"
|
|
|
|
#include "avc.h"
|
|
|
|
#include "avc_ss.h"
|
|
|
|
#include "security.h"
|
|
|
|
#include "context.h"
|
|
|
|
#include "policydb.h"
|
|
|
|
#include "sidtab.h"
|
|
|
|
#include "services.h"
|
|
|
|
#include "conditional.h"
|
|
|
|
#include "mls.h"
|
2006-08-05 14:17:57 +08:00
|
|
|
#include "objsec.h"
|
2007-03-01 04:14:23 +08:00
|
|
|
#include "netlabel.h"
|
2006-11-18 06:38:54 +08:00
|
|
|
#include "xfrm.h"
|
2006-11-30 02:18:18 +08:00
|
|
|
#include "ebitmap.h"
|
2008-03-02 04:03:14 +08:00
|
|
|
#include "audit.h"
|
2005-04-17 06:20:36 +08:00
|
|
|
|
|
|
|
extern void selnl_notify_policyload(u32 seqno);
|
|
|
|
|
2008-01-29 21:38:19 +08:00
|
|
|
int selinux_policycap_netpeer;
|
2008-02-29 01:58:40 +08:00
|
|
|
int selinux_policycap_openperm;
|
2008-01-29 21:38:19 +08:00
|
|
|
|
2005-04-17 06:20:36 +08:00
|
|
|
static DEFINE_RWLOCK(policy_rwlock);
|
|
|
|
|
|
|
|
static struct sidtab sidtab;
|
|
|
|
struct policydb policydb;
|
2008-04-19 05:38:33 +08:00
|
|
|
int ss_initialized;
|
2005-04-17 06:20:36 +08:00
|
|
|
|
|
|
|
/*
|
|
|
|
* The largest sequence number that has been used when
|
|
|
|
* providing an access decision to the access vector cache.
|
|
|
|
* The sequence number only changes when a policy change
|
|
|
|
* occurs.
|
|
|
|
*/
|
2008-04-19 05:38:33 +08:00
|
|
|
static u32 latest_granting;
|
2005-04-17 06:20:36 +08:00
|
|
|
|
|
|
|
/* Forward declaration. */
|
|
|
|
static int context_struct_to_string(struct context *context, char **scontext,
|
|
|
|
u32 *scontext_len);
|
|
|
|
|
2010-01-15 06:28:10 +08:00
|
|
|
static void context_struct_compute_av(struct context *scontext,
|
|
|
|
struct context *tcontext,
|
|
|
|
u16 tclass,
|
|
|
|
struct av_decision *avd);
|
selinux: dynamic class/perm discovery
Modify SELinux to dynamically discover class and permission values
upon policy load, based on the dynamic object class/perm discovery
logic from libselinux. A mapping is created between kernel-private
class and permission indices used outside the security server and the
policy values used within the security server.
The mappings are only applied upon kernel-internal computations;
similar mappings for the private indices of userspace object managers
is handled on a per-object manager basis by the userspace AVC. The
interfaces for compute_av and transition_sid are split for kernel
vs. userspace; the userspace functions are distinguished by a _user
suffix.
The kernel-private class indices are no longer tied to the policy
values and thus do not need to skip indices for userspace classes;
thus the kernel class index values are compressed. The flask.h
definitions were regenerated by deleting the userspace classes from
refpolicy's definitions and then regenerating the headers. Going
forward, we can just maintain the flask.h, av_permissions.h, and
classmap.h definitions separately from policy as they are no longer
tied to the policy values. The next patch introduces a utility to
automate generation of flask.h and av_permissions.h from the
classmap.h definitions.
The older kernel class and permission string tables are removed and
replaced by a single security class mapping table that is walked at
policy load to generate the mapping. The old kernel class validation
logic is completely replaced by the mapping logic.
The handle unknown logic is reworked. reject_unknown=1 is handled
when the mappings are computed at policy load time, similar to the old
handling by the class validation logic. allow_unknown=1 is handled
when computing and mapping decisions - if the permission was not able
to be mapped (i.e. undefined, mapped to zero), then it is
automatically added to the allowed vector. If the class was not able
to be mapped (i.e. undefined, mapped to zero), then all permissions
are allowed for it if allow_unknown=1.
avc_audit leverages the new security class mapping table to lookup the
class and permission names from the kernel-private indices.
The mdp program is updated to use the new table when generating the
class definitions and allow rules for a minimal boot policy for the
kernel. It should be noted that this policy will not include any
userspace classes, nor will its policy index values for the kernel
classes correspond with the ones in refpolicy (they will instead match
the kernel-private indices).
Signed-off-by: Stephen Smalley <sds@tycho.nsa.gov>
Signed-off-by: James Morris <jmorris@namei.org>
2009-10-01 01:37:50 +08:00
|
|
|
|
|
|
|
struct selinux_mapping {
|
|
|
|
u16 value; /* policy value */
|
|
|
|
unsigned num_perms;
|
|
|
|
u32 perms[sizeof(u32) * 8];
|
|
|
|
};
|
|
|
|
|
|
|
|
static struct selinux_mapping *current_mapping;
|
|
|
|
static u16 current_mapping_size;
|
|
|
|
|
|
|
|
static int selinux_set_mapping(struct policydb *pol,
|
|
|
|
struct security_class_mapping *map,
|
|
|
|
struct selinux_mapping **out_map_p,
|
|
|
|
u16 *out_map_size)
|
|
|
|
{
|
|
|
|
struct selinux_mapping *out_map = NULL;
|
|
|
|
size_t size = sizeof(struct selinux_mapping);
|
|
|
|
u16 i, j;
|
|
|
|
unsigned k;
|
|
|
|
bool print_unknown_handle = false;
|
|
|
|
|
|
|
|
/* Find number of classes in the input mapping */
|
|
|
|
if (!map)
|
|
|
|
return -EINVAL;
|
|
|
|
i = 0;
|
|
|
|
while (map[i].name)
|
|
|
|
i++;
|
|
|
|
|
|
|
|
/* Allocate space for the class records, plus one for class zero */
|
|
|
|
out_map = kcalloc(++i, size, GFP_ATOMIC);
|
|
|
|
if (!out_map)
|
|
|
|
return -ENOMEM;
|
|
|
|
|
|
|
|
/* Store the raw class and permission values */
|
|
|
|
j = 0;
|
|
|
|
while (map[j].name) {
|
|
|
|
struct security_class_mapping *p_in = map + (j++);
|
|
|
|
struct selinux_mapping *p_out = out_map + j;
|
|
|
|
|
|
|
|
/* An empty class string skips ahead */
|
|
|
|
if (!strcmp(p_in->name, "")) {
|
|
|
|
p_out->num_perms = 0;
|
|
|
|
continue;
|
|
|
|
}
|
|
|
|
|
|
|
|
p_out->value = string_to_security_class(pol, p_in->name);
|
|
|
|
if (!p_out->value) {
|
|
|
|
printk(KERN_INFO
|
|
|
|
"SELinux: Class %s not defined in policy.\n",
|
|
|
|
p_in->name);
|
|
|
|
if (pol->reject_unknown)
|
|
|
|
goto err;
|
|
|
|
p_out->num_perms = 0;
|
|
|
|
print_unknown_handle = true;
|
|
|
|
continue;
|
|
|
|
}
|
|
|
|
|
|
|
|
k = 0;
|
|
|
|
while (p_in->perms && p_in->perms[k]) {
|
|
|
|
/* An empty permission string skips ahead */
|
|
|
|
if (!*p_in->perms[k]) {
|
|
|
|
k++;
|
|
|
|
continue;
|
|
|
|
}
|
|
|
|
p_out->perms[k] = string_to_av_perm(pol, p_out->value,
|
|
|
|
p_in->perms[k]);
|
|
|
|
if (!p_out->perms[k]) {
|
|
|
|
printk(KERN_INFO
|
|
|
|
"SELinux: Permission %s in class %s not defined in policy.\n",
|
|
|
|
p_in->perms[k], p_in->name);
|
|
|
|
if (pol->reject_unknown)
|
|
|
|
goto err;
|
|
|
|
print_unknown_handle = true;
|
|
|
|
}
|
|
|
|
|
|
|
|
k++;
|
|
|
|
}
|
|
|
|
p_out->num_perms = k;
|
|
|
|
}
|
|
|
|
|
|
|
|
if (print_unknown_handle)
|
|
|
|
printk(KERN_INFO "SELinux: the above unknown classes and permissions will be %s\n",
|
|
|
|
pol->allow_unknown ? "allowed" : "denied");
|
|
|
|
|
|
|
|
*out_map_p = out_map;
|
|
|
|
*out_map_size = i;
|
|
|
|
return 0;
|
|
|
|
err:
|
|
|
|
kfree(out_map);
|
|
|
|
return -EINVAL;
|
|
|
|
}
|
|
|
|
|
|
|
|
/*
|
|
|
|
* Get real, policy values from mapped values
|
|
|
|
*/
|
|
|
|
|
|
|
|
static u16 unmap_class(u16 tclass)
|
|
|
|
{
|
|
|
|
if (tclass < current_mapping_size)
|
|
|
|
return current_mapping[tclass].value;
|
|
|
|
|
|
|
|
return tclass;
|
|
|
|
}
|
|
|
|
|
|
|
|
static void map_decision(u16 tclass, struct av_decision *avd,
|
|
|
|
int allow_unknown)
|
|
|
|
{
|
|
|
|
if (tclass < current_mapping_size) {
|
|
|
|
unsigned i, n = current_mapping[tclass].num_perms;
|
|
|
|
u32 result;
|
|
|
|
|
|
|
|
for (i = 0, result = 0; i < n; i++) {
|
|
|
|
if (avd->allowed & current_mapping[tclass].perms[i])
|
|
|
|
result |= 1<<i;
|
|
|
|
if (allow_unknown && !current_mapping[tclass].perms[i])
|
|
|
|
result |= 1<<i;
|
|
|
|
}
|
|
|
|
avd->allowed = result;
|
|
|
|
|
|
|
|
for (i = 0, result = 0; i < n; i++)
|
|
|
|
if (avd->auditallow & current_mapping[tclass].perms[i])
|
|
|
|
result |= 1<<i;
|
|
|
|
avd->auditallow = result;
|
|
|
|
|
|
|
|
for (i = 0, result = 0; i < n; i++) {
|
|
|
|
if (avd->auditdeny & current_mapping[tclass].perms[i])
|
|
|
|
result |= 1<<i;
|
|
|
|
if (!allow_unknown && !current_mapping[tclass].perms[i])
|
|
|
|
result |= 1<<i;
|
|
|
|
}
|
2009-11-24 05:47:23 +08:00
|
|
|
/*
|
|
|
|
* In case the kernel has a bug and requests a permission
|
|
|
|
* between num_perms and the maximum permission number, we
|
|
|
|
* should audit that denial
|
|
|
|
*/
|
|
|
|
for (; i < (sizeof(u32)*8); i++)
|
|
|
|
result |= 1<<i;
|
selinux: dynamic class/perm discovery
Modify SELinux to dynamically discover class and permission values
upon policy load, based on the dynamic object class/perm discovery
logic from libselinux. A mapping is created between kernel-private
class and permission indices used outside the security server and the
policy values used within the security server.
The mappings are only applied upon kernel-internal computations;
similar mappings for the private indices of userspace object managers
is handled on a per-object manager basis by the userspace AVC. The
interfaces for compute_av and transition_sid are split for kernel
vs. userspace; the userspace functions are distinguished by a _user
suffix.
The kernel-private class indices are no longer tied to the policy
values and thus do not need to skip indices for userspace classes;
thus the kernel class index values are compressed. The flask.h
definitions were regenerated by deleting the userspace classes from
refpolicy's definitions and then regenerating the headers. Going
forward, we can just maintain the flask.h, av_permissions.h, and
classmap.h definitions separately from policy as they are no longer
tied to the policy values. The next patch introduces a utility to
automate generation of flask.h and av_permissions.h from the
classmap.h definitions.
The older kernel class and permission string tables are removed and
replaced by a single security class mapping table that is walked at
policy load to generate the mapping. The old kernel class validation
logic is completely replaced by the mapping logic.
The handle unknown logic is reworked. reject_unknown=1 is handled
when the mappings are computed at policy load time, similar to the old
handling by the class validation logic. allow_unknown=1 is handled
when computing and mapping decisions - if the permission was not able
to be mapped (i.e. undefined, mapped to zero), then it is
automatically added to the allowed vector. If the class was not able
to be mapped (i.e. undefined, mapped to zero), then all permissions
are allowed for it if allow_unknown=1.
avc_audit leverages the new security class mapping table to lookup the
class and permission names from the kernel-private indices.
The mdp program is updated to use the new table when generating the
class definitions and allow rules for a minimal boot policy for the
kernel. It should be noted that this policy will not include any
userspace classes, nor will its policy index values for the kernel
classes correspond with the ones in refpolicy (they will instead match
the kernel-private indices).
Signed-off-by: Stephen Smalley <sds@tycho.nsa.gov>
Signed-off-by: James Morris <jmorris@namei.org>
2009-10-01 01:37:50 +08:00
|
|
|
avd->auditdeny = result;
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2010-02-03 23:40:20 +08:00
|
|
|
int security_mls_enabled(void)
|
|
|
|
{
|
|
|
|
return policydb.mls_enabled;
|
|
|
|
}
|
selinux: dynamic class/perm discovery
Modify SELinux to dynamically discover class and permission values
upon policy load, based on the dynamic object class/perm discovery
logic from libselinux. A mapping is created between kernel-private
class and permission indices used outside the security server and the
policy values used within the security server.
The mappings are only applied upon kernel-internal computations;
similar mappings for the private indices of userspace object managers
is handled on a per-object manager basis by the userspace AVC. The
interfaces for compute_av and transition_sid are split for kernel
vs. userspace; the userspace functions are distinguished by a _user
suffix.
The kernel-private class indices are no longer tied to the policy
values and thus do not need to skip indices for userspace classes;
thus the kernel class index values are compressed. The flask.h
definitions were regenerated by deleting the userspace classes from
refpolicy's definitions and then regenerating the headers. Going
forward, we can just maintain the flask.h, av_permissions.h, and
classmap.h definitions separately from policy as they are no longer
tied to the policy values. The next patch introduces a utility to
automate generation of flask.h and av_permissions.h from the
classmap.h definitions.
The older kernel class and permission string tables are removed and
replaced by a single security class mapping table that is walked at
policy load to generate the mapping. The old kernel class validation
logic is completely replaced by the mapping logic.
The handle unknown logic is reworked. reject_unknown=1 is handled
when the mappings are computed at policy load time, similar to the old
handling by the class validation logic. allow_unknown=1 is handled
when computing and mapping decisions - if the permission was not able
to be mapped (i.e. undefined, mapped to zero), then it is
automatically added to the allowed vector. If the class was not able
to be mapped (i.e. undefined, mapped to zero), then all permissions
are allowed for it if allow_unknown=1.
avc_audit leverages the new security class mapping table to lookup the
class and permission names from the kernel-private indices.
The mdp program is updated to use the new table when generating the
class definitions and allow rules for a minimal boot policy for the
kernel. It should be noted that this policy will not include any
userspace classes, nor will its policy index values for the kernel
classes correspond with the ones in refpolicy (they will instead match
the kernel-private indices).
Signed-off-by: Stephen Smalley <sds@tycho.nsa.gov>
Signed-off-by: James Morris <jmorris@namei.org>
2009-10-01 01:37:50 +08:00
|
|
|
|
2005-04-17 06:20:36 +08:00
|
|
|
/*
|
|
|
|
* Return the boolean value of a constraint expression
|
|
|
|
* when it is applied to the specified source and target
|
|
|
|
* security contexts.
|
|
|
|
*
|
|
|
|
* xcontext is a special beast... It is used by the validatetrans rules
|
|
|
|
* only. For these rules, scontext is the context before the transition,
|
|
|
|
* tcontext is the context after the transition, and xcontext is the context
|
|
|
|
* of the process performing the transition. All other callers of
|
|
|
|
* constraint_expr_eval should pass in NULL for xcontext.
|
|
|
|
*/
|
|
|
|
static int constraint_expr_eval(struct context *scontext,
|
|
|
|
struct context *tcontext,
|
|
|
|
struct context *xcontext,
|
|
|
|
struct constraint_expr *cexpr)
|
|
|
|
{
|
|
|
|
u32 val1, val2;
|
|
|
|
struct context *c;
|
|
|
|
struct role_datum *r1, *r2;
|
|
|
|
struct mls_level *l1, *l2;
|
|
|
|
struct constraint_expr *e;
|
|
|
|
int s[CEXPR_MAXDEPTH];
|
|
|
|
int sp = -1;
|
|
|
|
|
|
|
|
for (e = cexpr; e; e = e->next) {
|
|
|
|
switch (e->expr_type) {
|
|
|
|
case CEXPR_NOT:
|
|
|
|
BUG_ON(sp < 0);
|
|
|
|
s[sp] = !s[sp];
|
|
|
|
break;
|
|
|
|
case CEXPR_AND:
|
|
|
|
BUG_ON(sp < 1);
|
|
|
|
sp--;
|
2010-04-09 19:30:29 +08:00
|
|
|
s[sp] &= s[sp + 1];
|
2005-04-17 06:20:36 +08:00
|
|
|
break;
|
|
|
|
case CEXPR_OR:
|
|
|
|
BUG_ON(sp < 1);
|
|
|
|
sp--;
|
2010-04-09 19:30:29 +08:00
|
|
|
s[sp] |= s[sp + 1];
|
2005-04-17 06:20:36 +08:00
|
|
|
break;
|
|
|
|
case CEXPR_ATTR:
|
2010-04-09 19:30:29 +08:00
|
|
|
if (sp == (CEXPR_MAXDEPTH - 1))
|
2005-04-17 06:20:36 +08:00
|
|
|
return 0;
|
|
|
|
switch (e->attr) {
|
|
|
|
case CEXPR_USER:
|
|
|
|
val1 = scontext->user;
|
|
|
|
val2 = tcontext->user;
|
|
|
|
break;
|
|
|
|
case CEXPR_TYPE:
|
|
|
|
val1 = scontext->type;
|
|
|
|
val2 = tcontext->type;
|
|
|
|
break;
|
|
|
|
case CEXPR_ROLE:
|
|
|
|
val1 = scontext->role;
|
|
|
|
val2 = tcontext->role;
|
|
|
|
r1 = policydb.role_val_to_struct[val1 - 1];
|
|
|
|
r2 = policydb.role_val_to_struct[val2 - 1];
|
|
|
|
switch (e->op) {
|
|
|
|
case CEXPR_DOM:
|
|
|
|
s[++sp] = ebitmap_get_bit(&r1->dominates,
|
|
|
|
val2 - 1);
|
|
|
|
continue;
|
|
|
|
case CEXPR_DOMBY:
|
|
|
|
s[++sp] = ebitmap_get_bit(&r2->dominates,
|
|
|
|
val1 - 1);
|
|
|
|
continue;
|
|
|
|
case CEXPR_INCOMP:
|
2008-04-19 05:38:33 +08:00
|
|
|
s[++sp] = (!ebitmap_get_bit(&r1->dominates,
|
|
|
|
val2 - 1) &&
|
|
|
|
!ebitmap_get_bit(&r2->dominates,
|
|
|
|
val1 - 1));
|
2005-04-17 06:20:36 +08:00
|
|
|
continue;
|
|
|
|
default:
|
|
|
|
break;
|
|
|
|
}
|
|
|
|
break;
|
|
|
|
case CEXPR_L1L2:
|
|
|
|
l1 = &(scontext->range.level[0]);
|
|
|
|
l2 = &(tcontext->range.level[0]);
|
|
|
|
goto mls_ops;
|
|
|
|
case CEXPR_L1H2:
|
|
|
|
l1 = &(scontext->range.level[0]);
|
|
|
|
l2 = &(tcontext->range.level[1]);
|
|
|
|
goto mls_ops;
|
|
|
|
case CEXPR_H1L2:
|
|
|
|
l1 = &(scontext->range.level[1]);
|
|
|
|
l2 = &(tcontext->range.level[0]);
|
|
|
|
goto mls_ops;
|
|
|
|
case CEXPR_H1H2:
|
|
|
|
l1 = &(scontext->range.level[1]);
|
|
|
|
l2 = &(tcontext->range.level[1]);
|
|
|
|
goto mls_ops;
|
|
|
|
case CEXPR_L1H1:
|
|
|
|
l1 = &(scontext->range.level[0]);
|
|
|
|
l2 = &(scontext->range.level[1]);
|
|
|
|
goto mls_ops;
|
|
|
|
case CEXPR_L2H2:
|
|
|
|
l1 = &(tcontext->range.level[0]);
|
|
|
|
l2 = &(tcontext->range.level[1]);
|
|
|
|
goto mls_ops;
|
|
|
|
mls_ops:
|
|
|
|
switch (e->op) {
|
|
|
|
case CEXPR_EQ:
|
|
|
|
s[++sp] = mls_level_eq(l1, l2);
|
|
|
|
continue;
|
|
|
|
case CEXPR_NEQ:
|
|
|
|
s[++sp] = !mls_level_eq(l1, l2);
|
|
|
|
continue;
|
|
|
|
case CEXPR_DOM:
|
|
|
|
s[++sp] = mls_level_dom(l1, l2);
|
|
|
|
continue;
|
|
|
|
case CEXPR_DOMBY:
|
|
|
|
s[++sp] = mls_level_dom(l2, l1);
|
|
|
|
continue;
|
|
|
|
case CEXPR_INCOMP:
|
|
|
|
s[++sp] = mls_level_incomp(l2, l1);
|
|
|
|
continue;
|
|
|
|
default:
|
|
|
|
BUG();
|
|
|
|
return 0;
|
|
|
|
}
|
|
|
|
break;
|
|
|
|
default:
|
|
|
|
BUG();
|
|
|
|
return 0;
|
|
|
|
}
|
|
|
|
|
|
|
|
switch (e->op) {
|
|
|
|
case CEXPR_EQ:
|
|
|
|
s[++sp] = (val1 == val2);
|
|
|
|
break;
|
|
|
|
case CEXPR_NEQ:
|
|
|
|
s[++sp] = (val1 != val2);
|
|
|
|
break;
|
|
|
|
default:
|
|
|
|
BUG();
|
|
|
|
return 0;
|
|
|
|
}
|
|
|
|
break;
|
|
|
|
case CEXPR_NAMES:
|
|
|
|
if (sp == (CEXPR_MAXDEPTH-1))
|
|
|
|
return 0;
|
|
|
|
c = scontext;
|
|
|
|
if (e->attr & CEXPR_TARGET)
|
|
|
|
c = tcontext;
|
|
|
|
else if (e->attr & CEXPR_XTARGET) {
|
|
|
|
c = xcontext;
|
|
|
|
if (!c) {
|
|
|
|
BUG();
|
|
|
|
return 0;
|
|
|
|
}
|
|
|
|
}
|
|
|
|
if (e->attr & CEXPR_USER)
|
|
|
|
val1 = c->user;
|
|
|
|
else if (e->attr & CEXPR_ROLE)
|
|
|
|
val1 = c->role;
|
|
|
|
else if (e->attr & CEXPR_TYPE)
|
|
|
|
val1 = c->type;
|
|
|
|
else {
|
|
|
|
BUG();
|
|
|
|
return 0;
|
|
|
|
}
|
|
|
|
|
|
|
|
switch (e->op) {
|
|
|
|
case CEXPR_EQ:
|
|
|
|
s[++sp] = ebitmap_get_bit(&e->names, val1 - 1);
|
|
|
|
break;
|
|
|
|
case CEXPR_NEQ:
|
|
|
|
s[++sp] = !ebitmap_get_bit(&e->names, val1 - 1);
|
|
|
|
break;
|
|
|
|
default:
|
|
|
|
BUG();
|
|
|
|
return 0;
|
|
|
|
}
|
|
|
|
break;
|
|
|
|
default:
|
|
|
|
BUG();
|
|
|
|
return 0;
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
BUG_ON(sp != 0);
|
|
|
|
return s[0];
|
|
|
|
}
|
|
|
|
|
2009-06-18 16:26:13 +08:00
|
|
|
/*
|
|
|
|
* security_dump_masked_av - dumps masked permissions during
|
|
|
|
* security_compute_av due to RBAC, MLS/Constraint and Type bounds.
|
|
|
|
*/
|
|
|
|
static int dump_masked_av_helper(void *k, void *d, void *args)
|
|
|
|
{
|
|
|
|
struct perm_datum *pdatum = d;
|
|
|
|
char **permission_names = args;
|
|
|
|
|
|
|
|
BUG_ON(pdatum->value < 1 || pdatum->value > 32);
|
|
|
|
|
|
|
|
permission_names[pdatum->value - 1] = (char *)k;
|
|
|
|
|
|
|
|
return 0;
|
|
|
|
}
|
|
|
|
|
|
|
|
static void security_dump_masked_av(struct context *scontext,
|
|
|
|
struct context *tcontext,
|
|
|
|
u16 tclass,
|
|
|
|
u32 permissions,
|
|
|
|
const char *reason)
|
|
|
|
{
|
|
|
|
struct common_datum *common_dat;
|
|
|
|
struct class_datum *tclass_dat;
|
|
|
|
struct audit_buffer *ab;
|
|
|
|
char *tclass_name;
|
|
|
|
char *scontext_name = NULL;
|
|
|
|
char *tcontext_name = NULL;
|
|
|
|
char *permission_names[32];
|
2010-02-16 14:29:06 +08:00
|
|
|
int index;
|
|
|
|
u32 length;
|
2009-06-18 16:26:13 +08:00
|
|
|
bool need_comma = false;
|
|
|
|
|
|
|
|
if (!permissions)
|
|
|
|
return;
|
|
|
|
|
|
|
|
tclass_name = policydb.p_class_val_to_name[tclass - 1];
|
|
|
|
tclass_dat = policydb.class_val_to_struct[tclass - 1];
|
|
|
|
common_dat = tclass_dat->comdatum;
|
|
|
|
|
|
|
|
/* init permission_names */
|
|
|
|
if (common_dat &&
|
|
|
|
hashtab_map(common_dat->permissions.table,
|
|
|
|
dump_masked_av_helper, permission_names) < 0)
|
|
|
|
goto out;
|
|
|
|
|
|
|
|
if (hashtab_map(tclass_dat->permissions.table,
|
|
|
|
dump_masked_av_helper, permission_names) < 0)
|
|
|
|
goto out;
|
|
|
|
|
|
|
|
/* get scontext/tcontext in text form */
|
|
|
|
if (context_struct_to_string(scontext,
|
|
|
|
&scontext_name, &length) < 0)
|
|
|
|
goto out;
|
|
|
|
|
|
|
|
if (context_struct_to_string(tcontext,
|
|
|
|
&tcontext_name, &length) < 0)
|
|
|
|
goto out;
|
|
|
|
|
|
|
|
/* audit a message */
|
|
|
|
ab = audit_log_start(current->audit_context,
|
|
|
|
GFP_ATOMIC, AUDIT_SELINUX_ERR);
|
|
|
|
if (!ab)
|
|
|
|
goto out;
|
|
|
|
|
|
|
|
audit_log_format(ab, "op=security_compute_av reason=%s "
|
|
|
|
"scontext=%s tcontext=%s tclass=%s perms=",
|
|
|
|
reason, scontext_name, tcontext_name, tclass_name);
|
|
|
|
|
|
|
|
for (index = 0; index < 32; index++) {
|
|
|
|
u32 mask = (1 << index);
|
|
|
|
|
|
|
|
if ((mask & permissions) == 0)
|
|
|
|
continue;
|
|
|
|
|
|
|
|
audit_log_format(ab, "%s%s",
|
|
|
|
need_comma ? "," : "",
|
|
|
|
permission_names[index]
|
|
|
|
? permission_names[index] : "????");
|
|
|
|
need_comma = true;
|
|
|
|
}
|
|
|
|
audit_log_end(ab);
|
|
|
|
out:
|
|
|
|
/* release scontext/tcontext */
|
|
|
|
kfree(tcontext_name);
|
|
|
|
kfree(scontext_name);
|
|
|
|
|
|
|
|
return;
|
|
|
|
}
|
|
|
|
|
2008-08-28 15:35:57 +08:00
|
|
|
/*
|
|
|
|
* security_boundary_permission - drops violated permissions
|
|
|
|
* on boundary constraint.
|
|
|
|
*/
|
|
|
|
static void type_attribute_bounds_av(struct context *scontext,
|
|
|
|
struct context *tcontext,
|
|
|
|
u16 tclass,
|
|
|
|
struct av_decision *avd)
|
|
|
|
{
|
2010-02-17 07:49:41 +08:00
|
|
|
struct context lo_scontext;
|
|
|
|
struct context lo_tcontext;
|
|
|
|
struct av_decision lo_avd;
|
2008-08-28 15:35:57 +08:00
|
|
|
struct type_datum *source
|
|
|
|
= policydb.type_val_to_struct[scontext->type - 1];
|
2010-02-17 07:49:41 +08:00
|
|
|
struct type_datum *target
|
|
|
|
= policydb.type_val_to_struct[tcontext->type - 1];
|
|
|
|
u32 masked = 0;
|
2008-08-28 15:35:57 +08:00
|
|
|
|
|
|
|
if (source->bounds) {
|
|
|
|
memset(&lo_avd, 0, sizeof(lo_avd));
|
|
|
|
|
|
|
|
memcpy(&lo_scontext, scontext, sizeof(lo_scontext));
|
|
|
|
lo_scontext.type = source->bounds;
|
|
|
|
|
|
|
|
context_struct_compute_av(&lo_scontext,
|
|
|
|
tcontext,
|
|
|
|
tclass,
|
|
|
|
&lo_avd);
|
|
|
|
if ((lo_avd.allowed & avd->allowed) == avd->allowed)
|
|
|
|
return; /* no masked permission */
|
|
|
|
masked = ~lo_avd.allowed & avd->allowed;
|
2010-02-17 07:49:41 +08:00
|
|
|
}
|
|
|
|
|
|
|
|
if (target->bounds) {
|
|
|
|
memset(&lo_avd, 0, sizeof(lo_avd));
|
|
|
|
|
|
|
|
memcpy(&lo_tcontext, tcontext, sizeof(lo_tcontext));
|
|
|
|
lo_tcontext.type = target->bounds;
|
|
|
|
|
|
|
|
context_struct_compute_av(scontext,
|
|
|
|
&lo_tcontext,
|
|
|
|
tclass,
|
|
|
|
&lo_avd);
|
|
|
|
if ((lo_avd.allowed & avd->allowed) == avd->allowed)
|
|
|
|
return; /* no masked permission */
|
|
|
|
masked = ~lo_avd.allowed & avd->allowed;
|
|
|
|
}
|
|
|
|
|
|
|
|
if (source->bounds && target->bounds) {
|
|
|
|
memset(&lo_avd, 0, sizeof(lo_avd));
|
|
|
|
/*
|
|
|
|
* lo_scontext and lo_tcontext are already
|
|
|
|
* set up.
|
|
|
|
*/
|
|
|
|
|
|
|
|
context_struct_compute_av(&lo_scontext,
|
|
|
|
&lo_tcontext,
|
|
|
|
tclass,
|
|
|
|
&lo_avd);
|
|
|
|
if ((lo_avd.allowed & avd->allowed) == avd->allowed)
|
|
|
|
return; /* no masked permission */
|
|
|
|
masked = ~lo_avd.allowed & avd->allowed;
|
|
|
|
}
|
2008-08-28 15:35:57 +08:00
|
|
|
|
2010-02-17 07:49:41 +08:00
|
|
|
if (masked) {
|
2008-08-28 15:35:57 +08:00
|
|
|
/* mask violated permissions */
|
|
|
|
avd->allowed &= ~masked;
|
|
|
|
|
2009-06-18 16:26:13 +08:00
|
|
|
/* audit masked permissions */
|
|
|
|
security_dump_masked_av(scontext, tcontext,
|
|
|
|
tclass, masked, "bounds");
|
2008-08-28 15:35:57 +08:00
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2005-04-17 06:20:36 +08:00
|
|
|
/*
|
|
|
|
* Compute access vectors based on a context structure pair for
|
|
|
|
* the permissions in a particular class.
|
|
|
|
*/
|
2010-01-15 06:28:10 +08:00
|
|
|
static void context_struct_compute_av(struct context *scontext,
|
|
|
|
struct context *tcontext,
|
|
|
|
u16 tclass,
|
|
|
|
struct av_decision *avd)
|
2005-04-17 06:20:36 +08:00
|
|
|
{
|
|
|
|
struct constraint_node *constraint;
|
|
|
|
struct role_allow *ra;
|
|
|
|
struct avtab_key avkey;
|
2005-09-04 06:55:16 +08:00
|
|
|
struct avtab_node *node;
|
2005-04-17 06:20:36 +08:00
|
|
|
struct class_datum *tclass_datum;
|
2005-09-04 06:55:16 +08:00
|
|
|
struct ebitmap *sattr, *tattr;
|
|
|
|
struct ebitmap_node *snode, *tnode;
|
|
|
|
unsigned int i, j;
|
2005-04-17 06:20:36 +08:00
|
|
|
|
|
|
|
avd->allowed = 0;
|
|
|
|
avd->auditallow = 0;
|
|
|
|
avd->auditdeny = 0xffffffff;
|
|
|
|
|
selinux: dynamic class/perm discovery
Modify SELinux to dynamically discover class and permission values
upon policy load, based on the dynamic object class/perm discovery
logic from libselinux. A mapping is created between kernel-private
class and permission indices used outside the security server and the
policy values used within the security server.
The mappings are only applied upon kernel-internal computations;
similar mappings for the private indices of userspace object managers
is handled on a per-object manager basis by the userspace AVC. The
interfaces for compute_av and transition_sid are split for kernel
vs. userspace; the userspace functions are distinguished by a _user
suffix.
The kernel-private class indices are no longer tied to the policy
values and thus do not need to skip indices for userspace classes;
thus the kernel class index values are compressed. The flask.h
definitions were regenerated by deleting the userspace classes from
refpolicy's definitions and then regenerating the headers. Going
forward, we can just maintain the flask.h, av_permissions.h, and
classmap.h definitions separately from policy as they are no longer
tied to the policy values. The next patch introduces a utility to
automate generation of flask.h and av_permissions.h from the
classmap.h definitions.
The older kernel class and permission string tables are removed and
replaced by a single security class mapping table that is walked at
policy load to generate the mapping. The old kernel class validation
logic is completely replaced by the mapping logic.
The handle unknown logic is reworked. reject_unknown=1 is handled
when the mappings are computed at policy load time, similar to the old
handling by the class validation logic. allow_unknown=1 is handled
when computing and mapping decisions - if the permission was not able
to be mapped (i.e. undefined, mapped to zero), then it is
automatically added to the allowed vector. If the class was not able
to be mapped (i.e. undefined, mapped to zero), then all permissions
are allowed for it if allow_unknown=1.
avc_audit leverages the new security class mapping table to lookup the
class and permission names from the kernel-private indices.
The mdp program is updated to use the new table when generating the
class definitions and allow rules for a minimal boot policy for the
kernel. It should be noted that this policy will not include any
userspace classes, nor will its policy index values for the kernel
classes correspond with the ones in refpolicy (they will instead match
the kernel-private indices).
Signed-off-by: Stephen Smalley <sds@tycho.nsa.gov>
Signed-off-by: James Morris <jmorris@namei.org>
2009-10-01 01:37:50 +08:00
|
|
|
if (unlikely(!tclass || tclass > policydb.p_classes.nprim)) {
|
|
|
|
if (printk_ratelimit())
|
|
|
|
printk(KERN_WARNING "SELinux: Invalid class %hu\n", tclass);
|
2010-01-15 06:28:10 +08:00
|
|
|
return;
|
selinux: dynamic class/perm discovery
Modify SELinux to dynamically discover class and permission values
upon policy load, based on the dynamic object class/perm discovery
logic from libselinux. A mapping is created between kernel-private
class and permission indices used outside the security server and the
policy values used within the security server.
The mappings are only applied upon kernel-internal computations;
similar mappings for the private indices of userspace object managers
is handled on a per-object manager basis by the userspace AVC. The
interfaces for compute_av and transition_sid are split for kernel
vs. userspace; the userspace functions are distinguished by a _user
suffix.
The kernel-private class indices are no longer tied to the policy
values and thus do not need to skip indices for userspace classes;
thus the kernel class index values are compressed. The flask.h
definitions were regenerated by deleting the userspace classes from
refpolicy's definitions and then regenerating the headers. Going
forward, we can just maintain the flask.h, av_permissions.h, and
classmap.h definitions separately from policy as they are no longer
tied to the policy values. The next patch introduces a utility to
automate generation of flask.h and av_permissions.h from the
classmap.h definitions.
The older kernel class and permission string tables are removed and
replaced by a single security class mapping table that is walked at
policy load to generate the mapping. The old kernel class validation
logic is completely replaced by the mapping logic.
The handle unknown logic is reworked. reject_unknown=1 is handled
when the mappings are computed at policy load time, similar to the old
handling by the class validation logic. allow_unknown=1 is handled
when computing and mapping decisions - if the permission was not able
to be mapped (i.e. undefined, mapped to zero), then it is
automatically added to the allowed vector. If the class was not able
to be mapped (i.e. undefined, mapped to zero), then all permissions
are allowed for it if allow_unknown=1.
avc_audit leverages the new security class mapping table to lookup the
class and permission names from the kernel-private indices.
The mdp program is updated to use the new table when generating the
class definitions and allow rules for a minimal boot policy for the
kernel. It should be noted that this policy will not include any
userspace classes, nor will its policy index values for the kernel
classes correspond with the ones in refpolicy (they will instead match
the kernel-private indices).
Signed-off-by: Stephen Smalley <sds@tycho.nsa.gov>
Signed-off-by: James Morris <jmorris@namei.org>
2009-10-01 01:37:50 +08:00
|
|
|
}
|
2007-09-22 02:37:10 +08:00
|
|
|
|
|
|
|
tclass_datum = policydb.class_val_to_struct[tclass - 1];
|
|
|
|
|
2005-04-17 06:20:36 +08:00
|
|
|
/*
|
|
|
|
* If a specific type enforcement rule was defined for
|
|
|
|
* this permission check, then use it.
|
|
|
|
*/
|
|
|
|
avkey.target_class = tclass;
|
2005-09-04 06:55:16 +08:00
|
|
|
avkey.specified = AVTAB_AV;
|
2010-07-30 11:02:34 +08:00
|
|
|
sattr = flex_array_get(policydb.type_attr_map_array, scontext->type - 1);
|
|
|
|
BUG_ON(!sattr);
|
|
|
|
tattr = flex_array_get(policydb.type_attr_map_array, tcontext->type - 1);
|
|
|
|
BUG_ON(!tattr);
|
SELinux: improve performance when AVC misses.
* We add ebitmap_for_each_positive_bit() which enables to walk on
any positive bit on the given ebitmap, to improve its performance
using common bit-operations defined in linux/bitops.h.
In the previous version, this logic was implemented using a combination
of ebitmap_for_each_bit() and ebitmap_node_get_bit(), but is was worse
in performance aspect.
This logic is most frequestly used to compute a new AVC entry,
so this patch can improve SELinux performance when AVC misses are happen.
* struct ebitmap_node is redefined as an array of "unsigned long", to get
suitable for using find_next_bit() which is fasted than iteration of
shift and logical operation, and to maximize memory usage allocated
from general purpose slab.
* Any ebitmap_for_each_bit() are repleced by the new implementation
in ss/service.c and ss/mls.c. Some of related implementation are
changed, however, there is no incompatibility with the previous
version.
* The width of any new line are less or equal than 80-chars.
The following benchmark shows the effect of this patch, when we
access many files which have different security context one after
another. The number is more than /selinux/avc/cache_threshold, so
any access always causes AVC misses.
selinux-2.6 selinux-2.6-ebitmap
AVG: 22.763 [s] 8.750 [s]
STD: 0.265 0.019
------------------------------------------
1st: 22.558 [s] 8.786 [s]
2nd: 22.458 [s] 8.750 [s]
3rd: 22.478 [s] 8.754 [s]
4th: 22.724 [s] 8.745 [s]
5th: 22.918 [s] 8.748 [s]
6th: 22.905 [s] 8.764 [s]
7th: 23.238 [s] 8.726 [s]
8th: 22.822 [s] 8.729 [s]
Signed-off-by: KaiGai Kohei <kaigai@ak.jp.nec.com>
Acked-by: Stephen Smalley <sds@tycho.nsa.gov>
Signed-off-by: James Morris <jmorris@namei.org>
2007-09-29 01:20:55 +08:00
|
|
|
ebitmap_for_each_positive_bit(sattr, snode, i) {
|
|
|
|
ebitmap_for_each_positive_bit(tattr, tnode, j) {
|
2005-09-04 06:55:16 +08:00
|
|
|
avkey.source_type = i + 1;
|
|
|
|
avkey.target_type = j + 1;
|
|
|
|
for (node = avtab_search_node(&policydb.te_avtab, &avkey);
|
2008-08-07 08:18:20 +08:00
|
|
|
node;
|
2005-09-04 06:55:16 +08:00
|
|
|
node = avtab_search_node_next(node, avkey.specified)) {
|
|
|
|
if (node->key.specified == AVTAB_ALLOWED)
|
|
|
|
avd->allowed |= node->datum.data;
|
|
|
|
else if (node->key.specified == AVTAB_AUDITALLOW)
|
|
|
|
avd->auditallow |= node->datum.data;
|
|
|
|
else if (node->key.specified == AVTAB_AUDITDENY)
|
|
|
|
avd->auditdeny &= node->datum.data;
|
|
|
|
}
|
2005-04-17 06:20:36 +08:00
|
|
|
|
2005-09-04 06:55:16 +08:00
|
|
|
/* Check conditional av table for additional permissions */
|
|
|
|
cond_compute_av(&policydb.te_cond_avtab, &avkey, avd);
|
|
|
|
|
|
|
|
}
|
|
|
|
}
|
2005-04-17 06:20:36 +08:00
|
|
|
|
|
|
|
/*
|
|
|
|
* Remove any permissions prohibited by a constraint (this includes
|
|
|
|
* the MLS policy).
|
|
|
|
*/
|
|
|
|
constraint = tclass_datum->constraints;
|
|
|
|
while (constraint) {
|
|
|
|
if ((constraint->permissions & (avd->allowed)) &&
|
|
|
|
!constraint_expr_eval(scontext, tcontext, NULL,
|
|
|
|
constraint->expr)) {
|
2009-06-18 16:30:07 +08:00
|
|
|
avd->allowed &= ~(constraint->permissions);
|
2005-04-17 06:20:36 +08:00
|
|
|
}
|
|
|
|
constraint = constraint->next;
|
|
|
|
}
|
|
|
|
|
|
|
|
/*
|
|
|
|
* If checking process transition permission and the
|
|
|
|
* role is changing, then check the (current_role, new_role)
|
|
|
|
* pair.
|
|
|
|
*/
|
selinux: dynamic class/perm discovery
Modify SELinux to dynamically discover class and permission values
upon policy load, based on the dynamic object class/perm discovery
logic from libselinux. A mapping is created between kernel-private
class and permission indices used outside the security server and the
policy values used within the security server.
The mappings are only applied upon kernel-internal computations;
similar mappings for the private indices of userspace object managers
is handled on a per-object manager basis by the userspace AVC. The
interfaces for compute_av and transition_sid are split for kernel
vs. userspace; the userspace functions are distinguished by a _user
suffix.
The kernel-private class indices are no longer tied to the policy
values and thus do not need to skip indices for userspace classes;
thus the kernel class index values are compressed. The flask.h
definitions were regenerated by deleting the userspace classes from
refpolicy's definitions and then regenerating the headers. Going
forward, we can just maintain the flask.h, av_permissions.h, and
classmap.h definitions separately from policy as they are no longer
tied to the policy values. The next patch introduces a utility to
automate generation of flask.h and av_permissions.h from the
classmap.h definitions.
The older kernel class and permission string tables are removed and
replaced by a single security class mapping table that is walked at
policy load to generate the mapping. The old kernel class validation
logic is completely replaced by the mapping logic.
The handle unknown logic is reworked. reject_unknown=1 is handled
when the mappings are computed at policy load time, similar to the old
handling by the class validation logic. allow_unknown=1 is handled
when computing and mapping decisions - if the permission was not able
to be mapped (i.e. undefined, mapped to zero), then it is
automatically added to the allowed vector. If the class was not able
to be mapped (i.e. undefined, mapped to zero), then all permissions
are allowed for it if allow_unknown=1.
avc_audit leverages the new security class mapping table to lookup the
class and permission names from the kernel-private indices.
The mdp program is updated to use the new table when generating the
class definitions and allow rules for a minimal boot policy for the
kernel. It should be noted that this policy will not include any
userspace classes, nor will its policy index values for the kernel
classes correspond with the ones in refpolicy (they will instead match
the kernel-private indices).
Signed-off-by: Stephen Smalley <sds@tycho.nsa.gov>
Signed-off-by: James Morris <jmorris@namei.org>
2009-10-01 01:37:50 +08:00
|
|
|
if (tclass == policydb.process_class &&
|
|
|
|
(avd->allowed & policydb.process_trans_perms) &&
|
2005-04-17 06:20:36 +08:00
|
|
|
scontext->role != tcontext->role) {
|
|
|
|
for (ra = policydb.role_allow; ra; ra = ra->next) {
|
|
|
|
if (scontext->role == ra->role &&
|
|
|
|
tcontext->role == ra->new_role)
|
|
|
|
break;
|
|
|
|
}
|
|
|
|
if (!ra)
|
selinux: dynamic class/perm discovery
Modify SELinux to dynamically discover class and permission values
upon policy load, based on the dynamic object class/perm discovery
logic from libselinux. A mapping is created between kernel-private
class and permission indices used outside the security server and the
policy values used within the security server.
The mappings are only applied upon kernel-internal computations;
similar mappings for the private indices of userspace object managers
is handled on a per-object manager basis by the userspace AVC. The
interfaces for compute_av and transition_sid are split for kernel
vs. userspace; the userspace functions are distinguished by a _user
suffix.
The kernel-private class indices are no longer tied to the policy
values and thus do not need to skip indices for userspace classes;
thus the kernel class index values are compressed. The flask.h
definitions were regenerated by deleting the userspace classes from
refpolicy's definitions and then regenerating the headers. Going
forward, we can just maintain the flask.h, av_permissions.h, and
classmap.h definitions separately from policy as they are no longer
tied to the policy values. The next patch introduces a utility to
automate generation of flask.h and av_permissions.h from the
classmap.h definitions.
The older kernel class and permission string tables are removed and
replaced by a single security class mapping table that is walked at
policy load to generate the mapping. The old kernel class validation
logic is completely replaced by the mapping logic.
The handle unknown logic is reworked. reject_unknown=1 is handled
when the mappings are computed at policy load time, similar to the old
handling by the class validation logic. allow_unknown=1 is handled
when computing and mapping decisions - if the permission was not able
to be mapped (i.e. undefined, mapped to zero), then it is
automatically added to the allowed vector. If the class was not able
to be mapped (i.e. undefined, mapped to zero), then all permissions
are allowed for it if allow_unknown=1.
avc_audit leverages the new security class mapping table to lookup the
class and permission names from the kernel-private indices.
The mdp program is updated to use the new table when generating the
class definitions and allow rules for a minimal boot policy for the
kernel. It should be noted that this policy will not include any
userspace classes, nor will its policy index values for the kernel
classes correspond with the ones in refpolicy (they will instead match
the kernel-private indices).
Signed-off-by: Stephen Smalley <sds@tycho.nsa.gov>
Signed-off-by: James Morris <jmorris@namei.org>
2009-10-01 01:37:50 +08:00
|
|
|
avd->allowed &= ~policydb.process_trans_perms;
|
2005-04-17 06:20:36 +08:00
|
|
|
}
|
|
|
|
|
2008-08-28 15:35:57 +08:00
|
|
|
/*
|
|
|
|
* If the given source and target types have boundary
|
|
|
|
* constraint, lazy checks have to mask any violated
|
|
|
|
* permission and notice it to userspace via audit.
|
|
|
|
*/
|
|
|
|
type_attribute_bounds_av(scontext, tcontext,
|
2010-01-15 06:28:10 +08:00
|
|
|
tclass, avd);
|
2005-04-17 06:20:36 +08:00
|
|
|
}
|
|
|
|
|
|
|
|
static int security_validtrans_handle_fail(struct context *ocontext,
|
2008-04-19 05:38:33 +08:00
|
|
|
struct context *ncontext,
|
|
|
|
struct context *tcontext,
|
|
|
|
u16 tclass)
|
2005-04-17 06:20:36 +08:00
|
|
|
{
|
|
|
|
char *o = NULL, *n = NULL, *t = NULL;
|
|
|
|
u32 olen, nlen, tlen;
|
|
|
|
|
|
|
|
if (context_struct_to_string(ocontext, &o, &olen) < 0)
|
|
|
|
goto out;
|
|
|
|
if (context_struct_to_string(ncontext, &n, &nlen) < 0)
|
|
|
|
goto out;
|
|
|
|
if (context_struct_to_string(tcontext, &t, &tlen) < 0)
|
|
|
|
goto out;
|
2005-06-22 22:04:33 +08:00
|
|
|
audit_log(current->audit_context, GFP_ATOMIC, AUDIT_SELINUX_ERR,
|
2008-04-19 05:38:33 +08:00
|
|
|
"security_validate_transition: denied for"
|
|
|
|
" oldcontext=%s newcontext=%s taskcontext=%s tclass=%s",
|
|
|
|
o, n, t, policydb.p_class_val_to_name[tclass-1]);
|
2005-04-17 06:20:36 +08:00
|
|
|
out:
|
|
|
|
kfree(o);
|
|
|
|
kfree(n);
|
|
|
|
kfree(t);
|
|
|
|
|
|
|
|
if (!selinux_enforcing)
|
|
|
|
return 0;
|
|
|
|
return -EPERM;
|
|
|
|
}
|
|
|
|
|
|
|
|
int security_validate_transition(u32 oldsid, u32 newsid, u32 tasksid,
|
selinux: dynamic class/perm discovery
Modify SELinux to dynamically discover class and permission values
upon policy load, based on the dynamic object class/perm discovery
logic from libselinux. A mapping is created between kernel-private
class and permission indices used outside the security server and the
policy values used within the security server.
The mappings are only applied upon kernel-internal computations;
similar mappings for the private indices of userspace object managers
is handled on a per-object manager basis by the userspace AVC. The
interfaces for compute_av and transition_sid are split for kernel
vs. userspace; the userspace functions are distinguished by a _user
suffix.
The kernel-private class indices are no longer tied to the policy
values and thus do not need to skip indices for userspace classes;
thus the kernel class index values are compressed. The flask.h
definitions were regenerated by deleting the userspace classes from
refpolicy's definitions and then regenerating the headers. Going
forward, we can just maintain the flask.h, av_permissions.h, and
classmap.h definitions separately from policy as they are no longer
tied to the policy values. The next patch introduces a utility to
automate generation of flask.h and av_permissions.h from the
classmap.h definitions.
The older kernel class and permission string tables are removed and
replaced by a single security class mapping table that is walked at
policy load to generate the mapping. The old kernel class validation
logic is completely replaced by the mapping logic.
The handle unknown logic is reworked. reject_unknown=1 is handled
when the mappings are computed at policy load time, similar to the old
handling by the class validation logic. allow_unknown=1 is handled
when computing and mapping decisions - if the permission was not able
to be mapped (i.e. undefined, mapped to zero), then it is
automatically added to the allowed vector. If the class was not able
to be mapped (i.e. undefined, mapped to zero), then all permissions
are allowed for it if allow_unknown=1.
avc_audit leverages the new security class mapping table to lookup the
class and permission names from the kernel-private indices.
The mdp program is updated to use the new table when generating the
class definitions and allow rules for a minimal boot policy for the
kernel. It should be noted that this policy will not include any
userspace classes, nor will its policy index values for the kernel
classes correspond with the ones in refpolicy (they will instead match
the kernel-private indices).
Signed-off-by: Stephen Smalley <sds@tycho.nsa.gov>
Signed-off-by: James Morris <jmorris@namei.org>
2009-10-01 01:37:50 +08:00
|
|
|
u16 orig_tclass)
|
2005-04-17 06:20:36 +08:00
|
|
|
{
|
|
|
|
struct context *ocontext;
|
|
|
|
struct context *ncontext;
|
|
|
|
struct context *tcontext;
|
|
|
|
struct class_datum *tclass_datum;
|
|
|
|
struct constraint_node *constraint;
|
selinux: dynamic class/perm discovery
Modify SELinux to dynamically discover class and permission values
upon policy load, based on the dynamic object class/perm discovery
logic from libselinux. A mapping is created between kernel-private
class and permission indices used outside the security server and the
policy values used within the security server.
The mappings are only applied upon kernel-internal computations;
similar mappings for the private indices of userspace object managers
is handled on a per-object manager basis by the userspace AVC. The
interfaces for compute_av and transition_sid are split for kernel
vs. userspace; the userspace functions are distinguished by a _user
suffix.
The kernel-private class indices are no longer tied to the policy
values and thus do not need to skip indices for userspace classes;
thus the kernel class index values are compressed. The flask.h
definitions were regenerated by deleting the userspace classes from
refpolicy's definitions and then regenerating the headers. Going
forward, we can just maintain the flask.h, av_permissions.h, and
classmap.h definitions separately from policy as they are no longer
tied to the policy values. The next patch introduces a utility to
automate generation of flask.h and av_permissions.h from the
classmap.h definitions.
The older kernel class and permission string tables are removed and
replaced by a single security class mapping table that is walked at
policy load to generate the mapping. The old kernel class validation
logic is completely replaced by the mapping logic.
The handle unknown logic is reworked. reject_unknown=1 is handled
when the mappings are computed at policy load time, similar to the old
handling by the class validation logic. allow_unknown=1 is handled
when computing and mapping decisions - if the permission was not able
to be mapped (i.e. undefined, mapped to zero), then it is
automatically added to the allowed vector. If the class was not able
to be mapped (i.e. undefined, mapped to zero), then all permissions
are allowed for it if allow_unknown=1.
avc_audit leverages the new security class mapping table to lookup the
class and permission names from the kernel-private indices.
The mdp program is updated to use the new table when generating the
class definitions and allow rules for a minimal boot policy for the
kernel. It should be noted that this policy will not include any
userspace classes, nor will its policy index values for the kernel
classes correspond with the ones in refpolicy (they will instead match
the kernel-private indices).
Signed-off-by: Stephen Smalley <sds@tycho.nsa.gov>
Signed-off-by: James Morris <jmorris@namei.org>
2009-10-01 01:37:50 +08:00
|
|
|
u16 tclass;
|
2005-04-17 06:20:36 +08:00
|
|
|
int rc = 0;
|
|
|
|
|
|
|
|
if (!ss_initialized)
|
|
|
|
return 0;
|
|
|
|
|
2008-06-06 16:40:29 +08:00
|
|
|
read_lock(&policy_rwlock);
|
2005-04-17 06:20:36 +08:00
|
|
|
|
selinux: dynamic class/perm discovery
Modify SELinux to dynamically discover class and permission values
upon policy load, based on the dynamic object class/perm discovery
logic from libselinux. A mapping is created between kernel-private
class and permission indices used outside the security server and the
policy values used within the security server.
The mappings are only applied upon kernel-internal computations;
similar mappings for the private indices of userspace object managers
is handled on a per-object manager basis by the userspace AVC. The
interfaces for compute_av and transition_sid are split for kernel
vs. userspace; the userspace functions are distinguished by a _user
suffix.
The kernel-private class indices are no longer tied to the policy
values and thus do not need to skip indices for userspace classes;
thus the kernel class index values are compressed. The flask.h
definitions were regenerated by deleting the userspace classes from
refpolicy's definitions and then regenerating the headers. Going
forward, we can just maintain the flask.h, av_permissions.h, and
classmap.h definitions separately from policy as they are no longer
tied to the policy values. The next patch introduces a utility to
automate generation of flask.h and av_permissions.h from the
classmap.h definitions.
The older kernel class and permission string tables are removed and
replaced by a single security class mapping table that is walked at
policy load to generate the mapping. The old kernel class validation
logic is completely replaced by the mapping logic.
The handle unknown logic is reworked. reject_unknown=1 is handled
when the mappings are computed at policy load time, similar to the old
handling by the class validation logic. allow_unknown=1 is handled
when computing and mapping decisions - if the permission was not able
to be mapped (i.e. undefined, mapped to zero), then it is
automatically added to the allowed vector. If the class was not able
to be mapped (i.e. undefined, mapped to zero), then all permissions
are allowed for it if allow_unknown=1.
avc_audit leverages the new security class mapping table to lookup the
class and permission names from the kernel-private indices.
The mdp program is updated to use the new table when generating the
class definitions and allow rules for a minimal boot policy for the
kernel. It should be noted that this policy will not include any
userspace classes, nor will its policy index values for the kernel
classes correspond with the ones in refpolicy (they will instead match
the kernel-private indices).
Signed-off-by: Stephen Smalley <sds@tycho.nsa.gov>
Signed-off-by: James Morris <jmorris@namei.org>
2009-10-01 01:37:50 +08:00
|
|
|
tclass = unmap_class(orig_tclass);
|
|
|
|
|
2005-04-17 06:20:36 +08:00
|
|
|
if (!tclass || tclass > policydb.p_classes.nprim) {
|
2008-04-17 23:52:44 +08:00
|
|
|
printk(KERN_ERR "SELinux: %s: unrecognized class %d\n",
|
|
|
|
__func__, tclass);
|
2005-04-17 06:20:36 +08:00
|
|
|
rc = -EINVAL;
|
|
|
|
goto out;
|
|
|
|
}
|
|
|
|
tclass_datum = policydb.class_val_to_struct[tclass - 1];
|
|
|
|
|
|
|
|
ocontext = sidtab_search(&sidtab, oldsid);
|
|
|
|
if (!ocontext) {
|
2008-04-17 23:52:44 +08:00
|
|
|
printk(KERN_ERR "SELinux: %s: unrecognized SID %d\n",
|
|
|
|
__func__, oldsid);
|
2005-04-17 06:20:36 +08:00
|
|
|
rc = -EINVAL;
|
|
|
|
goto out;
|
|
|
|
}
|
|
|
|
|
|
|
|
ncontext = sidtab_search(&sidtab, newsid);
|
|
|
|
if (!ncontext) {
|
2008-04-17 23:52:44 +08:00
|
|
|
printk(KERN_ERR "SELinux: %s: unrecognized SID %d\n",
|
|
|
|
__func__, newsid);
|
2005-04-17 06:20:36 +08:00
|
|
|
rc = -EINVAL;
|
|
|
|
goto out;
|
|
|
|
}
|
|
|
|
|
|
|
|
tcontext = sidtab_search(&sidtab, tasksid);
|
|
|
|
if (!tcontext) {
|
2008-04-17 23:52:44 +08:00
|
|
|
printk(KERN_ERR "SELinux: %s: unrecognized SID %d\n",
|
|
|
|
__func__, tasksid);
|
2005-04-17 06:20:36 +08:00
|
|
|
rc = -EINVAL;
|
|
|
|
goto out;
|
|
|
|
}
|
|
|
|
|
|
|
|
constraint = tclass_datum->validatetrans;
|
|
|
|
while (constraint) {
|
|
|
|
if (!constraint_expr_eval(ocontext, ncontext, tcontext,
|
2008-04-19 05:38:33 +08:00
|
|
|
constraint->expr)) {
|
2005-04-17 06:20:36 +08:00
|
|
|
rc = security_validtrans_handle_fail(ocontext, ncontext,
|
2008-04-19 05:38:33 +08:00
|
|
|
tcontext, tclass);
|
2005-04-17 06:20:36 +08:00
|
|
|
goto out;
|
|
|
|
}
|
|
|
|
constraint = constraint->next;
|
|
|
|
}
|
|
|
|
|
|
|
|
out:
|
2008-06-06 16:40:29 +08:00
|
|
|
read_unlock(&policy_rwlock);
|
2005-04-17 06:20:36 +08:00
|
|
|
return rc;
|
|
|
|
}
|
|
|
|
|
2008-08-28 15:35:57 +08:00
|
|
|
/*
|
|
|
|
* security_bounded_transition - check whether the given
|
|
|
|
* transition is directed to bounded, or not.
|
|
|
|
* It returns 0, if @newsid is bounded by @oldsid.
|
|
|
|
* Otherwise, it returns error code.
|
|
|
|
*
|
|
|
|
* @oldsid : current security identifier
|
|
|
|
* @newsid : destinated security identifier
|
|
|
|
*/
|
|
|
|
int security_bounded_transition(u32 old_sid, u32 new_sid)
|
|
|
|
{
|
|
|
|
struct context *old_context, *new_context;
|
|
|
|
struct type_datum *type;
|
|
|
|
int index;
|
|
|
|
int rc = -EINVAL;
|
|
|
|
|
|
|
|
read_lock(&policy_rwlock);
|
|
|
|
|
|
|
|
old_context = sidtab_search(&sidtab, old_sid);
|
|
|
|
if (!old_context) {
|
|
|
|
printk(KERN_ERR "SELinux: %s: unrecognized SID %u\n",
|
|
|
|
__func__, old_sid);
|
|
|
|
goto out;
|
|
|
|
}
|
|
|
|
|
|
|
|
new_context = sidtab_search(&sidtab, new_sid);
|
|
|
|
if (!new_context) {
|
|
|
|
printk(KERN_ERR "SELinux: %s: unrecognized SID %u\n",
|
|
|
|
__func__, new_sid);
|
|
|
|
goto out;
|
|
|
|
}
|
|
|
|
|
tree-wide: fix assorted typos all over the place
That is "success", "unknown", "through", "performance", "[re|un]mapping"
, "access", "default", "reasonable", "[con]currently", "temperature"
, "channel", "[un]used", "application", "example","hierarchy", "therefore"
, "[over|under]flow", "contiguous", "threshold", "enough" and others.
Signed-off-by: André Goddard Rosa <andre.goddard@gmail.com>
Signed-off-by: Jiri Kosina <jkosina@suse.cz>
2009-11-14 23:09:05 +08:00
|
|
|
/* type/domain unchanged */
|
2008-08-28 15:35:57 +08:00
|
|
|
if (old_context->type == new_context->type) {
|
|
|
|
rc = 0;
|
|
|
|
goto out;
|
|
|
|
}
|
|
|
|
|
|
|
|
index = new_context->type;
|
|
|
|
while (true) {
|
|
|
|
type = policydb.type_val_to_struct[index - 1];
|
|
|
|
BUG_ON(!type);
|
|
|
|
|
|
|
|
/* not bounded anymore */
|
|
|
|
if (!type->bounds) {
|
|
|
|
rc = -EPERM;
|
|
|
|
break;
|
|
|
|
}
|
|
|
|
|
|
|
|
/* @newsid is bounded by @oldsid */
|
|
|
|
if (type->bounds == old_context->type) {
|
|
|
|
rc = 0;
|
|
|
|
break;
|
|
|
|
}
|
|
|
|
index = type->bounds;
|
|
|
|
}
|
2009-06-18 16:26:13 +08:00
|
|
|
|
|
|
|
if (rc) {
|
|
|
|
char *old_name = NULL;
|
|
|
|
char *new_name = NULL;
|
2010-02-16 14:29:06 +08:00
|
|
|
u32 length;
|
2009-06-18 16:26:13 +08:00
|
|
|
|
|
|
|
if (!context_struct_to_string(old_context,
|
|
|
|
&old_name, &length) &&
|
|
|
|
!context_struct_to_string(new_context,
|
|
|
|
&new_name, &length)) {
|
|
|
|
audit_log(current->audit_context,
|
|
|
|
GFP_ATOMIC, AUDIT_SELINUX_ERR,
|
|
|
|
"op=security_bounded_transition "
|
|
|
|
"result=denied "
|
|
|
|
"oldcontext=%s newcontext=%s",
|
|
|
|
old_name, new_name);
|
|
|
|
}
|
|
|
|
kfree(new_name);
|
|
|
|
kfree(old_name);
|
|
|
|
}
|
2008-08-28 15:35:57 +08:00
|
|
|
out:
|
|
|
|
read_unlock(&policy_rwlock);
|
|
|
|
|
|
|
|
return rc;
|
|
|
|
}
|
|
|
|
|
2010-01-15 06:28:10 +08:00
|
|
|
static void avd_init(struct av_decision *avd)
|
selinux: dynamic class/perm discovery
Modify SELinux to dynamically discover class and permission values
upon policy load, based on the dynamic object class/perm discovery
logic from libselinux. A mapping is created between kernel-private
class and permission indices used outside the security server and the
policy values used within the security server.
The mappings are only applied upon kernel-internal computations;
similar mappings for the private indices of userspace object managers
is handled on a per-object manager basis by the userspace AVC. The
interfaces for compute_av and transition_sid are split for kernel
vs. userspace; the userspace functions are distinguished by a _user
suffix.
The kernel-private class indices are no longer tied to the policy
values and thus do not need to skip indices for userspace classes;
thus the kernel class index values are compressed. The flask.h
definitions were regenerated by deleting the userspace classes from
refpolicy's definitions and then regenerating the headers. Going
forward, we can just maintain the flask.h, av_permissions.h, and
classmap.h definitions separately from policy as they are no longer
tied to the policy values. The next patch introduces a utility to
automate generation of flask.h and av_permissions.h from the
classmap.h definitions.
The older kernel class and permission string tables are removed and
replaced by a single security class mapping table that is walked at
policy load to generate the mapping. The old kernel class validation
logic is completely replaced by the mapping logic.
The handle unknown logic is reworked. reject_unknown=1 is handled
when the mappings are computed at policy load time, similar to the old
handling by the class validation logic. allow_unknown=1 is handled
when computing and mapping decisions - if the permission was not able
to be mapped (i.e. undefined, mapped to zero), then it is
automatically added to the allowed vector. If the class was not able
to be mapped (i.e. undefined, mapped to zero), then all permissions
are allowed for it if allow_unknown=1.
avc_audit leverages the new security class mapping table to lookup the
class and permission names from the kernel-private indices.
The mdp program is updated to use the new table when generating the
class definitions and allow rules for a minimal boot policy for the
kernel. It should be noted that this policy will not include any
userspace classes, nor will its policy index values for the kernel
classes correspond with the ones in refpolicy (they will instead match
the kernel-private indices).
Signed-off-by: Stephen Smalley <sds@tycho.nsa.gov>
Signed-off-by: James Morris <jmorris@namei.org>
2009-10-01 01:37:50 +08:00
|
|
|
{
|
2010-01-15 06:28:10 +08:00
|
|
|
avd->allowed = 0;
|
|
|
|
avd->auditallow = 0;
|
|
|
|
avd->auditdeny = 0xffffffff;
|
|
|
|
avd->seqno = latest_granting;
|
|
|
|
avd->flags = 0;
|
selinux: dynamic class/perm discovery
Modify SELinux to dynamically discover class and permission values
upon policy load, based on the dynamic object class/perm discovery
logic from libselinux. A mapping is created between kernel-private
class and permission indices used outside the security server and the
policy values used within the security server.
The mappings are only applied upon kernel-internal computations;
similar mappings for the private indices of userspace object managers
is handled on a per-object manager basis by the userspace AVC. The
interfaces for compute_av and transition_sid are split for kernel
vs. userspace; the userspace functions are distinguished by a _user
suffix.
The kernel-private class indices are no longer tied to the policy
values and thus do not need to skip indices for userspace classes;
thus the kernel class index values are compressed. The flask.h
definitions were regenerated by deleting the userspace classes from
refpolicy's definitions and then regenerating the headers. Going
forward, we can just maintain the flask.h, av_permissions.h, and
classmap.h definitions separately from policy as they are no longer
tied to the policy values. The next patch introduces a utility to
automate generation of flask.h and av_permissions.h from the
classmap.h definitions.
The older kernel class and permission string tables are removed and
replaced by a single security class mapping table that is walked at
policy load to generate the mapping. The old kernel class validation
logic is completely replaced by the mapping logic.
The handle unknown logic is reworked. reject_unknown=1 is handled
when the mappings are computed at policy load time, similar to the old
handling by the class validation logic. allow_unknown=1 is handled
when computing and mapping decisions - if the permission was not able
to be mapped (i.e. undefined, mapped to zero), then it is
automatically added to the allowed vector. If the class was not able
to be mapped (i.e. undefined, mapped to zero), then all permissions
are allowed for it if allow_unknown=1.
avc_audit leverages the new security class mapping table to lookup the
class and permission names from the kernel-private indices.
The mdp program is updated to use the new table when generating the
class definitions and allow rules for a minimal boot policy for the
kernel. It should be noted that this policy will not include any
userspace classes, nor will its policy index values for the kernel
classes correspond with the ones in refpolicy (they will instead match
the kernel-private indices).
Signed-off-by: Stephen Smalley <sds@tycho.nsa.gov>
Signed-off-by: James Morris <jmorris@namei.org>
2009-10-01 01:37:50 +08:00
|
|
|
}
|
|
|
|
|
2010-01-15 06:28:10 +08:00
|
|
|
|
2005-04-17 06:20:36 +08:00
|
|
|
/**
|
|
|
|
* security_compute_av - Compute access vector decisions.
|
|
|
|
* @ssid: source security identifier
|
|
|
|
* @tsid: target security identifier
|
|
|
|
* @tclass: target security class
|
|
|
|
* @avd: access vector decisions
|
|
|
|
*
|
|
|
|
* Compute a set of access vector decisions based on the
|
|
|
|
* SID pair (@ssid, @tsid) for the permissions in @tclass.
|
|
|
|
*/
|
2010-01-15 06:28:10 +08:00
|
|
|
void security_compute_av(u32 ssid,
|
|
|
|
u32 tsid,
|
|
|
|
u16 orig_tclass,
|
|
|
|
struct av_decision *avd)
|
2005-04-17 06:20:36 +08:00
|
|
|
{
|
selinux: dynamic class/perm discovery
Modify SELinux to dynamically discover class and permission values
upon policy load, based on the dynamic object class/perm discovery
logic from libselinux. A mapping is created between kernel-private
class and permission indices used outside the security server and the
policy values used within the security server.
The mappings are only applied upon kernel-internal computations;
similar mappings for the private indices of userspace object managers
is handled on a per-object manager basis by the userspace AVC. The
interfaces for compute_av and transition_sid are split for kernel
vs. userspace; the userspace functions are distinguished by a _user
suffix.
The kernel-private class indices are no longer tied to the policy
values and thus do not need to skip indices for userspace classes;
thus the kernel class index values are compressed. The flask.h
definitions were regenerated by deleting the userspace classes from
refpolicy's definitions and then regenerating the headers. Going
forward, we can just maintain the flask.h, av_permissions.h, and
classmap.h definitions separately from policy as they are no longer
tied to the policy values. The next patch introduces a utility to
automate generation of flask.h and av_permissions.h from the
classmap.h definitions.
The older kernel class and permission string tables are removed and
replaced by a single security class mapping table that is walked at
policy load to generate the mapping. The old kernel class validation
logic is completely replaced by the mapping logic.
The handle unknown logic is reworked. reject_unknown=1 is handled
when the mappings are computed at policy load time, similar to the old
handling by the class validation logic. allow_unknown=1 is handled
when computing and mapping decisions - if the permission was not able
to be mapped (i.e. undefined, mapped to zero), then it is
automatically added to the allowed vector. If the class was not able
to be mapped (i.e. undefined, mapped to zero), then all permissions
are allowed for it if allow_unknown=1.
avc_audit leverages the new security class mapping table to lookup the
class and permission names from the kernel-private indices.
The mdp program is updated to use the new table when generating the
class definitions and allow rules for a minimal boot policy for the
kernel. It should be noted that this policy will not include any
userspace classes, nor will its policy index values for the kernel
classes correspond with the ones in refpolicy (they will instead match
the kernel-private indices).
Signed-off-by: Stephen Smalley <sds@tycho.nsa.gov>
Signed-off-by: James Morris <jmorris@namei.org>
2009-10-01 01:37:50 +08:00
|
|
|
u16 tclass;
|
2010-01-15 06:28:10 +08:00
|
|
|
struct context *scontext = NULL, *tcontext = NULL;
|
selinux: dynamic class/perm discovery
Modify SELinux to dynamically discover class and permission values
upon policy load, based on the dynamic object class/perm discovery
logic from libselinux. A mapping is created between kernel-private
class and permission indices used outside the security server and the
policy values used within the security server.
The mappings are only applied upon kernel-internal computations;
similar mappings for the private indices of userspace object managers
is handled on a per-object manager basis by the userspace AVC. The
interfaces for compute_av and transition_sid are split for kernel
vs. userspace; the userspace functions are distinguished by a _user
suffix.
The kernel-private class indices are no longer tied to the policy
values and thus do not need to skip indices for userspace classes;
thus the kernel class index values are compressed. The flask.h
definitions were regenerated by deleting the userspace classes from
refpolicy's definitions and then regenerating the headers. Going
forward, we can just maintain the flask.h, av_permissions.h, and
classmap.h definitions separately from policy as they are no longer
tied to the policy values. The next patch introduces a utility to
automate generation of flask.h and av_permissions.h from the
classmap.h definitions.
The older kernel class and permission string tables are removed and
replaced by a single security class mapping table that is walked at
policy load to generate the mapping. The old kernel class validation
logic is completely replaced by the mapping logic.
The handle unknown logic is reworked. reject_unknown=1 is handled
when the mappings are computed at policy load time, similar to the old
handling by the class validation logic. allow_unknown=1 is handled
when computing and mapping decisions - if the permission was not able
to be mapped (i.e. undefined, mapped to zero), then it is
automatically added to the allowed vector. If the class was not able
to be mapped (i.e. undefined, mapped to zero), then all permissions
are allowed for it if allow_unknown=1.
avc_audit leverages the new security class mapping table to lookup the
class and permission names from the kernel-private indices.
The mdp program is updated to use the new table when generating the
class definitions and allow rules for a minimal boot policy for the
kernel. It should be noted that this policy will not include any
userspace classes, nor will its policy index values for the kernel
classes correspond with the ones in refpolicy (they will instead match
the kernel-private indices).
Signed-off-by: Stephen Smalley <sds@tycho.nsa.gov>
Signed-off-by: James Morris <jmorris@namei.org>
2009-10-01 01:37:50 +08:00
|
|
|
|
2009-10-19 22:08:50 +08:00
|
|
|
read_lock(&policy_rwlock);
|
2010-01-15 06:28:10 +08:00
|
|
|
avd_init(avd);
|
selinux: dynamic class/perm discovery
Modify SELinux to dynamically discover class and permission values
upon policy load, based on the dynamic object class/perm discovery
logic from libselinux. A mapping is created between kernel-private
class and permission indices used outside the security server and the
policy values used within the security server.
The mappings are only applied upon kernel-internal computations;
similar mappings for the private indices of userspace object managers
is handled on a per-object manager basis by the userspace AVC. The
interfaces for compute_av and transition_sid are split for kernel
vs. userspace; the userspace functions are distinguished by a _user
suffix.
The kernel-private class indices are no longer tied to the policy
values and thus do not need to skip indices for userspace classes;
thus the kernel class index values are compressed. The flask.h
definitions were regenerated by deleting the userspace classes from
refpolicy's definitions and then regenerating the headers. Going
forward, we can just maintain the flask.h, av_permissions.h, and
classmap.h definitions separately from policy as they are no longer
tied to the policy values. The next patch introduces a utility to
automate generation of flask.h and av_permissions.h from the
classmap.h definitions.
The older kernel class and permission string tables are removed and
replaced by a single security class mapping table that is walked at
policy load to generate the mapping. The old kernel class validation
logic is completely replaced by the mapping logic.
The handle unknown logic is reworked. reject_unknown=1 is handled
when the mappings are computed at policy load time, similar to the old
handling by the class validation logic. allow_unknown=1 is handled
when computing and mapping decisions - if the permission was not able
to be mapped (i.e. undefined, mapped to zero), then it is
automatically added to the allowed vector. If the class was not able
to be mapped (i.e. undefined, mapped to zero), then all permissions
are allowed for it if allow_unknown=1.
avc_audit leverages the new security class mapping table to lookup the
class and permission names from the kernel-private indices.
The mdp program is updated to use the new table when generating the
class definitions and allow rules for a minimal boot policy for the
kernel. It should be noted that this policy will not include any
userspace classes, nor will its policy index values for the kernel
classes correspond with the ones in refpolicy (they will instead match
the kernel-private indices).
Signed-off-by: Stephen Smalley <sds@tycho.nsa.gov>
Signed-off-by: James Morris <jmorris@namei.org>
2009-10-01 01:37:50 +08:00
|
|
|
if (!ss_initialized)
|
|
|
|
goto allow;
|
|
|
|
|
2010-01-15 06:28:10 +08:00
|
|
|
scontext = sidtab_search(&sidtab, ssid);
|
|
|
|
if (!scontext) {
|
|
|
|
printk(KERN_ERR "SELinux: %s: unrecognized SID %d\n",
|
|
|
|
__func__, ssid);
|
|
|
|
goto out;
|
|
|
|
}
|
|
|
|
|
|
|
|
/* permissive domain? */
|
|
|
|
if (ebitmap_get_bit(&policydb.permissive_map, scontext->type))
|
|
|
|
avd->flags |= AVD_FLAGS_PERMISSIVE;
|
|
|
|
|
|
|
|
tcontext = sidtab_search(&sidtab, tsid);
|
|
|
|
if (!tcontext) {
|
|
|
|
printk(KERN_ERR "SELinux: %s: unrecognized SID %d\n",
|
|
|
|
__func__, tsid);
|
|
|
|
goto out;
|
|
|
|
}
|
|
|
|
|
selinux: dynamic class/perm discovery
Modify SELinux to dynamically discover class and permission values
upon policy load, based on the dynamic object class/perm discovery
logic from libselinux. A mapping is created between kernel-private
class and permission indices used outside the security server and the
policy values used within the security server.
The mappings are only applied upon kernel-internal computations;
similar mappings for the private indices of userspace object managers
is handled on a per-object manager basis by the userspace AVC. The
interfaces for compute_av and transition_sid are split for kernel
vs. userspace; the userspace functions are distinguished by a _user
suffix.
The kernel-private class indices are no longer tied to the policy
values and thus do not need to skip indices for userspace classes;
thus the kernel class index values are compressed. The flask.h
definitions were regenerated by deleting the userspace classes from
refpolicy's definitions and then regenerating the headers. Going
forward, we can just maintain the flask.h, av_permissions.h, and
classmap.h definitions separately from policy as they are no longer
tied to the policy values. The next patch introduces a utility to
automate generation of flask.h and av_permissions.h from the
classmap.h definitions.
The older kernel class and permission string tables are removed and
replaced by a single security class mapping table that is walked at
policy load to generate the mapping. The old kernel class validation
logic is completely replaced by the mapping logic.
The handle unknown logic is reworked. reject_unknown=1 is handled
when the mappings are computed at policy load time, similar to the old
handling by the class validation logic. allow_unknown=1 is handled
when computing and mapping decisions - if the permission was not able
to be mapped (i.e. undefined, mapped to zero), then it is
automatically added to the allowed vector. If the class was not able
to be mapped (i.e. undefined, mapped to zero), then all permissions
are allowed for it if allow_unknown=1.
avc_audit leverages the new security class mapping table to lookup the
class and permission names from the kernel-private indices.
The mdp program is updated to use the new table when generating the
class definitions and allow rules for a minimal boot policy for the
kernel. It should be noted that this policy will not include any
userspace classes, nor will its policy index values for the kernel
classes correspond with the ones in refpolicy (they will instead match
the kernel-private indices).
Signed-off-by: Stephen Smalley <sds@tycho.nsa.gov>
Signed-off-by: James Morris <jmorris@namei.org>
2009-10-01 01:37:50 +08:00
|
|
|
tclass = unmap_class(orig_tclass);
|
|
|
|
if (unlikely(orig_tclass && !tclass)) {
|
|
|
|
if (policydb.allow_unknown)
|
|
|
|
goto allow;
|
2009-10-19 22:08:50 +08:00
|
|
|
goto out;
|
selinux: dynamic class/perm discovery
Modify SELinux to dynamically discover class and permission values
upon policy load, based on the dynamic object class/perm discovery
logic from libselinux. A mapping is created between kernel-private
class and permission indices used outside the security server and the
policy values used within the security server.
The mappings are only applied upon kernel-internal computations;
similar mappings for the private indices of userspace object managers
is handled on a per-object manager basis by the userspace AVC. The
interfaces for compute_av and transition_sid are split for kernel
vs. userspace; the userspace functions are distinguished by a _user
suffix.
The kernel-private class indices are no longer tied to the policy
values and thus do not need to skip indices for userspace classes;
thus the kernel class index values are compressed. The flask.h
definitions were regenerated by deleting the userspace classes from
refpolicy's definitions and then regenerating the headers. Going
forward, we can just maintain the flask.h, av_permissions.h, and
classmap.h definitions separately from policy as they are no longer
tied to the policy values. The next patch introduces a utility to
automate generation of flask.h and av_permissions.h from the
classmap.h definitions.
The older kernel class and permission string tables are removed and
replaced by a single security class mapping table that is walked at
policy load to generate the mapping. The old kernel class validation
logic is completely replaced by the mapping logic.
The handle unknown logic is reworked. reject_unknown=1 is handled
when the mappings are computed at policy load time, similar to the old
handling by the class validation logic. allow_unknown=1 is handled
when computing and mapping decisions - if the permission was not able
to be mapped (i.e. undefined, mapped to zero), then it is
automatically added to the allowed vector. If the class was not able
to be mapped (i.e. undefined, mapped to zero), then all permissions
are allowed for it if allow_unknown=1.
avc_audit leverages the new security class mapping table to lookup the
class and permission names from the kernel-private indices.
The mdp program is updated to use the new table when generating the
class definitions and allow rules for a minimal boot policy for the
kernel. It should be noted that this policy will not include any
userspace classes, nor will its policy index values for the kernel
classes correspond with the ones in refpolicy (they will instead match
the kernel-private indices).
Signed-off-by: Stephen Smalley <sds@tycho.nsa.gov>
Signed-off-by: James Morris <jmorris@namei.org>
2009-10-01 01:37:50 +08:00
|
|
|
}
|
2010-01-15 06:28:10 +08:00
|
|
|
context_struct_compute_av(scontext, tcontext, tclass, avd);
|
selinux: dynamic class/perm discovery
Modify SELinux to dynamically discover class and permission values
upon policy load, based on the dynamic object class/perm discovery
logic from libselinux. A mapping is created between kernel-private
class and permission indices used outside the security server and the
policy values used within the security server.
The mappings are only applied upon kernel-internal computations;
similar mappings for the private indices of userspace object managers
is handled on a per-object manager basis by the userspace AVC. The
interfaces for compute_av and transition_sid are split for kernel
vs. userspace; the userspace functions are distinguished by a _user
suffix.
The kernel-private class indices are no longer tied to the policy
values and thus do not need to skip indices for userspace classes;
thus the kernel class index values are compressed. The flask.h
definitions were regenerated by deleting the userspace classes from
refpolicy's definitions and then regenerating the headers. Going
forward, we can just maintain the flask.h, av_permissions.h, and
classmap.h definitions separately from policy as they are no longer
tied to the policy values. The next patch introduces a utility to
automate generation of flask.h and av_permissions.h from the
classmap.h definitions.
The older kernel class and permission string tables are removed and
replaced by a single security class mapping table that is walked at
policy load to generate the mapping. The old kernel class validation
logic is completely replaced by the mapping logic.
The handle unknown logic is reworked. reject_unknown=1 is handled
when the mappings are computed at policy load time, similar to the old
handling by the class validation logic. allow_unknown=1 is handled
when computing and mapping decisions - if the permission was not able
to be mapped (i.e. undefined, mapped to zero), then it is
automatically added to the allowed vector. If the class was not able
to be mapped (i.e. undefined, mapped to zero), then all permissions
are allowed for it if allow_unknown=1.
avc_audit leverages the new security class mapping table to lookup the
class and permission names from the kernel-private indices.
The mdp program is updated to use the new table when generating the
class definitions and allow rules for a minimal boot policy for the
kernel. It should be noted that this policy will not include any
userspace classes, nor will its policy index values for the kernel
classes correspond with the ones in refpolicy (they will instead match
the kernel-private indices).
Signed-off-by: Stephen Smalley <sds@tycho.nsa.gov>
Signed-off-by: James Morris <jmorris@namei.org>
2009-10-01 01:37:50 +08:00
|
|
|
map_decision(orig_tclass, avd, policydb.allow_unknown);
|
2009-10-19 22:08:50 +08:00
|
|
|
out:
|
selinux: dynamic class/perm discovery
Modify SELinux to dynamically discover class and permission values
upon policy load, based on the dynamic object class/perm discovery
logic from libselinux. A mapping is created between kernel-private
class and permission indices used outside the security server and the
policy values used within the security server.
The mappings are only applied upon kernel-internal computations;
similar mappings for the private indices of userspace object managers
is handled on a per-object manager basis by the userspace AVC. The
interfaces for compute_av and transition_sid are split for kernel
vs. userspace; the userspace functions are distinguished by a _user
suffix.
The kernel-private class indices are no longer tied to the policy
values and thus do not need to skip indices for userspace classes;
thus the kernel class index values are compressed. The flask.h
definitions were regenerated by deleting the userspace classes from
refpolicy's definitions and then regenerating the headers. Going
forward, we can just maintain the flask.h, av_permissions.h, and
classmap.h definitions separately from policy as they are no longer
tied to the policy values. The next patch introduces a utility to
automate generation of flask.h and av_permissions.h from the
classmap.h definitions.
The older kernel class and permission string tables are removed and
replaced by a single security class mapping table that is walked at
policy load to generate the mapping. The old kernel class validation
logic is completely replaced by the mapping logic.
The handle unknown logic is reworked. reject_unknown=1 is handled
when the mappings are computed at policy load time, similar to the old
handling by the class validation logic. allow_unknown=1 is handled
when computing and mapping decisions - if the permission was not able
to be mapped (i.e. undefined, mapped to zero), then it is
automatically added to the allowed vector. If the class was not able
to be mapped (i.e. undefined, mapped to zero), then all permissions
are allowed for it if allow_unknown=1.
avc_audit leverages the new security class mapping table to lookup the
class and permission names from the kernel-private indices.
The mdp program is updated to use the new table when generating the
class definitions and allow rules for a minimal boot policy for the
kernel. It should be noted that this policy will not include any
userspace classes, nor will its policy index values for the kernel
classes correspond with the ones in refpolicy (they will instead match
the kernel-private indices).
Signed-off-by: Stephen Smalley <sds@tycho.nsa.gov>
Signed-off-by: James Morris <jmorris@namei.org>
2009-10-01 01:37:50 +08:00
|
|
|
read_unlock(&policy_rwlock);
|
2010-01-15 06:28:10 +08:00
|
|
|
return;
|
selinux: dynamic class/perm discovery
Modify SELinux to dynamically discover class and permission values
upon policy load, based on the dynamic object class/perm discovery
logic from libselinux. A mapping is created between kernel-private
class and permission indices used outside the security server and the
policy values used within the security server.
The mappings are only applied upon kernel-internal computations;
similar mappings for the private indices of userspace object managers
is handled on a per-object manager basis by the userspace AVC. The
interfaces for compute_av and transition_sid are split for kernel
vs. userspace; the userspace functions are distinguished by a _user
suffix.
The kernel-private class indices are no longer tied to the policy
values and thus do not need to skip indices for userspace classes;
thus the kernel class index values are compressed. The flask.h
definitions were regenerated by deleting the userspace classes from
refpolicy's definitions and then regenerating the headers. Going
forward, we can just maintain the flask.h, av_permissions.h, and
classmap.h definitions separately from policy as they are no longer
tied to the policy values. The next patch introduces a utility to
automate generation of flask.h and av_permissions.h from the
classmap.h definitions.
The older kernel class and permission string tables are removed and
replaced by a single security class mapping table that is walked at
policy load to generate the mapping. The old kernel class validation
logic is completely replaced by the mapping logic.
The handle unknown logic is reworked. reject_unknown=1 is handled
when the mappings are computed at policy load time, similar to the old
handling by the class validation logic. allow_unknown=1 is handled
when computing and mapping decisions - if the permission was not able
to be mapped (i.e. undefined, mapped to zero), then it is
automatically added to the allowed vector. If the class was not able
to be mapped (i.e. undefined, mapped to zero), then all permissions
are allowed for it if allow_unknown=1.
avc_audit leverages the new security class mapping table to lookup the
class and permission names from the kernel-private indices.
The mdp program is updated to use the new table when generating the
class definitions and allow rules for a minimal boot policy for the
kernel. It should be noted that this policy will not include any
userspace classes, nor will its policy index values for the kernel
classes correspond with the ones in refpolicy (they will instead match
the kernel-private indices).
Signed-off-by: Stephen Smalley <sds@tycho.nsa.gov>
Signed-off-by: James Morris <jmorris@namei.org>
2009-10-01 01:37:50 +08:00
|
|
|
allow:
|
|
|
|
avd->allowed = 0xffffffff;
|
2009-10-19 22:08:50 +08:00
|
|
|
goto out;
|
selinux: dynamic class/perm discovery
Modify SELinux to dynamically discover class and permission values
upon policy load, based on the dynamic object class/perm discovery
logic from libselinux. A mapping is created between kernel-private
class and permission indices used outside the security server and the
policy values used within the security server.
The mappings are only applied upon kernel-internal computations;
similar mappings for the private indices of userspace object managers
is handled on a per-object manager basis by the userspace AVC. The
interfaces for compute_av and transition_sid are split for kernel
vs. userspace; the userspace functions are distinguished by a _user
suffix.
The kernel-private class indices are no longer tied to the policy
values and thus do not need to skip indices for userspace classes;
thus the kernel class index values are compressed. The flask.h
definitions were regenerated by deleting the userspace classes from
refpolicy's definitions and then regenerating the headers. Going
forward, we can just maintain the flask.h, av_permissions.h, and
classmap.h definitions separately from policy as they are no longer
tied to the policy values. The next patch introduces a utility to
automate generation of flask.h and av_permissions.h from the
classmap.h definitions.
The older kernel class and permission string tables are removed and
replaced by a single security class mapping table that is walked at
policy load to generate the mapping. The old kernel class validation
logic is completely replaced by the mapping logic.
The handle unknown logic is reworked. reject_unknown=1 is handled
when the mappings are computed at policy load time, similar to the old
handling by the class validation logic. allow_unknown=1 is handled
when computing and mapping decisions - if the permission was not able
to be mapped (i.e. undefined, mapped to zero), then it is
automatically added to the allowed vector. If the class was not able
to be mapped (i.e. undefined, mapped to zero), then all permissions
are allowed for it if allow_unknown=1.
avc_audit leverages the new security class mapping table to lookup the
class and permission names from the kernel-private indices.
The mdp program is updated to use the new table when generating the
class definitions and allow rules for a minimal boot policy for the
kernel. It should be noted that this policy will not include any
userspace classes, nor will its policy index values for the kernel
classes correspond with the ones in refpolicy (they will instead match
the kernel-private indices).
Signed-off-by: Stephen Smalley <sds@tycho.nsa.gov>
Signed-off-by: James Morris <jmorris@namei.org>
2009-10-01 01:37:50 +08:00
|
|
|
}
|
|
|
|
|
2010-01-15 06:28:10 +08:00
|
|
|
void security_compute_av_user(u32 ssid,
|
|
|
|
u32 tsid,
|
|
|
|
u16 tclass,
|
|
|
|
struct av_decision *avd)
|
selinux: dynamic class/perm discovery
Modify SELinux to dynamically discover class and permission values
upon policy load, based on the dynamic object class/perm discovery
logic from libselinux. A mapping is created between kernel-private
class and permission indices used outside the security server and the
policy values used within the security server.
The mappings are only applied upon kernel-internal computations;
similar mappings for the private indices of userspace object managers
is handled on a per-object manager basis by the userspace AVC. The
interfaces for compute_av and transition_sid are split for kernel
vs. userspace; the userspace functions are distinguished by a _user
suffix.
The kernel-private class indices are no longer tied to the policy
values and thus do not need to skip indices for userspace classes;
thus the kernel class index values are compressed. The flask.h
definitions were regenerated by deleting the userspace classes from
refpolicy's definitions and then regenerating the headers. Going
forward, we can just maintain the flask.h, av_permissions.h, and
classmap.h definitions separately from policy as they are no longer
tied to the policy values. The next patch introduces a utility to
automate generation of flask.h and av_permissions.h from the
classmap.h definitions.
The older kernel class and permission string tables are removed and
replaced by a single security class mapping table that is walked at
policy load to generate the mapping. The old kernel class validation
logic is completely replaced by the mapping logic.
The handle unknown logic is reworked. reject_unknown=1 is handled
when the mappings are computed at policy load time, similar to the old
handling by the class validation logic. allow_unknown=1 is handled
when computing and mapping decisions - if the permission was not able
to be mapped (i.e. undefined, mapped to zero), then it is
automatically added to the allowed vector. If the class was not able
to be mapped (i.e. undefined, mapped to zero), then all permissions
are allowed for it if allow_unknown=1.
avc_audit leverages the new security class mapping table to lookup the
class and permission names from the kernel-private indices.
The mdp program is updated to use the new table when generating the
class definitions and allow rules for a minimal boot policy for the
kernel. It should be noted that this policy will not include any
userspace classes, nor will its policy index values for the kernel
classes correspond with the ones in refpolicy (they will instead match
the kernel-private indices).
Signed-off-by: Stephen Smalley <sds@tycho.nsa.gov>
Signed-off-by: James Morris <jmorris@namei.org>
2009-10-01 01:37:50 +08:00
|
|
|
{
|
2010-01-15 06:28:10 +08:00
|
|
|
struct context *scontext = NULL, *tcontext = NULL;
|
2005-04-17 06:20:36 +08:00
|
|
|
|
2010-01-15 06:28:10 +08:00
|
|
|
read_lock(&policy_rwlock);
|
|
|
|
avd_init(avd);
|
|
|
|
if (!ss_initialized)
|
|
|
|
goto allow;
|
|
|
|
|
|
|
|
scontext = sidtab_search(&sidtab, ssid);
|
|
|
|
if (!scontext) {
|
|
|
|
printk(KERN_ERR "SELinux: %s: unrecognized SID %d\n",
|
|
|
|
__func__, ssid);
|
|
|
|
goto out;
|
2005-04-17 06:20:36 +08:00
|
|
|
}
|
|
|
|
|
2010-01-15 06:28:10 +08:00
|
|
|
/* permissive domain? */
|
|
|
|
if (ebitmap_get_bit(&policydb.permissive_map, scontext->type))
|
|
|
|
avd->flags |= AVD_FLAGS_PERMISSIVE;
|
|
|
|
|
|
|
|
tcontext = sidtab_search(&sidtab, tsid);
|
|
|
|
if (!tcontext) {
|
|
|
|
printk(KERN_ERR "SELinux: %s: unrecognized SID %d\n",
|
|
|
|
__func__, tsid);
|
|
|
|
goto out;
|
|
|
|
}
|
|
|
|
|
|
|
|
if (unlikely(!tclass)) {
|
|
|
|
if (policydb.allow_unknown)
|
|
|
|
goto allow;
|
|
|
|
goto out;
|
|
|
|
}
|
|
|
|
|
|
|
|
context_struct_compute_av(scontext, tcontext, tclass, avd);
|
|
|
|
out:
|
2008-06-06 16:40:29 +08:00
|
|
|
read_unlock(&policy_rwlock);
|
2010-01-15 06:28:10 +08:00
|
|
|
return;
|
|
|
|
allow:
|
|
|
|
avd->allowed = 0xffffffff;
|
|
|
|
goto out;
|
2005-04-17 06:20:36 +08:00
|
|
|
}
|
|
|
|
|
|
|
|
/*
|
|
|
|
* Write the security context string representation of
|
|
|
|
* the context structure `context' into a dynamically
|
|
|
|
* allocated string of the correct size. Set `*scontext'
|
|
|
|
* to point to this string and set `*scontext_len' to
|
|
|
|
* the length of the string.
|
|
|
|
*/
|
|
|
|
static int context_struct_to_string(struct context *context, char **scontext, u32 *scontext_len)
|
|
|
|
{
|
|
|
|
char *scontextp;
|
|
|
|
|
|
|
|
*scontext = NULL;
|
|
|
|
*scontext_len = 0;
|
|
|
|
|
2008-05-08 01:03:20 +08:00
|
|
|
if (context->len) {
|
|
|
|
*scontext_len = context->len;
|
|
|
|
*scontext = kstrdup(context->str, GFP_ATOMIC);
|
|
|
|
if (!(*scontext))
|
|
|
|
return -ENOMEM;
|
|
|
|
return 0;
|
|
|
|
}
|
|
|
|
|
2005-04-17 06:20:36 +08:00
|
|
|
/* Compute the size of the context. */
|
|
|
|
*scontext_len += strlen(policydb.p_user_val_to_name[context->user - 1]) + 1;
|
|
|
|
*scontext_len += strlen(policydb.p_role_val_to_name[context->role - 1]) + 1;
|
|
|
|
*scontext_len += strlen(policydb.p_type_val_to_name[context->type - 1]) + 1;
|
|
|
|
*scontext_len += mls_compute_context_len(context);
|
|
|
|
|
|
|
|
/* Allocate space for the context; caller must free this space. */
|
|
|
|
scontextp = kmalloc(*scontext_len, GFP_ATOMIC);
|
2008-04-19 05:38:33 +08:00
|
|
|
if (!scontextp)
|
2005-04-17 06:20:36 +08:00
|
|
|
return -ENOMEM;
|
|
|
|
*scontext = scontextp;
|
|
|
|
|
|
|
|
/*
|
|
|
|
* Copy the user name, role name and type name into the context.
|
|
|
|
*/
|
|
|
|
sprintf(scontextp, "%s:%s:%s",
|
|
|
|
policydb.p_user_val_to_name[context->user - 1],
|
|
|
|
policydb.p_role_val_to_name[context->role - 1],
|
|
|
|
policydb.p_type_val_to_name[context->type - 1]);
|
|
|
|
scontextp += strlen(policydb.p_user_val_to_name[context->user - 1]) +
|
2008-04-19 05:38:33 +08:00
|
|
|
1 + strlen(policydb.p_role_val_to_name[context->role - 1]) +
|
|
|
|
1 + strlen(policydb.p_type_val_to_name[context->type - 1]);
|
2005-04-17 06:20:36 +08:00
|
|
|
|
|
|
|
mls_sid_to_context(context, &scontextp);
|
|
|
|
|
|
|
|
*scontextp = 0;
|
|
|
|
|
|
|
|
return 0;
|
|
|
|
}
|
|
|
|
|
|
|
|
#include "initial_sid_to_string.h"
|
|
|
|
|
2007-04-04 22:11:29 +08:00
|
|
|
const char *security_get_initial_sid_context(u32 sid)
|
|
|
|
{
|
|
|
|
if (unlikely(sid > SECINITSID_NUM))
|
|
|
|
return NULL;
|
|
|
|
return initial_sid_to_string[sid];
|
|
|
|
}
|
|
|
|
|
2008-05-08 01:03:20 +08:00
|
|
|
static int security_sid_to_context_core(u32 sid, char **scontext,
|
|
|
|
u32 *scontext_len, int force)
|
2005-04-17 06:20:36 +08:00
|
|
|
{
|
|
|
|
struct context *context;
|
|
|
|
int rc = 0;
|
|
|
|
|
2007-02-27 01:02:34 +08:00
|
|
|
*scontext = NULL;
|
|
|
|
*scontext_len = 0;
|
|
|
|
|
2005-04-17 06:20:36 +08:00
|
|
|
if (!ss_initialized) {
|
|
|
|
if (sid <= SECINITSID_NUM) {
|
|
|
|
char *scontextp;
|
|
|
|
|
|
|
|
*scontext_len = strlen(initial_sid_to_string[sid]) + 1;
|
2008-04-19 05:38:33 +08:00
|
|
|
scontextp = kmalloc(*scontext_len, GFP_ATOMIC);
|
2006-05-16 00:43:48 +08:00
|
|
|
if (!scontextp) {
|
|
|
|
rc = -ENOMEM;
|
|
|
|
goto out;
|
|
|
|
}
|
2005-04-17 06:20:36 +08:00
|
|
|
strcpy(scontextp, initial_sid_to_string[sid]);
|
|
|
|
*scontext = scontextp;
|
|
|
|
goto out;
|
|
|
|
}
|
2008-04-17 23:52:44 +08:00
|
|
|
printk(KERN_ERR "SELinux: %s: called before initial "
|
|
|
|
"load_policy on unknown SID %d\n", __func__, sid);
|
2005-04-17 06:20:36 +08:00
|
|
|
rc = -EINVAL;
|
|
|
|
goto out;
|
|
|
|
}
|
2008-06-06 16:40:29 +08:00
|
|
|
read_lock(&policy_rwlock);
|
2008-05-08 01:03:20 +08:00
|
|
|
if (force)
|
|
|
|
context = sidtab_search_force(&sidtab, sid);
|
|
|
|
else
|
|
|
|
context = sidtab_search(&sidtab, sid);
|
2005-04-17 06:20:36 +08:00
|
|
|
if (!context) {
|
2008-04-17 23:52:44 +08:00
|
|
|
printk(KERN_ERR "SELinux: %s: unrecognized SID %d\n",
|
|
|
|
__func__, sid);
|
2005-04-17 06:20:36 +08:00
|
|
|
rc = -EINVAL;
|
|
|
|
goto out_unlock;
|
|
|
|
}
|
|
|
|
rc = context_struct_to_string(context, scontext, scontext_len);
|
|
|
|
out_unlock:
|
2008-06-06 16:40:29 +08:00
|
|
|
read_unlock(&policy_rwlock);
|
2005-04-17 06:20:36 +08:00
|
|
|
out:
|
|
|
|
return rc;
|
|
|
|
|
|
|
|
}
|
|
|
|
|
2008-05-08 01:03:20 +08:00
|
|
|
/**
|
|
|
|
* security_sid_to_context - Obtain a context for a given SID.
|
|
|
|
* @sid: security identifier, SID
|
|
|
|
* @scontext: security context
|
|
|
|
* @scontext_len: length in bytes
|
|
|
|
*
|
|
|
|
* Write the string representation of the context associated with @sid
|
|
|
|
* into a dynamically allocated string of the correct size. Set @scontext
|
|
|
|
* to point to this string and set @scontext_len to the length of the string.
|
|
|
|
*/
|
|
|
|
int security_sid_to_context(u32 sid, char **scontext, u32 *scontext_len)
|
2005-04-17 06:20:36 +08:00
|
|
|
{
|
2008-05-08 01:03:20 +08:00
|
|
|
return security_sid_to_context_core(sid, scontext, scontext_len, 0);
|
|
|
|
}
|
|
|
|
|
|
|
|
int security_sid_to_context_force(u32 sid, char **scontext, u32 *scontext_len)
|
|
|
|
{
|
|
|
|
return security_sid_to_context_core(sid, scontext, scontext_len, 1);
|
|
|
|
}
|
|
|
|
|
2008-05-14 22:33:55 +08:00
|
|
|
/*
|
|
|
|
* Caveat: Mutates scontext.
|
|
|
|
*/
|
2008-05-08 01:03:20 +08:00
|
|
|
static int string_to_context_struct(struct policydb *pol,
|
|
|
|
struct sidtab *sidtabp,
|
2008-05-14 22:33:55 +08:00
|
|
|
char *scontext,
|
2008-05-08 01:03:20 +08:00
|
|
|
u32 scontext_len,
|
|
|
|
struct context *ctx,
|
2008-05-14 22:33:55 +08:00
|
|
|
u32 def_sid)
|
2008-05-08 01:03:20 +08:00
|
|
|
{
|
2005-04-17 06:20:36 +08:00
|
|
|
struct role_datum *role;
|
|
|
|
struct type_datum *typdatum;
|
|
|
|
struct user_datum *usrdatum;
|
|
|
|
char *scontextp, *p, oldc;
|
|
|
|
int rc = 0;
|
|
|
|
|
2008-05-08 01:03:20 +08:00
|
|
|
context_init(ctx);
|
2005-04-17 06:20:36 +08:00
|
|
|
|
|
|
|
/* Parse the security context. */
|
|
|
|
|
|
|
|
rc = -EINVAL;
|
2008-05-14 22:33:55 +08:00
|
|
|
scontextp = (char *) scontext;
|
2005-04-17 06:20:36 +08:00
|
|
|
|
|
|
|
/* Extract the user. */
|
|
|
|
p = scontextp;
|
|
|
|
while (*p && *p != ':')
|
|
|
|
p++;
|
|
|
|
|
|
|
|
if (*p == 0)
|
2008-05-08 01:03:20 +08:00
|
|
|
goto out;
|
2005-04-17 06:20:36 +08:00
|
|
|
|
|
|
|
*p++ = 0;
|
|
|
|
|
2008-05-08 01:03:20 +08:00
|
|
|
usrdatum = hashtab_search(pol->p_users.table, scontextp);
|
2005-04-17 06:20:36 +08:00
|
|
|
if (!usrdatum)
|
2008-05-08 01:03:20 +08:00
|
|
|
goto out;
|
2005-04-17 06:20:36 +08:00
|
|
|
|
2008-05-08 01:03:20 +08:00
|
|
|
ctx->user = usrdatum->value;
|
2005-04-17 06:20:36 +08:00
|
|
|
|
|
|
|
/* Extract role. */
|
|
|
|
scontextp = p;
|
|
|
|
while (*p && *p != ':')
|
|
|
|
p++;
|
|
|
|
|
|
|
|
if (*p == 0)
|
2008-05-08 01:03:20 +08:00
|
|
|
goto out;
|
2005-04-17 06:20:36 +08:00
|
|
|
|
|
|
|
*p++ = 0;
|
|
|
|
|
2008-05-08 01:03:20 +08:00
|
|
|
role = hashtab_search(pol->p_roles.table, scontextp);
|
2005-04-17 06:20:36 +08:00
|
|
|
if (!role)
|
2008-05-08 01:03:20 +08:00
|
|
|
goto out;
|
|
|
|
ctx->role = role->value;
|
2005-04-17 06:20:36 +08:00
|
|
|
|
|
|
|
/* Extract type. */
|
|
|
|
scontextp = p;
|
|
|
|
while (*p && *p != ':')
|
|
|
|
p++;
|
|
|
|
oldc = *p;
|
|
|
|
*p++ = 0;
|
|
|
|
|
2008-05-08 01:03:20 +08:00
|
|
|
typdatum = hashtab_search(pol->p_types.table, scontextp);
|
2008-08-28 15:35:57 +08:00
|
|
|
if (!typdatum || typdatum->attribute)
|
2008-05-08 01:03:20 +08:00
|
|
|
goto out;
|
2005-04-17 06:20:36 +08:00
|
|
|
|
2008-05-08 01:03:20 +08:00
|
|
|
ctx->type = typdatum->value;
|
2005-04-17 06:20:36 +08:00
|
|
|
|
2008-05-08 01:03:20 +08:00
|
|
|
rc = mls_context_to_sid(pol, oldc, &p, ctx, sidtabp, def_sid);
|
2005-04-17 06:20:36 +08:00
|
|
|
if (rc)
|
2008-05-08 01:03:20 +08:00
|
|
|
goto out;
|
2005-04-17 06:20:36 +08:00
|
|
|
|
2008-05-14 22:33:55 +08:00
|
|
|
if ((p - scontext) < scontext_len) {
|
2005-04-17 06:20:36 +08:00
|
|
|
rc = -EINVAL;
|
2008-05-08 01:03:20 +08:00
|
|
|
goto out;
|
2005-04-17 06:20:36 +08:00
|
|
|
}
|
|
|
|
|
|
|
|
/* Check the validity of the new context. */
|
2008-05-08 01:03:20 +08:00
|
|
|
if (!policydb_context_isvalid(pol, ctx)) {
|
2005-04-17 06:20:36 +08:00
|
|
|
rc = -EINVAL;
|
2008-05-08 01:03:20 +08:00
|
|
|
goto out;
|
2005-04-17 06:20:36 +08:00
|
|
|
}
|
2008-05-08 01:03:20 +08:00
|
|
|
rc = 0;
|
|
|
|
out:
|
2008-09-03 23:49:47 +08:00
|
|
|
if (rc)
|
|
|
|
context_destroy(ctx);
|
2008-05-08 01:03:20 +08:00
|
|
|
return rc;
|
|
|
|
}
|
|
|
|
|
|
|
|
static int security_context_to_sid_core(const char *scontext, u32 scontext_len,
|
|
|
|
u32 *sid, u32 def_sid, gfp_t gfp_flags,
|
|
|
|
int force)
|
|
|
|
{
|
2008-05-14 22:33:55 +08:00
|
|
|
char *scontext2, *str = NULL;
|
2008-05-08 01:03:20 +08:00
|
|
|
struct context context;
|
|
|
|
int rc = 0;
|
|
|
|
|
|
|
|
if (!ss_initialized) {
|
|
|
|
int i;
|
|
|
|
|
|
|
|
for (i = 1; i < SECINITSID_NUM; i++) {
|
|
|
|
if (!strcmp(initial_sid_to_string[i], scontext)) {
|
|
|
|
*sid = i;
|
2008-05-14 22:33:55 +08:00
|
|
|
return 0;
|
2008-05-08 01:03:20 +08:00
|
|
|
}
|
|
|
|
}
|
|
|
|
*sid = SECINITSID_KERNEL;
|
2008-05-14 22:33:55 +08:00
|
|
|
return 0;
|
2008-05-08 01:03:20 +08:00
|
|
|
}
|
|
|
|
*sid = SECSID_NULL;
|
|
|
|
|
2008-05-14 22:33:55 +08:00
|
|
|
/* Copy the string so that we can modify the copy as we parse it. */
|
2010-04-09 19:30:29 +08:00
|
|
|
scontext2 = kmalloc(scontext_len + 1, gfp_flags);
|
2008-05-14 22:33:55 +08:00
|
|
|
if (!scontext2)
|
|
|
|
return -ENOMEM;
|
|
|
|
memcpy(scontext2, scontext, scontext_len);
|
|
|
|
scontext2[scontext_len] = 0;
|
|
|
|
|
|
|
|
if (force) {
|
|
|
|
/* Save another copy for storing in uninterpreted form */
|
|
|
|
str = kstrdup(scontext2, gfp_flags);
|
|
|
|
if (!str) {
|
|
|
|
kfree(scontext2);
|
|
|
|
return -ENOMEM;
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2008-06-06 16:40:29 +08:00
|
|
|
read_lock(&policy_rwlock);
|
2008-05-08 01:03:20 +08:00
|
|
|
rc = string_to_context_struct(&policydb, &sidtab,
|
2008-05-14 22:33:55 +08:00
|
|
|
scontext2, scontext_len,
|
|
|
|
&context, def_sid);
|
2008-05-08 01:03:20 +08:00
|
|
|
if (rc == -EINVAL && force) {
|
2008-05-14 22:33:55 +08:00
|
|
|
context.str = str;
|
2008-05-08 01:03:20 +08:00
|
|
|
context.len = scontext_len;
|
2008-05-14 22:33:55 +08:00
|
|
|
str = NULL;
|
2008-05-08 01:03:20 +08:00
|
|
|
} else if (rc)
|
|
|
|
goto out;
|
|
|
|
rc = sidtab_context_to_sid(&sidtab, &context, sid);
|
2008-09-03 23:49:47 +08:00
|
|
|
context_destroy(&context);
|
2005-04-17 06:20:36 +08:00
|
|
|
out:
|
2008-06-06 16:40:29 +08:00
|
|
|
read_unlock(&policy_rwlock);
|
2008-05-14 22:33:55 +08:00
|
|
|
kfree(scontext2);
|
|
|
|
kfree(str);
|
2005-04-17 06:20:36 +08:00
|
|
|
return rc;
|
|
|
|
}
|
|
|
|
|
2005-07-28 16:07:37 +08:00
|
|
|
/**
|
|
|
|
* security_context_to_sid - Obtain a SID for a given security context.
|
|
|
|
* @scontext: security context
|
|
|
|
* @scontext_len: length in bytes
|
|
|
|
* @sid: security identifier, SID
|
|
|
|
*
|
|
|
|
* Obtains a SID associated with the security context that
|
|
|
|
* has the string representation specified by @scontext.
|
|
|
|
* Returns -%EINVAL if the context is invalid, -%ENOMEM if insufficient
|
|
|
|
* memory is available, or 0 on success.
|
|
|
|
*/
|
2008-04-29 15:59:41 +08:00
|
|
|
int security_context_to_sid(const char *scontext, u32 scontext_len, u32 *sid)
|
2005-07-28 16:07:37 +08:00
|
|
|
{
|
|
|
|
return security_context_to_sid_core(scontext, scontext_len,
|
2008-05-08 01:03:20 +08:00
|
|
|
sid, SECSID_NULL, GFP_KERNEL, 0);
|
2005-07-28 16:07:37 +08:00
|
|
|
}
|
|
|
|
|
|
|
|
/**
|
|
|
|
* security_context_to_sid_default - Obtain a SID for a given security context,
|
|
|
|
* falling back to specified default if needed.
|
|
|
|
*
|
|
|
|
* @scontext: security context
|
|
|
|
* @scontext_len: length in bytes
|
|
|
|
* @sid: security identifier, SID
|
2007-07-31 15:39:19 +08:00
|
|
|
* @def_sid: default SID to assign on error
|
2005-07-28 16:07:37 +08:00
|
|
|
*
|
|
|
|
* Obtains a SID associated with the security context that
|
|
|
|
* has the string representation specified by @scontext.
|
|
|
|
* The default SID is passed to the MLS layer to be used to allow
|
|
|
|
* kernel labeling of the MLS field if the MLS field is not present
|
|
|
|
* (for upgrading to MLS without full relabel).
|
2008-05-08 01:03:20 +08:00
|
|
|
* Implicitly forces adding of the context even if it cannot be mapped yet.
|
2005-07-28 16:07:37 +08:00
|
|
|
* Returns -%EINVAL if the context is invalid, -%ENOMEM if insufficient
|
|
|
|
* memory is available, or 0 on success.
|
|
|
|
*/
|
2008-04-30 03:52:51 +08:00
|
|
|
int security_context_to_sid_default(const char *scontext, u32 scontext_len,
|
|
|
|
u32 *sid, u32 def_sid, gfp_t gfp_flags)
|
2005-07-28 16:07:37 +08:00
|
|
|
{
|
|
|
|
return security_context_to_sid_core(scontext, scontext_len,
|
2008-05-08 01:03:20 +08:00
|
|
|
sid, def_sid, gfp_flags, 1);
|
|
|
|
}
|
|
|
|
|
|
|
|
int security_context_to_sid_force(const char *scontext, u32 scontext_len,
|
|
|
|
u32 *sid)
|
|
|
|
{
|
|
|
|
return security_context_to_sid_core(scontext, scontext_len,
|
|
|
|
sid, SECSID_NULL, GFP_KERNEL, 1);
|
2005-07-28 16:07:37 +08:00
|
|
|
}
|
|
|
|
|
2005-04-17 06:20:36 +08:00
|
|
|
static int compute_sid_handle_invalid_context(
|
|
|
|
struct context *scontext,
|
|
|
|
struct context *tcontext,
|
|
|
|
u16 tclass,
|
|
|
|
struct context *newcontext)
|
|
|
|
{
|
|
|
|
char *s = NULL, *t = NULL, *n = NULL;
|
|
|
|
u32 slen, tlen, nlen;
|
|
|
|
|
|
|
|
if (context_struct_to_string(scontext, &s, &slen) < 0)
|
|
|
|
goto out;
|
|
|
|
if (context_struct_to_string(tcontext, &t, &tlen) < 0)
|
|
|
|
goto out;
|
|
|
|
if (context_struct_to_string(newcontext, &n, &nlen) < 0)
|
|
|
|
goto out;
|
2005-06-22 22:04:33 +08:00
|
|
|
audit_log(current->audit_context, GFP_ATOMIC, AUDIT_SELINUX_ERR,
|
2005-04-17 06:20:36 +08:00
|
|
|
"security_compute_sid: invalid context %s"
|
|
|
|
" for scontext=%s"
|
|
|
|
" tcontext=%s"
|
|
|
|
" tclass=%s",
|
|
|
|
n, s, t, policydb.p_class_val_to_name[tclass-1]);
|
|
|
|
out:
|
|
|
|
kfree(s);
|
|
|
|
kfree(t);
|
|
|
|
kfree(n);
|
|
|
|
if (!selinux_enforcing)
|
|
|
|
return 0;
|
|
|
|
return -EACCES;
|
|
|
|
}
|
|
|
|
|
|
|
|
static int security_compute_sid(u32 ssid,
|
|
|
|
u32 tsid,
|
selinux: dynamic class/perm discovery
Modify SELinux to dynamically discover class and permission values
upon policy load, based on the dynamic object class/perm discovery
logic from libselinux. A mapping is created between kernel-private
class and permission indices used outside the security server and the
policy values used within the security server.
The mappings are only applied upon kernel-internal computations;
similar mappings for the private indices of userspace object managers
is handled on a per-object manager basis by the userspace AVC. The
interfaces for compute_av and transition_sid are split for kernel
vs. userspace; the userspace functions are distinguished by a _user
suffix.
The kernel-private class indices are no longer tied to the policy
values and thus do not need to skip indices for userspace classes;
thus the kernel class index values are compressed. The flask.h
definitions were regenerated by deleting the userspace classes from
refpolicy's definitions and then regenerating the headers. Going
forward, we can just maintain the flask.h, av_permissions.h, and
classmap.h definitions separately from policy as they are no longer
tied to the policy values. The next patch introduces a utility to
automate generation of flask.h and av_permissions.h from the
classmap.h definitions.
The older kernel class and permission string tables are removed and
replaced by a single security class mapping table that is walked at
policy load to generate the mapping. The old kernel class validation
logic is completely replaced by the mapping logic.
The handle unknown logic is reworked. reject_unknown=1 is handled
when the mappings are computed at policy load time, similar to the old
handling by the class validation logic. allow_unknown=1 is handled
when computing and mapping decisions - if the permission was not able
to be mapped (i.e. undefined, mapped to zero), then it is
automatically added to the allowed vector. If the class was not able
to be mapped (i.e. undefined, mapped to zero), then all permissions
are allowed for it if allow_unknown=1.
avc_audit leverages the new security class mapping table to lookup the
class and permission names from the kernel-private indices.
The mdp program is updated to use the new table when generating the
class definitions and allow rules for a minimal boot policy for the
kernel. It should be noted that this policy will not include any
userspace classes, nor will its policy index values for the kernel
classes correspond with the ones in refpolicy (they will instead match
the kernel-private indices).
Signed-off-by: Stephen Smalley <sds@tycho.nsa.gov>
Signed-off-by: James Morris <jmorris@namei.org>
2009-10-01 01:37:50 +08:00
|
|
|
u16 orig_tclass,
|
2005-04-17 06:20:36 +08:00
|
|
|
u32 specified,
|
selinux: dynamic class/perm discovery
Modify SELinux to dynamically discover class and permission values
upon policy load, based on the dynamic object class/perm discovery
logic from libselinux. A mapping is created between kernel-private
class and permission indices used outside the security server and the
policy values used within the security server.
The mappings are only applied upon kernel-internal computations;
similar mappings for the private indices of userspace object managers
is handled on a per-object manager basis by the userspace AVC. The
interfaces for compute_av and transition_sid are split for kernel
vs. userspace; the userspace functions are distinguished by a _user
suffix.
The kernel-private class indices are no longer tied to the policy
values and thus do not need to skip indices for userspace classes;
thus the kernel class index values are compressed. The flask.h
definitions were regenerated by deleting the userspace classes from
refpolicy's definitions and then regenerating the headers. Going
forward, we can just maintain the flask.h, av_permissions.h, and
classmap.h definitions separately from policy as they are no longer
tied to the policy values. The next patch introduces a utility to
automate generation of flask.h and av_permissions.h from the
classmap.h definitions.
The older kernel class and permission string tables are removed and
replaced by a single security class mapping table that is walked at
policy load to generate the mapping. The old kernel class validation
logic is completely replaced by the mapping logic.
The handle unknown logic is reworked. reject_unknown=1 is handled
when the mappings are computed at policy load time, similar to the old
handling by the class validation logic. allow_unknown=1 is handled
when computing and mapping decisions - if the permission was not able
to be mapped (i.e. undefined, mapped to zero), then it is
automatically added to the allowed vector. If the class was not able
to be mapped (i.e. undefined, mapped to zero), then all permissions
are allowed for it if allow_unknown=1.
avc_audit leverages the new security class mapping table to lookup the
class and permission names from the kernel-private indices.
The mdp program is updated to use the new table when generating the
class definitions and allow rules for a minimal boot policy for the
kernel. It should be noted that this policy will not include any
userspace classes, nor will its policy index values for the kernel
classes correspond with the ones in refpolicy (they will instead match
the kernel-private indices).
Signed-off-by: Stephen Smalley <sds@tycho.nsa.gov>
Signed-off-by: James Morris <jmorris@namei.org>
2009-10-01 01:37:50 +08:00
|
|
|
u32 *out_sid,
|
|
|
|
bool kern)
|
2005-04-17 06:20:36 +08:00
|
|
|
{
|
|
|
|
struct context *scontext = NULL, *tcontext = NULL, newcontext;
|
|
|
|
struct role_trans *roletr = NULL;
|
|
|
|
struct avtab_key avkey;
|
|
|
|
struct avtab_datum *avdatum;
|
|
|
|
struct avtab_node *node;
|
selinux: dynamic class/perm discovery
Modify SELinux to dynamically discover class and permission values
upon policy load, based on the dynamic object class/perm discovery
logic from libselinux. A mapping is created between kernel-private
class and permission indices used outside the security server and the
policy values used within the security server.
The mappings are only applied upon kernel-internal computations;
similar mappings for the private indices of userspace object managers
is handled on a per-object manager basis by the userspace AVC. The
interfaces for compute_av and transition_sid are split for kernel
vs. userspace; the userspace functions are distinguished by a _user
suffix.
The kernel-private class indices are no longer tied to the policy
values and thus do not need to skip indices for userspace classes;
thus the kernel class index values are compressed. The flask.h
definitions were regenerated by deleting the userspace classes from
refpolicy's definitions and then regenerating the headers. Going
forward, we can just maintain the flask.h, av_permissions.h, and
classmap.h definitions separately from policy as they are no longer
tied to the policy values. The next patch introduces a utility to
automate generation of flask.h and av_permissions.h from the
classmap.h definitions.
The older kernel class and permission string tables are removed and
replaced by a single security class mapping table that is walked at
policy load to generate the mapping. The old kernel class validation
logic is completely replaced by the mapping logic.
The handle unknown logic is reworked. reject_unknown=1 is handled
when the mappings are computed at policy load time, similar to the old
handling by the class validation logic. allow_unknown=1 is handled
when computing and mapping decisions - if the permission was not able
to be mapped (i.e. undefined, mapped to zero), then it is
automatically added to the allowed vector. If the class was not able
to be mapped (i.e. undefined, mapped to zero), then all permissions
are allowed for it if allow_unknown=1.
avc_audit leverages the new security class mapping table to lookup the
class and permission names from the kernel-private indices.
The mdp program is updated to use the new table when generating the
class definitions and allow rules for a minimal boot policy for the
kernel. It should be noted that this policy will not include any
userspace classes, nor will its policy index values for the kernel
classes correspond with the ones in refpolicy (they will instead match
the kernel-private indices).
Signed-off-by: Stephen Smalley <sds@tycho.nsa.gov>
Signed-off-by: James Morris <jmorris@namei.org>
2009-10-01 01:37:50 +08:00
|
|
|
u16 tclass;
|
2005-04-17 06:20:36 +08:00
|
|
|
int rc = 0;
|
|
|
|
|
|
|
|
if (!ss_initialized) {
|
selinux: dynamic class/perm discovery
Modify SELinux to dynamically discover class and permission values
upon policy load, based on the dynamic object class/perm discovery
logic from libselinux. A mapping is created between kernel-private
class and permission indices used outside the security server and the
policy values used within the security server.
The mappings are only applied upon kernel-internal computations;
similar mappings for the private indices of userspace object managers
is handled on a per-object manager basis by the userspace AVC. The
interfaces for compute_av and transition_sid are split for kernel
vs. userspace; the userspace functions are distinguished by a _user
suffix.
The kernel-private class indices are no longer tied to the policy
values and thus do not need to skip indices for userspace classes;
thus the kernel class index values are compressed. The flask.h
definitions were regenerated by deleting the userspace classes from
refpolicy's definitions and then regenerating the headers. Going
forward, we can just maintain the flask.h, av_permissions.h, and
classmap.h definitions separately from policy as they are no longer
tied to the policy values. The next patch introduces a utility to
automate generation of flask.h and av_permissions.h from the
classmap.h definitions.
The older kernel class and permission string tables are removed and
replaced by a single security class mapping table that is walked at
policy load to generate the mapping. The old kernel class validation
logic is completely replaced by the mapping logic.
The handle unknown logic is reworked. reject_unknown=1 is handled
when the mappings are computed at policy load time, similar to the old
handling by the class validation logic. allow_unknown=1 is handled
when computing and mapping decisions - if the permission was not able
to be mapped (i.e. undefined, mapped to zero), then it is
automatically added to the allowed vector. If the class was not able
to be mapped (i.e. undefined, mapped to zero), then all permissions
are allowed for it if allow_unknown=1.
avc_audit leverages the new security class mapping table to lookup the
class and permission names from the kernel-private indices.
The mdp program is updated to use the new table when generating the
class definitions and allow rules for a minimal boot policy for the
kernel. It should be noted that this policy will not include any
userspace classes, nor will its policy index values for the kernel
classes correspond with the ones in refpolicy (they will instead match
the kernel-private indices).
Signed-off-by: Stephen Smalley <sds@tycho.nsa.gov>
Signed-off-by: James Morris <jmorris@namei.org>
2009-10-01 01:37:50 +08:00
|
|
|
switch (orig_tclass) {
|
|
|
|
case SECCLASS_PROCESS: /* kernel value */
|
2005-04-17 06:20:36 +08:00
|
|
|
*out_sid = ssid;
|
|
|
|
break;
|
|
|
|
default:
|
|
|
|
*out_sid = tsid;
|
|
|
|
break;
|
|
|
|
}
|
|
|
|
goto out;
|
|
|
|
}
|
|
|
|
|
2006-07-30 18:03:18 +08:00
|
|
|
context_init(&newcontext);
|
|
|
|
|
2008-06-06 16:40:29 +08:00
|
|
|
read_lock(&policy_rwlock);
|
2005-04-17 06:20:36 +08:00
|
|
|
|
selinux: dynamic class/perm discovery
Modify SELinux to dynamically discover class and permission values
upon policy load, based on the dynamic object class/perm discovery
logic from libselinux. A mapping is created between kernel-private
class and permission indices used outside the security server and the
policy values used within the security server.
The mappings are only applied upon kernel-internal computations;
similar mappings for the private indices of userspace object managers
is handled on a per-object manager basis by the userspace AVC. The
interfaces for compute_av and transition_sid are split for kernel
vs. userspace; the userspace functions are distinguished by a _user
suffix.
The kernel-private class indices are no longer tied to the policy
values and thus do not need to skip indices for userspace classes;
thus the kernel class index values are compressed. The flask.h
definitions were regenerated by deleting the userspace classes from
refpolicy's definitions and then regenerating the headers. Going
forward, we can just maintain the flask.h, av_permissions.h, and
classmap.h definitions separately from policy as they are no longer
tied to the policy values. The next patch introduces a utility to
automate generation of flask.h and av_permissions.h from the
classmap.h definitions.
The older kernel class and permission string tables are removed and
replaced by a single security class mapping table that is walked at
policy load to generate the mapping. The old kernel class validation
logic is completely replaced by the mapping logic.
The handle unknown logic is reworked. reject_unknown=1 is handled
when the mappings are computed at policy load time, similar to the old
handling by the class validation logic. allow_unknown=1 is handled
when computing and mapping decisions - if the permission was not able
to be mapped (i.e. undefined, mapped to zero), then it is
automatically added to the allowed vector. If the class was not able
to be mapped (i.e. undefined, mapped to zero), then all permissions
are allowed for it if allow_unknown=1.
avc_audit leverages the new security class mapping table to lookup the
class and permission names from the kernel-private indices.
The mdp program is updated to use the new table when generating the
class definitions and allow rules for a minimal boot policy for the
kernel. It should be noted that this policy will not include any
userspace classes, nor will its policy index values for the kernel
classes correspond with the ones in refpolicy (they will instead match
the kernel-private indices).
Signed-off-by: Stephen Smalley <sds@tycho.nsa.gov>
Signed-off-by: James Morris <jmorris@namei.org>
2009-10-01 01:37:50 +08:00
|
|
|
if (kern)
|
|
|
|
tclass = unmap_class(orig_tclass);
|
|
|
|
else
|
|
|
|
tclass = orig_tclass;
|
|
|
|
|
2005-04-17 06:20:36 +08:00
|
|
|
scontext = sidtab_search(&sidtab, ssid);
|
|
|
|
if (!scontext) {
|
2008-04-17 23:52:44 +08:00
|
|
|
printk(KERN_ERR "SELinux: %s: unrecognized SID %d\n",
|
|
|
|
__func__, ssid);
|
2005-04-17 06:20:36 +08:00
|
|
|
rc = -EINVAL;
|
|
|
|
goto out_unlock;
|
|
|
|
}
|
|
|
|
tcontext = sidtab_search(&sidtab, tsid);
|
|
|
|
if (!tcontext) {
|
2008-04-17 23:52:44 +08:00
|
|
|
printk(KERN_ERR "SELinux: %s: unrecognized SID %d\n",
|
|
|
|
__func__, tsid);
|
2005-04-17 06:20:36 +08:00
|
|
|
rc = -EINVAL;
|
|
|
|
goto out_unlock;
|
|
|
|
}
|
|
|
|
|
|
|
|
/* Set the user identity. */
|
|
|
|
switch (specified) {
|
|
|
|
case AVTAB_TRANSITION:
|
|
|
|
case AVTAB_CHANGE:
|
|
|
|
/* Use the process user identity. */
|
|
|
|
newcontext.user = scontext->user;
|
|
|
|
break;
|
|
|
|
case AVTAB_MEMBER:
|
|
|
|
/* Use the related object owner. */
|
|
|
|
newcontext.user = tcontext->user;
|
|
|
|
break;
|
|
|
|
}
|
|
|
|
|
|
|
|
/* Set the role and type to default values. */
|
selinux: dynamic class/perm discovery
Modify SELinux to dynamically discover class and permission values
upon policy load, based on the dynamic object class/perm discovery
logic from libselinux. A mapping is created between kernel-private
class and permission indices used outside the security server and the
policy values used within the security server.
The mappings are only applied upon kernel-internal computations;
similar mappings for the private indices of userspace object managers
is handled on a per-object manager basis by the userspace AVC. The
interfaces for compute_av and transition_sid are split for kernel
vs. userspace; the userspace functions are distinguished by a _user
suffix.
The kernel-private class indices are no longer tied to the policy
values and thus do not need to skip indices for userspace classes;
thus the kernel class index values are compressed. The flask.h
definitions were regenerated by deleting the userspace classes from
refpolicy's definitions and then regenerating the headers. Going
forward, we can just maintain the flask.h, av_permissions.h, and
classmap.h definitions separately from policy as they are no longer
tied to the policy values. The next patch introduces a utility to
automate generation of flask.h and av_permissions.h from the
classmap.h definitions.
The older kernel class and permission string tables are removed and
replaced by a single security class mapping table that is walked at
policy load to generate the mapping. The old kernel class validation
logic is completely replaced by the mapping logic.
The handle unknown logic is reworked. reject_unknown=1 is handled
when the mappings are computed at policy load time, similar to the old
handling by the class validation logic. allow_unknown=1 is handled
when computing and mapping decisions - if the permission was not able
to be mapped (i.e. undefined, mapped to zero), then it is
automatically added to the allowed vector. If the class was not able
to be mapped (i.e. undefined, mapped to zero), then all permissions
are allowed for it if allow_unknown=1.
avc_audit leverages the new security class mapping table to lookup the
class and permission names from the kernel-private indices.
The mdp program is updated to use the new table when generating the
class definitions and allow rules for a minimal boot policy for the
kernel. It should be noted that this policy will not include any
userspace classes, nor will its policy index values for the kernel
classes correspond with the ones in refpolicy (they will instead match
the kernel-private indices).
Signed-off-by: Stephen Smalley <sds@tycho.nsa.gov>
Signed-off-by: James Morris <jmorris@namei.org>
2009-10-01 01:37:50 +08:00
|
|
|
if (tclass == policydb.process_class) {
|
2005-04-17 06:20:36 +08:00
|
|
|
/* Use the current role and type of process. */
|
|
|
|
newcontext.role = scontext->role;
|
|
|
|
newcontext.type = scontext->type;
|
selinux: dynamic class/perm discovery
Modify SELinux to dynamically discover class and permission values
upon policy load, based on the dynamic object class/perm discovery
logic from libselinux. A mapping is created between kernel-private
class and permission indices used outside the security server and the
policy values used within the security server.
The mappings are only applied upon kernel-internal computations;
similar mappings for the private indices of userspace object managers
is handled on a per-object manager basis by the userspace AVC. The
interfaces for compute_av and transition_sid are split for kernel
vs. userspace; the userspace functions are distinguished by a _user
suffix.
The kernel-private class indices are no longer tied to the policy
values and thus do not need to skip indices for userspace classes;
thus the kernel class index values are compressed. The flask.h
definitions were regenerated by deleting the userspace classes from
refpolicy's definitions and then regenerating the headers. Going
forward, we can just maintain the flask.h, av_permissions.h, and
classmap.h definitions separately from policy as they are no longer
tied to the policy values. The next patch introduces a utility to
automate generation of flask.h and av_permissions.h from the
classmap.h definitions.
The older kernel class and permission string tables are removed and
replaced by a single security class mapping table that is walked at
policy load to generate the mapping. The old kernel class validation
logic is completely replaced by the mapping logic.
The handle unknown logic is reworked. reject_unknown=1 is handled
when the mappings are computed at policy load time, similar to the old
handling by the class validation logic. allow_unknown=1 is handled
when computing and mapping decisions - if the permission was not able
to be mapped (i.e. undefined, mapped to zero), then it is
automatically added to the allowed vector. If the class was not able
to be mapped (i.e. undefined, mapped to zero), then all permissions
are allowed for it if allow_unknown=1.
avc_audit leverages the new security class mapping table to lookup the
class and permission names from the kernel-private indices.
The mdp program is updated to use the new table when generating the
class definitions and allow rules for a minimal boot policy for the
kernel. It should be noted that this policy will not include any
userspace classes, nor will its policy index values for the kernel
classes correspond with the ones in refpolicy (they will instead match
the kernel-private indices).
Signed-off-by: Stephen Smalley <sds@tycho.nsa.gov>
Signed-off-by: James Morris <jmorris@namei.org>
2009-10-01 01:37:50 +08:00
|
|
|
} else {
|
2005-04-17 06:20:36 +08:00
|
|
|
/* Use the well-defined object role. */
|
|
|
|
newcontext.role = OBJECT_R_VAL;
|
|
|
|
/* Use the type of the related object. */
|
|
|
|
newcontext.type = tcontext->type;
|
|
|
|
}
|
|
|
|
|
|
|
|
/* Look for a type transition/member/change rule. */
|
|
|
|
avkey.source_type = scontext->type;
|
|
|
|
avkey.target_type = tcontext->type;
|
|
|
|
avkey.target_class = tclass;
|
2005-09-04 06:55:16 +08:00
|
|
|
avkey.specified = specified;
|
|
|
|
avdatum = avtab_search(&policydb.te_avtab, &avkey);
|
2005-04-17 06:20:36 +08:00
|
|
|
|
|
|
|
/* If no permanent rule, also check for enabled conditional rules */
|
2008-04-19 05:38:33 +08:00
|
|
|
if (!avdatum) {
|
2005-09-04 06:55:16 +08:00
|
|
|
node = avtab_search_node(&policydb.te_cond_avtab, &avkey);
|
2008-08-07 08:18:20 +08:00
|
|
|
for (; node; node = avtab_search_node_next(node, specified)) {
|
2005-09-04 06:55:16 +08:00
|
|
|
if (node->key.specified & AVTAB_ENABLED) {
|
2005-04-17 06:20:36 +08:00
|
|
|
avdatum = &node->datum;
|
|
|
|
break;
|
|
|
|
}
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2005-09-04 06:55:16 +08:00
|
|
|
if (avdatum) {
|
2005-04-17 06:20:36 +08:00
|
|
|
/* Use the type from the type transition/member/change rule. */
|
2005-09-04 06:55:16 +08:00
|
|
|
newcontext.type = avdatum->data;
|
2005-04-17 06:20:36 +08:00
|
|
|
}
|
|
|
|
|
|
|
|
/* Check for class-specific changes. */
|
selinux: dynamic class/perm discovery
Modify SELinux to dynamically discover class and permission values
upon policy load, based on the dynamic object class/perm discovery
logic from libselinux. A mapping is created between kernel-private
class and permission indices used outside the security server and the
policy values used within the security server.
The mappings are only applied upon kernel-internal computations;
similar mappings for the private indices of userspace object managers
is handled on a per-object manager basis by the userspace AVC. The
interfaces for compute_av and transition_sid are split for kernel
vs. userspace; the userspace functions are distinguished by a _user
suffix.
The kernel-private class indices are no longer tied to the policy
values and thus do not need to skip indices for userspace classes;
thus the kernel class index values are compressed. The flask.h
definitions were regenerated by deleting the userspace classes from
refpolicy's definitions and then regenerating the headers. Going
forward, we can just maintain the flask.h, av_permissions.h, and
classmap.h definitions separately from policy as they are no longer
tied to the policy values. The next patch introduces a utility to
automate generation of flask.h and av_permissions.h from the
classmap.h definitions.
The older kernel class and permission string tables are removed and
replaced by a single security class mapping table that is walked at
policy load to generate the mapping. The old kernel class validation
logic is completely replaced by the mapping logic.
The handle unknown logic is reworked. reject_unknown=1 is handled
when the mappings are computed at policy load time, similar to the old
handling by the class validation logic. allow_unknown=1 is handled
when computing and mapping decisions - if the permission was not able
to be mapped (i.e. undefined, mapped to zero), then it is
automatically added to the allowed vector. If the class was not able
to be mapped (i.e. undefined, mapped to zero), then all permissions
are allowed for it if allow_unknown=1.
avc_audit leverages the new security class mapping table to lookup the
class and permission names from the kernel-private indices.
The mdp program is updated to use the new table when generating the
class definitions and allow rules for a minimal boot policy for the
kernel. It should be noted that this policy will not include any
userspace classes, nor will its policy index values for the kernel
classes correspond with the ones in refpolicy (they will instead match
the kernel-private indices).
Signed-off-by: Stephen Smalley <sds@tycho.nsa.gov>
Signed-off-by: James Morris <jmorris@namei.org>
2009-10-01 01:37:50 +08:00
|
|
|
if (tclass == policydb.process_class) {
|
2005-04-17 06:20:36 +08:00
|
|
|
if (specified & AVTAB_TRANSITION) {
|
|
|
|
/* Look for a role transition rule. */
|
|
|
|
for (roletr = policydb.role_tr; roletr;
|
|
|
|
roletr = roletr->next) {
|
|
|
|
if (roletr->role == scontext->role &&
|
|
|
|
roletr->type == tcontext->type) {
|
|
|
|
/* Use the role transition rule. */
|
|
|
|
newcontext.role = roletr->new_role;
|
|
|
|
break;
|
|
|
|
}
|
|
|
|
}
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
/* Set the MLS attributes.
|
|
|
|
This is done last because it may allocate memory. */
|
|
|
|
rc = mls_compute_sid(scontext, tcontext, tclass, specified, &newcontext);
|
|
|
|
if (rc)
|
|
|
|
goto out_unlock;
|
|
|
|
|
|
|
|
/* Check the validity of the context. */
|
|
|
|
if (!policydb_context_isvalid(&policydb, &newcontext)) {
|
|
|
|
rc = compute_sid_handle_invalid_context(scontext,
|
|
|
|
tcontext,
|
|
|
|
tclass,
|
|
|
|
&newcontext);
|
|
|
|
if (rc)
|
|
|
|
goto out_unlock;
|
|
|
|
}
|
|
|
|
/* Obtain the sid for the context. */
|
|
|
|
rc = sidtab_context_to_sid(&sidtab, &newcontext, out_sid);
|
|
|
|
out_unlock:
|
2008-06-06 16:40:29 +08:00
|
|
|
read_unlock(&policy_rwlock);
|
2005-04-17 06:20:36 +08:00
|
|
|
context_destroy(&newcontext);
|
|
|
|
out:
|
|
|
|
return rc;
|
|
|
|
}
|
|
|
|
|
|
|
|
/**
|
|
|
|
* security_transition_sid - Compute the SID for a new subject/object.
|
|
|
|
* @ssid: source security identifier
|
|
|
|
* @tsid: target security identifier
|
|
|
|
* @tclass: target security class
|
|
|
|
* @out_sid: security identifier for new subject/object
|
|
|
|
*
|
|
|
|
* Compute a SID to use for labeling a new subject or object in the
|
|
|
|
* class @tclass based on a SID pair (@ssid, @tsid).
|
|
|
|
* Return -%EINVAL if any of the parameters are invalid, -%ENOMEM
|
|
|
|
* if insufficient memory is available, or %0 if the new SID was
|
|
|
|
* computed successfully.
|
|
|
|
*/
|
|
|
|
int security_transition_sid(u32 ssid,
|
|
|
|
u32 tsid,
|
|
|
|
u16 tclass,
|
|
|
|
u32 *out_sid)
|
|
|
|
{
|
selinux: dynamic class/perm discovery
Modify SELinux to dynamically discover class and permission values
upon policy load, based on the dynamic object class/perm discovery
logic from libselinux. A mapping is created between kernel-private
class and permission indices used outside the security server and the
policy values used within the security server.
The mappings are only applied upon kernel-internal computations;
similar mappings for the private indices of userspace object managers
is handled on a per-object manager basis by the userspace AVC. The
interfaces for compute_av and transition_sid are split for kernel
vs. userspace; the userspace functions are distinguished by a _user
suffix.
The kernel-private class indices are no longer tied to the policy
values and thus do not need to skip indices for userspace classes;
thus the kernel class index values are compressed. The flask.h
definitions were regenerated by deleting the userspace classes from
refpolicy's definitions and then regenerating the headers. Going
forward, we can just maintain the flask.h, av_permissions.h, and
classmap.h definitions separately from policy as they are no longer
tied to the policy values. The next patch introduces a utility to
automate generation of flask.h and av_permissions.h from the
classmap.h definitions.
The older kernel class and permission string tables are removed and
replaced by a single security class mapping table that is walked at
policy load to generate the mapping. The old kernel class validation
logic is completely replaced by the mapping logic.
The handle unknown logic is reworked. reject_unknown=1 is handled
when the mappings are computed at policy load time, similar to the old
handling by the class validation logic. allow_unknown=1 is handled
when computing and mapping decisions - if the permission was not able
to be mapped (i.e. undefined, mapped to zero), then it is
automatically added to the allowed vector. If the class was not able
to be mapped (i.e. undefined, mapped to zero), then all permissions
are allowed for it if allow_unknown=1.
avc_audit leverages the new security class mapping table to lookup the
class and permission names from the kernel-private indices.
The mdp program is updated to use the new table when generating the
class definitions and allow rules for a minimal boot policy for the
kernel. It should be noted that this policy will not include any
userspace classes, nor will its policy index values for the kernel
classes correspond with the ones in refpolicy (they will instead match
the kernel-private indices).
Signed-off-by: Stephen Smalley <sds@tycho.nsa.gov>
Signed-off-by: James Morris <jmorris@namei.org>
2009-10-01 01:37:50 +08:00
|
|
|
return security_compute_sid(ssid, tsid, tclass, AVTAB_TRANSITION,
|
|
|
|
out_sid, true);
|
|
|
|
}
|
|
|
|
|
|
|
|
int security_transition_sid_user(u32 ssid,
|
|
|
|
u32 tsid,
|
|
|
|
u16 tclass,
|
|
|
|
u32 *out_sid)
|
|
|
|
{
|
|
|
|
return security_compute_sid(ssid, tsid, tclass, AVTAB_TRANSITION,
|
|
|
|
out_sid, false);
|
2005-04-17 06:20:36 +08:00
|
|
|
}
|
|
|
|
|
|
|
|
/**
|
|
|
|
* security_member_sid - Compute the SID for member selection.
|
|
|
|
* @ssid: source security identifier
|
|
|
|
* @tsid: target security identifier
|
|
|
|
* @tclass: target security class
|
|
|
|
* @out_sid: security identifier for selected member
|
|
|
|
*
|
|
|
|
* Compute a SID to use when selecting a member of a polyinstantiated
|
|
|
|
* object of class @tclass based on a SID pair (@ssid, @tsid).
|
|
|
|
* Return -%EINVAL if any of the parameters are invalid, -%ENOMEM
|
|
|
|
* if insufficient memory is available, or %0 if the SID was
|
|
|
|
* computed successfully.
|
|
|
|
*/
|
|
|
|
int security_member_sid(u32 ssid,
|
|
|
|
u32 tsid,
|
|
|
|
u16 tclass,
|
|
|
|
u32 *out_sid)
|
|
|
|
{
|
selinux: dynamic class/perm discovery
Modify SELinux to dynamically discover class and permission values
upon policy load, based on the dynamic object class/perm discovery
logic from libselinux. A mapping is created between kernel-private
class and permission indices used outside the security server and the
policy values used within the security server.
The mappings are only applied upon kernel-internal computations;
similar mappings for the private indices of userspace object managers
is handled on a per-object manager basis by the userspace AVC. The
interfaces for compute_av and transition_sid are split for kernel
vs. userspace; the userspace functions are distinguished by a _user
suffix.
The kernel-private class indices are no longer tied to the policy
values and thus do not need to skip indices for userspace classes;
thus the kernel class index values are compressed. The flask.h
definitions were regenerated by deleting the userspace classes from
refpolicy's definitions and then regenerating the headers. Going
forward, we can just maintain the flask.h, av_permissions.h, and
classmap.h definitions separately from policy as they are no longer
tied to the policy values. The next patch introduces a utility to
automate generation of flask.h and av_permissions.h from the
classmap.h definitions.
The older kernel class and permission string tables are removed and
replaced by a single security class mapping table that is walked at
policy load to generate the mapping. The old kernel class validation
logic is completely replaced by the mapping logic.
The handle unknown logic is reworked. reject_unknown=1 is handled
when the mappings are computed at policy load time, similar to the old
handling by the class validation logic. allow_unknown=1 is handled
when computing and mapping decisions - if the permission was not able
to be mapped (i.e. undefined, mapped to zero), then it is
automatically added to the allowed vector. If the class was not able
to be mapped (i.e. undefined, mapped to zero), then all permissions
are allowed for it if allow_unknown=1.
avc_audit leverages the new security class mapping table to lookup the
class and permission names from the kernel-private indices.
The mdp program is updated to use the new table when generating the
class definitions and allow rules for a minimal boot policy for the
kernel. It should be noted that this policy will not include any
userspace classes, nor will its policy index values for the kernel
classes correspond with the ones in refpolicy (they will instead match
the kernel-private indices).
Signed-off-by: Stephen Smalley <sds@tycho.nsa.gov>
Signed-off-by: James Morris <jmorris@namei.org>
2009-10-01 01:37:50 +08:00
|
|
|
return security_compute_sid(ssid, tsid, tclass, AVTAB_MEMBER, out_sid,
|
|
|
|
false);
|
2005-04-17 06:20:36 +08:00
|
|
|
}
|
|
|
|
|
|
|
|
/**
|
|
|
|
* security_change_sid - Compute the SID for object relabeling.
|
|
|
|
* @ssid: source security identifier
|
|
|
|
* @tsid: target security identifier
|
|
|
|
* @tclass: target security class
|
|
|
|
* @out_sid: security identifier for selected member
|
|
|
|
*
|
|
|
|
* Compute a SID to use for relabeling an object of class @tclass
|
|
|
|
* based on a SID pair (@ssid, @tsid).
|
|
|
|
* Return -%EINVAL if any of the parameters are invalid, -%ENOMEM
|
|
|
|
* if insufficient memory is available, or %0 if the SID was
|
|
|
|
* computed successfully.
|
|
|
|
*/
|
|
|
|
int security_change_sid(u32 ssid,
|
|
|
|
u32 tsid,
|
|
|
|
u16 tclass,
|
|
|
|
u32 *out_sid)
|
|
|
|
{
|
selinux: dynamic class/perm discovery
Modify SELinux to dynamically discover class and permission values
upon policy load, based on the dynamic object class/perm discovery
logic from libselinux. A mapping is created between kernel-private
class and permission indices used outside the security server and the
policy values used within the security server.
The mappings are only applied upon kernel-internal computations;
similar mappings for the private indices of userspace object managers
is handled on a per-object manager basis by the userspace AVC. The
interfaces for compute_av and transition_sid are split for kernel
vs. userspace; the userspace functions are distinguished by a _user
suffix.
The kernel-private class indices are no longer tied to the policy
values and thus do not need to skip indices for userspace classes;
thus the kernel class index values are compressed. The flask.h
definitions were regenerated by deleting the userspace classes from
refpolicy's definitions and then regenerating the headers. Going
forward, we can just maintain the flask.h, av_permissions.h, and
classmap.h definitions separately from policy as they are no longer
tied to the policy values. The next patch introduces a utility to
automate generation of flask.h and av_permissions.h from the
classmap.h definitions.
The older kernel class and permission string tables are removed and
replaced by a single security class mapping table that is walked at
policy load to generate the mapping. The old kernel class validation
logic is completely replaced by the mapping logic.
The handle unknown logic is reworked. reject_unknown=1 is handled
when the mappings are computed at policy load time, similar to the old
handling by the class validation logic. allow_unknown=1 is handled
when computing and mapping decisions - if the permission was not able
to be mapped (i.e. undefined, mapped to zero), then it is
automatically added to the allowed vector. If the class was not able
to be mapped (i.e. undefined, mapped to zero), then all permissions
are allowed for it if allow_unknown=1.
avc_audit leverages the new security class mapping table to lookup the
class and permission names from the kernel-private indices.
The mdp program is updated to use the new table when generating the
class definitions and allow rules for a minimal boot policy for the
kernel. It should be noted that this policy will not include any
userspace classes, nor will its policy index values for the kernel
classes correspond with the ones in refpolicy (they will instead match
the kernel-private indices).
Signed-off-by: Stephen Smalley <sds@tycho.nsa.gov>
Signed-off-by: James Morris <jmorris@namei.org>
2009-10-01 01:37:50 +08:00
|
|
|
return security_compute_sid(ssid, tsid, tclass, AVTAB_CHANGE, out_sid,
|
|
|
|
false);
|
2006-11-07 01:38:18 +08:00
|
|
|
}
|
|
|
|
|
2005-04-17 06:20:36 +08:00
|
|
|
/* Clone the SID into the new SID table. */
|
|
|
|
static int clone_sid(u32 sid,
|
|
|
|
struct context *context,
|
|
|
|
void *arg)
|
|
|
|
{
|
|
|
|
struct sidtab *s = arg;
|
|
|
|
|
2010-02-04 00:06:01 +08:00
|
|
|
if (sid > SECINITSID_NUM)
|
|
|
|
return sidtab_insert(s, sid, context);
|
|
|
|
else
|
|
|
|
return 0;
|
2005-04-17 06:20:36 +08:00
|
|
|
}
|
|
|
|
|
|
|
|
static inline int convert_context_handle_invalid_context(struct context *context)
|
|
|
|
{
|
|
|
|
int rc = 0;
|
|
|
|
|
|
|
|
if (selinux_enforcing) {
|
|
|
|
rc = -EINVAL;
|
|
|
|
} else {
|
|
|
|
char *s;
|
|
|
|
u32 len;
|
|
|
|
|
2008-05-08 01:03:20 +08:00
|
|
|
if (!context_struct_to_string(context, &s, &len)) {
|
|
|
|
printk(KERN_WARNING
|
|
|
|
"SELinux: Context %s would be invalid if enforcing\n",
|
|
|
|
s);
|
|
|
|
kfree(s);
|
|
|
|
}
|
2005-04-17 06:20:36 +08:00
|
|
|
}
|
|
|
|
return rc;
|
|
|
|
}
|
|
|
|
|
|
|
|
struct convert_context_args {
|
|
|
|
struct policydb *oldp;
|
|
|
|
struct policydb *newp;
|
|
|
|
};
|
|
|
|
|
|
|
|
/*
|
|
|
|
* Convert the values in the security context
|
|
|
|
* structure `c' from the values specified
|
|
|
|
* in the policy `p->oldp' to the values specified
|
|
|
|
* in the policy `p->newp'. Verify that the
|
|
|
|
* context is valid under the new policy.
|
|
|
|
*/
|
|
|
|
static int convert_context(u32 key,
|
|
|
|
struct context *c,
|
|
|
|
void *p)
|
|
|
|
{
|
|
|
|
struct convert_context_args *args;
|
|
|
|
struct context oldc;
|
2010-02-03 23:40:20 +08:00
|
|
|
struct ocontext *oc;
|
|
|
|
struct mls_range *range;
|
2005-04-17 06:20:36 +08:00
|
|
|
struct role_datum *role;
|
|
|
|
struct type_datum *typdatum;
|
|
|
|
struct user_datum *usrdatum;
|
|
|
|
char *s;
|
|
|
|
u32 len;
|
2010-02-04 00:06:01 +08:00
|
|
|
int rc = 0;
|
|
|
|
|
|
|
|
if (key <= SECINITSID_NUM)
|
|
|
|
goto out;
|
2005-04-17 06:20:36 +08:00
|
|
|
|
|
|
|
args = p;
|
|
|
|
|
2008-05-08 01:03:20 +08:00
|
|
|
if (c->str) {
|
|
|
|
struct context ctx;
|
2008-05-14 22:33:55 +08:00
|
|
|
s = kstrdup(c->str, GFP_KERNEL);
|
|
|
|
if (!s) {
|
|
|
|
rc = -ENOMEM;
|
|
|
|
goto out;
|
|
|
|
}
|
|
|
|
rc = string_to_context_struct(args->newp, NULL, s,
|
|
|
|
c->len, &ctx, SECSID_NULL);
|
|
|
|
kfree(s);
|
2008-05-08 01:03:20 +08:00
|
|
|
if (!rc) {
|
|
|
|
printk(KERN_INFO
|
|
|
|
"SELinux: Context %s became valid (mapped).\n",
|
|
|
|
c->str);
|
|
|
|
/* Replace string with mapped representation. */
|
|
|
|
kfree(c->str);
|
|
|
|
memcpy(c, &ctx, sizeof(*c));
|
|
|
|
goto out;
|
|
|
|
} else if (rc == -EINVAL) {
|
|
|
|
/* Retain string representation for later mapping. */
|
|
|
|
rc = 0;
|
|
|
|
goto out;
|
|
|
|
} else {
|
|
|
|
/* Other error condition, e.g. ENOMEM. */
|
|
|
|
printk(KERN_ERR
|
|
|
|
"SELinux: Unable to map context %s, rc = %d.\n",
|
|
|
|
c->str, -rc);
|
|
|
|
goto out;
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2005-04-17 06:20:36 +08:00
|
|
|
rc = context_cpy(&oldc, c);
|
|
|
|
if (rc)
|
|
|
|
goto out;
|
|
|
|
|
|
|
|
rc = -EINVAL;
|
|
|
|
|
|
|
|
/* Convert the user. */
|
|
|
|
usrdatum = hashtab_search(args->newp->p_users.table,
|
2008-04-19 05:38:33 +08:00
|
|
|
args->oldp->p_user_val_to_name[c->user - 1]);
|
|
|
|
if (!usrdatum)
|
2005-04-17 06:20:36 +08:00
|
|
|
goto bad;
|
|
|
|
c->user = usrdatum->value;
|
|
|
|
|
|
|
|
/* Convert the role. */
|
|
|
|
role = hashtab_search(args->newp->p_roles.table,
|
2008-04-19 05:38:33 +08:00
|
|
|
args->oldp->p_role_val_to_name[c->role - 1]);
|
|
|
|
if (!role)
|
2005-04-17 06:20:36 +08:00
|
|
|
goto bad;
|
|
|
|
c->role = role->value;
|
|
|
|
|
|
|
|
/* Convert the type. */
|
|
|
|
typdatum = hashtab_search(args->newp->p_types.table,
|
2008-04-19 05:38:33 +08:00
|
|
|
args->oldp->p_type_val_to_name[c->type - 1]);
|
|
|
|
if (!typdatum)
|
2005-04-17 06:20:36 +08:00
|
|
|
goto bad;
|
|
|
|
c->type = typdatum->value;
|
|
|
|
|
2010-02-03 23:40:20 +08:00
|
|
|
/* Convert the MLS fields if dealing with MLS policies */
|
|
|
|
if (args->oldp->mls_enabled && args->newp->mls_enabled) {
|
|
|
|
rc = mls_convert_context(args->oldp, args->newp, c);
|
|
|
|
if (rc)
|
|
|
|
goto bad;
|
|
|
|
} else if (args->oldp->mls_enabled && !args->newp->mls_enabled) {
|
|
|
|
/*
|
|
|
|
* Switching between MLS and non-MLS policy:
|
|
|
|
* free any storage used by the MLS fields in the
|
|
|
|
* context for all existing entries in the sidtab.
|
|
|
|
*/
|
|
|
|
mls_context_destroy(c);
|
|
|
|
} else if (!args->oldp->mls_enabled && args->newp->mls_enabled) {
|
|
|
|
/*
|
|
|
|
* Switching between non-MLS and MLS policy:
|
|
|
|
* ensure that the MLS fields of the context for all
|
|
|
|
* existing entries in the sidtab are filled in with a
|
|
|
|
* suitable default value, likely taken from one of the
|
|
|
|
* initial SIDs.
|
|
|
|
*/
|
|
|
|
oc = args->newp->ocontexts[OCON_ISID];
|
|
|
|
while (oc && oc->sid[0] != SECINITSID_UNLABELED)
|
|
|
|
oc = oc->next;
|
|
|
|
if (!oc) {
|
|
|
|
printk(KERN_ERR "SELinux: unable to look up"
|
|
|
|
" the initial SIDs list\n");
|
|
|
|
goto bad;
|
|
|
|
}
|
|
|
|
range = &oc->context[0].range;
|
|
|
|
rc = mls_range_set(c, range);
|
|
|
|
if (rc)
|
|
|
|
goto bad;
|
|
|
|
}
|
2005-04-17 06:20:36 +08:00
|
|
|
|
|
|
|
/* Check the validity of the new context. */
|
|
|
|
if (!policydb_context_isvalid(args->newp, c)) {
|
|
|
|
rc = convert_context_handle_invalid_context(&oldc);
|
|
|
|
if (rc)
|
|
|
|
goto bad;
|
|
|
|
}
|
|
|
|
|
|
|
|
context_destroy(&oldc);
|
2008-05-08 01:03:20 +08:00
|
|
|
rc = 0;
|
2005-04-17 06:20:36 +08:00
|
|
|
out:
|
|
|
|
return rc;
|
|
|
|
bad:
|
2008-05-08 01:03:20 +08:00
|
|
|
/* Map old representation to string and save it. */
|
|
|
|
if (context_struct_to_string(&oldc, &s, &len))
|
|
|
|
return -ENOMEM;
|
2005-04-17 06:20:36 +08:00
|
|
|
context_destroy(&oldc);
|
2008-05-08 01:03:20 +08:00
|
|
|
context_destroy(c);
|
|
|
|
c->str = s;
|
|
|
|
c->len = len;
|
|
|
|
printk(KERN_INFO
|
|
|
|
"SELinux: Context %s became invalid (unmapped).\n",
|
|
|
|
c->str);
|
|
|
|
rc = 0;
|
2005-04-17 06:20:36 +08:00
|
|
|
goto out;
|
|
|
|
}
|
|
|
|
|
2008-01-29 21:38:19 +08:00
|
|
|
static void security_load_policycaps(void)
|
|
|
|
{
|
|
|
|
selinux_policycap_netpeer = ebitmap_get_bit(&policydb.policycaps,
|
|
|
|
POLICYDB_CAPABILITY_NETPEER);
|
2008-02-29 01:58:40 +08:00
|
|
|
selinux_policycap_openperm = ebitmap_get_bit(&policydb.policycaps,
|
|
|
|
POLICYDB_CAPABILITY_OPENPERM);
|
2008-01-29 21:38:19 +08:00
|
|
|
}
|
|
|
|
|
2005-04-17 06:20:36 +08:00
|
|
|
extern void selinux_complete_init(void);
|
2007-04-20 02:16:19 +08:00
|
|
|
static int security_preserve_bools(struct policydb *p);
|
2005-04-17 06:20:36 +08:00
|
|
|
|
|
|
|
/**
|
|
|
|
* security_load_policy - Load a security policy configuration.
|
|
|
|
* @data: binary policy data
|
|
|
|
* @len: length of data in bytes
|
|
|
|
*
|
|
|
|
* Load a new set of security policy configuration data,
|
|
|
|
* validate it and convert the SID table as necessary.
|
|
|
|
* This function will flush the access vector cache after
|
|
|
|
* loading the new policy.
|
|
|
|
*/
|
|
|
|
int security_load_policy(void *data, size_t len)
|
|
|
|
{
|
|
|
|
struct policydb oldpolicydb, newpolicydb;
|
|
|
|
struct sidtab oldsidtab, newsidtab;
|
selinux: dynamic class/perm discovery
Modify SELinux to dynamically discover class and permission values
upon policy load, based on the dynamic object class/perm discovery
logic from libselinux. A mapping is created between kernel-private
class and permission indices used outside the security server and the
policy values used within the security server.
The mappings are only applied upon kernel-internal computations;
similar mappings for the private indices of userspace object managers
is handled on a per-object manager basis by the userspace AVC. The
interfaces for compute_av and transition_sid are split for kernel
vs. userspace; the userspace functions are distinguished by a _user
suffix.
The kernel-private class indices are no longer tied to the policy
values and thus do not need to skip indices for userspace classes;
thus the kernel class index values are compressed. The flask.h
definitions were regenerated by deleting the userspace classes from
refpolicy's definitions and then regenerating the headers. Going
forward, we can just maintain the flask.h, av_permissions.h, and
classmap.h definitions separately from policy as they are no longer
tied to the policy values. The next patch introduces a utility to
automate generation of flask.h and av_permissions.h from the
classmap.h definitions.
The older kernel class and permission string tables are removed and
replaced by a single security class mapping table that is walked at
policy load to generate the mapping. The old kernel class validation
logic is completely replaced by the mapping logic.
The handle unknown logic is reworked. reject_unknown=1 is handled
when the mappings are computed at policy load time, similar to the old
handling by the class validation logic. allow_unknown=1 is handled
when computing and mapping decisions - if the permission was not able
to be mapped (i.e. undefined, mapped to zero), then it is
automatically added to the allowed vector. If the class was not able
to be mapped (i.e. undefined, mapped to zero), then all permissions
are allowed for it if allow_unknown=1.
avc_audit leverages the new security class mapping table to lookup the
class and permission names from the kernel-private indices.
The mdp program is updated to use the new table when generating the
class definitions and allow rules for a minimal boot policy for the
kernel. It should be noted that this policy will not include any
userspace classes, nor will its policy index values for the kernel
classes correspond with the ones in refpolicy (they will instead match
the kernel-private indices).
Signed-off-by: Stephen Smalley <sds@tycho.nsa.gov>
Signed-off-by: James Morris <jmorris@namei.org>
2009-10-01 01:37:50 +08:00
|
|
|
struct selinux_mapping *oldmap, *map = NULL;
|
2005-04-17 06:20:36 +08:00
|
|
|
struct convert_context_args args;
|
|
|
|
u32 seqno;
|
selinux: dynamic class/perm discovery
Modify SELinux to dynamically discover class and permission values
upon policy load, based on the dynamic object class/perm discovery
logic from libselinux. A mapping is created between kernel-private
class and permission indices used outside the security server and the
policy values used within the security server.
The mappings are only applied upon kernel-internal computations;
similar mappings for the private indices of userspace object managers
is handled on a per-object manager basis by the userspace AVC. The
interfaces for compute_av and transition_sid are split for kernel
vs. userspace; the userspace functions are distinguished by a _user
suffix.
The kernel-private class indices are no longer tied to the policy
values and thus do not need to skip indices for userspace classes;
thus the kernel class index values are compressed. The flask.h
definitions were regenerated by deleting the userspace classes from
refpolicy's definitions and then regenerating the headers. Going
forward, we can just maintain the flask.h, av_permissions.h, and
classmap.h definitions separately from policy as they are no longer
tied to the policy values. The next patch introduces a utility to
automate generation of flask.h and av_permissions.h from the
classmap.h definitions.
The older kernel class and permission string tables are removed and
replaced by a single security class mapping table that is walked at
policy load to generate the mapping. The old kernel class validation
logic is completely replaced by the mapping logic.
The handle unknown logic is reworked. reject_unknown=1 is handled
when the mappings are computed at policy load time, similar to the old
handling by the class validation logic. allow_unknown=1 is handled
when computing and mapping decisions - if the permission was not able
to be mapped (i.e. undefined, mapped to zero), then it is
automatically added to the allowed vector. If the class was not able
to be mapped (i.e. undefined, mapped to zero), then all permissions
are allowed for it if allow_unknown=1.
avc_audit leverages the new security class mapping table to lookup the
class and permission names from the kernel-private indices.
The mdp program is updated to use the new table when generating the
class definitions and allow rules for a minimal boot policy for the
kernel. It should be noted that this policy will not include any
userspace classes, nor will its policy index values for the kernel
classes correspond with the ones in refpolicy (they will instead match
the kernel-private indices).
Signed-off-by: Stephen Smalley <sds@tycho.nsa.gov>
Signed-off-by: James Morris <jmorris@namei.org>
2009-10-01 01:37:50 +08:00
|
|
|
u16 map_size;
|
2005-04-17 06:20:36 +08:00
|
|
|
int rc = 0;
|
|
|
|
struct policy_file file = { data, len }, *fp = &file;
|
|
|
|
|
|
|
|
if (!ss_initialized) {
|
|
|
|
avtab_cache_init();
|
2010-04-20 22:29:42 +08:00
|
|
|
rc = policydb_read(&policydb, fp);
|
|
|
|
if (rc) {
|
2005-04-17 06:20:36 +08:00
|
|
|
avtab_cache_destroy();
|
2010-04-20 22:29:42 +08:00
|
|
|
return rc;
|
2005-04-17 06:20:36 +08:00
|
|
|
}
|
2010-04-20 22:29:42 +08:00
|
|
|
|
|
|
|
rc = selinux_set_mapping(&policydb, secclass_map,
|
|
|
|
¤t_mapping,
|
|
|
|
¤t_mapping_size);
|
|
|
|
if (rc) {
|
2005-04-17 06:20:36 +08:00
|
|
|
policydb_destroy(&policydb);
|
|
|
|
avtab_cache_destroy();
|
2010-04-20 22:29:42 +08:00
|
|
|
return rc;
|
2005-04-17 06:20:36 +08:00
|
|
|
}
|
2010-04-20 22:29:42 +08:00
|
|
|
|
|
|
|
rc = policydb_load_isids(&policydb, &sidtab);
|
|
|
|
if (rc) {
|
2006-11-07 01:38:18 +08:00
|
|
|
policydb_destroy(&policydb);
|
|
|
|
avtab_cache_destroy();
|
2010-04-20 22:29:42 +08:00
|
|
|
return rc;
|
2006-11-07 01:38:18 +08:00
|
|
|
}
|
2010-04-20 22:29:42 +08:00
|
|
|
|
2008-01-29 21:38:19 +08:00
|
|
|
security_load_policycaps();
|
2005-04-17 06:20:36 +08:00
|
|
|
ss_initialized = 1;
|
2005-05-17 12:53:52 +08:00
|
|
|
seqno = ++latest_granting;
|
2005-04-17 06:20:36 +08:00
|
|
|
selinux_complete_init();
|
2005-05-17 12:53:52 +08:00
|
|
|
avc_ss_reset(seqno);
|
|
|
|
selnl_notify_policyload(seqno);
|
2006-08-05 14:17:57 +08:00
|
|
|
selinux_netlbl_cache_invalidate();
|
2007-01-27 11:03:48 +08:00
|
|
|
selinux_xfrm_notify_policyload();
|
2005-04-17 06:20:36 +08:00
|
|
|
return 0;
|
|
|
|
}
|
|
|
|
|
|
|
|
#if 0
|
|
|
|
sidtab_hash_eval(&sidtab, "sids");
|
|
|
|
#endif
|
|
|
|
|
2010-04-20 22:29:42 +08:00
|
|
|
rc = policydb_read(&newpolicydb, fp);
|
|
|
|
if (rc)
|
|
|
|
return rc;
|
2005-04-17 06:20:36 +08:00
|
|
|
|
2010-02-03 23:40:20 +08:00
|
|
|
/* If switching between different policy types, log MLS status */
|
|
|
|
if (policydb.mls_enabled && !newpolicydb.mls_enabled)
|
|
|
|
printk(KERN_INFO "SELinux: Disabling MLS support...\n");
|
|
|
|
else if (!policydb.mls_enabled && newpolicydb.mls_enabled)
|
|
|
|
printk(KERN_INFO "SELinux: Enabling MLS support...\n");
|
|
|
|
|
2010-02-04 00:06:01 +08:00
|
|
|
rc = policydb_load_isids(&newpolicydb, &newsidtab);
|
|
|
|
if (rc) {
|
|
|
|
printk(KERN_ERR "SELinux: unable to load the initial SIDs\n");
|
2008-05-08 01:03:20 +08:00
|
|
|
policydb_destroy(&newpolicydb);
|
2010-02-04 00:06:01 +08:00
|
|
|
return rc;
|
2008-05-08 01:03:20 +08:00
|
|
|
}
|
2005-04-17 06:20:36 +08:00
|
|
|
|
2010-04-20 22:29:42 +08:00
|
|
|
rc = selinux_set_mapping(&newpolicydb, secclass_map, &map, &map_size);
|
|
|
|
if (rc)
|
2006-11-07 01:38:18 +08:00
|
|
|
goto err;
|
|
|
|
|
2007-04-20 02:16:19 +08:00
|
|
|
rc = security_preserve_bools(&newpolicydb);
|
|
|
|
if (rc) {
|
2008-02-26 17:42:02 +08:00
|
|
|
printk(KERN_ERR "SELinux: unable to preserve booleans\n");
|
2007-04-20 02:16:19 +08:00
|
|
|
goto err;
|
|
|
|
}
|
|
|
|
|
2005-04-17 06:20:36 +08:00
|
|
|
/* Clone the SID table. */
|
|
|
|
sidtab_shutdown(&sidtab);
|
2010-04-20 22:29:42 +08:00
|
|
|
|
|
|
|
rc = sidtab_map(&sidtab, clone_sid, &newsidtab);
|
|
|
|
if (rc)
|
2005-04-17 06:20:36 +08:00
|
|
|
goto err;
|
|
|
|
|
2008-05-08 01:03:20 +08:00
|
|
|
/*
|
|
|
|
* Convert the internal representations of contexts
|
|
|
|
* in the new SID table.
|
|
|
|
*/
|
2005-04-17 06:20:36 +08:00
|
|
|
args.oldp = &policydb;
|
|
|
|
args.newp = &newpolicydb;
|
2008-05-08 01:03:20 +08:00
|
|
|
rc = sidtab_map(&newsidtab, convert_context, &args);
|
2010-02-03 23:40:20 +08:00
|
|
|
if (rc) {
|
|
|
|
printk(KERN_ERR "SELinux: unable to convert the internal"
|
|
|
|
" representation of contexts in the new SID"
|
|
|
|
" table\n");
|
2008-05-08 01:03:20 +08:00
|
|
|
goto err;
|
2010-02-03 23:40:20 +08:00
|
|
|
}
|
2005-04-17 06:20:36 +08:00
|
|
|
|
|
|
|
/* Save the old policydb and SID table to free later. */
|
|
|
|
memcpy(&oldpolicydb, &policydb, sizeof policydb);
|
|
|
|
sidtab_set(&oldsidtab, &sidtab);
|
|
|
|
|
|
|
|
/* Install the new policydb and SID table. */
|
2008-06-06 16:40:29 +08:00
|
|
|
write_lock_irq(&policy_rwlock);
|
2005-04-17 06:20:36 +08:00
|
|
|
memcpy(&policydb, &newpolicydb, sizeof policydb);
|
|
|
|
sidtab_set(&sidtab, &newsidtab);
|
2008-01-29 21:38:19 +08:00
|
|
|
security_load_policycaps();
|
selinux: dynamic class/perm discovery
Modify SELinux to dynamically discover class and permission values
upon policy load, based on the dynamic object class/perm discovery
logic from libselinux. A mapping is created between kernel-private
class and permission indices used outside the security server and the
policy values used within the security server.
The mappings are only applied upon kernel-internal computations;
similar mappings for the private indices of userspace object managers
is handled on a per-object manager basis by the userspace AVC. The
interfaces for compute_av and transition_sid are split for kernel
vs. userspace; the userspace functions are distinguished by a _user
suffix.
The kernel-private class indices are no longer tied to the policy
values and thus do not need to skip indices for userspace classes;
thus the kernel class index values are compressed. The flask.h
definitions were regenerated by deleting the userspace classes from
refpolicy's definitions and then regenerating the headers. Going
forward, we can just maintain the flask.h, av_permissions.h, and
classmap.h definitions separately from policy as they are no longer
tied to the policy values. The next patch introduces a utility to
automate generation of flask.h and av_permissions.h from the
classmap.h definitions.
The older kernel class and permission string tables are removed and
replaced by a single security class mapping table that is walked at
policy load to generate the mapping. The old kernel class validation
logic is completely replaced by the mapping logic.
The handle unknown logic is reworked. reject_unknown=1 is handled
when the mappings are computed at policy load time, similar to the old
handling by the class validation logic. allow_unknown=1 is handled
when computing and mapping decisions - if the permission was not able
to be mapped (i.e. undefined, mapped to zero), then it is
automatically added to the allowed vector. If the class was not able
to be mapped (i.e. undefined, mapped to zero), then all permissions
are allowed for it if allow_unknown=1.
avc_audit leverages the new security class mapping table to lookup the
class and permission names from the kernel-private indices.
The mdp program is updated to use the new table when generating the
class definitions and allow rules for a minimal boot policy for the
kernel. It should be noted that this policy will not include any
userspace classes, nor will its policy index values for the kernel
classes correspond with the ones in refpolicy (they will instead match
the kernel-private indices).
Signed-off-by: Stephen Smalley <sds@tycho.nsa.gov>
Signed-off-by: James Morris <jmorris@namei.org>
2009-10-01 01:37:50 +08:00
|
|
|
oldmap = current_mapping;
|
|
|
|
current_mapping = map;
|
|
|
|
current_mapping_size = map_size;
|
2005-04-17 06:20:36 +08:00
|
|
|
seqno = ++latest_granting;
|
2008-06-06 16:40:29 +08:00
|
|
|
write_unlock_irq(&policy_rwlock);
|
2005-04-17 06:20:36 +08:00
|
|
|
|
|
|
|
/* Free the old policydb and SID table. */
|
|
|
|
policydb_destroy(&oldpolicydb);
|
|
|
|
sidtab_destroy(&oldsidtab);
|
selinux: dynamic class/perm discovery
Modify SELinux to dynamically discover class and permission values
upon policy load, based on the dynamic object class/perm discovery
logic from libselinux. A mapping is created between kernel-private
class and permission indices used outside the security server and the
policy values used within the security server.
The mappings are only applied upon kernel-internal computations;
similar mappings for the private indices of userspace object managers
is handled on a per-object manager basis by the userspace AVC. The
interfaces for compute_av and transition_sid are split for kernel
vs. userspace; the userspace functions are distinguished by a _user
suffix.
The kernel-private class indices are no longer tied to the policy
values and thus do not need to skip indices for userspace classes;
thus the kernel class index values are compressed. The flask.h
definitions were regenerated by deleting the userspace classes from
refpolicy's definitions and then regenerating the headers. Going
forward, we can just maintain the flask.h, av_permissions.h, and
classmap.h definitions separately from policy as they are no longer
tied to the policy values. The next patch introduces a utility to
automate generation of flask.h and av_permissions.h from the
classmap.h definitions.
The older kernel class and permission string tables are removed and
replaced by a single security class mapping table that is walked at
policy load to generate the mapping. The old kernel class validation
logic is completely replaced by the mapping logic.
The handle unknown logic is reworked. reject_unknown=1 is handled
when the mappings are computed at policy load time, similar to the old
handling by the class validation logic. allow_unknown=1 is handled
when computing and mapping decisions - if the permission was not able
to be mapped (i.e. undefined, mapped to zero), then it is
automatically added to the allowed vector. If the class was not able
to be mapped (i.e. undefined, mapped to zero), then all permissions
are allowed for it if allow_unknown=1.
avc_audit leverages the new security class mapping table to lookup the
class and permission names from the kernel-private indices.
The mdp program is updated to use the new table when generating the
class definitions and allow rules for a minimal boot policy for the
kernel. It should be noted that this policy will not include any
userspace classes, nor will its policy index values for the kernel
classes correspond with the ones in refpolicy (they will instead match
the kernel-private indices).
Signed-off-by: Stephen Smalley <sds@tycho.nsa.gov>
Signed-off-by: James Morris <jmorris@namei.org>
2009-10-01 01:37:50 +08:00
|
|
|
kfree(oldmap);
|
2005-04-17 06:20:36 +08:00
|
|
|
|
|
|
|
avc_ss_reset(seqno);
|
|
|
|
selnl_notify_policyload(seqno);
|
2006-08-05 14:17:57 +08:00
|
|
|
selinux_netlbl_cache_invalidate();
|
2007-01-27 11:03:48 +08:00
|
|
|
selinux_xfrm_notify_policyload();
|
2005-04-17 06:20:36 +08:00
|
|
|
|
|
|
|
return 0;
|
|
|
|
|
|
|
|
err:
|
selinux: dynamic class/perm discovery
Modify SELinux to dynamically discover class and permission values
upon policy load, based on the dynamic object class/perm discovery
logic from libselinux. A mapping is created between kernel-private
class and permission indices used outside the security server and the
policy values used within the security server.
The mappings are only applied upon kernel-internal computations;
similar mappings for the private indices of userspace object managers
is handled on a per-object manager basis by the userspace AVC. The
interfaces for compute_av and transition_sid are split for kernel
vs. userspace; the userspace functions are distinguished by a _user
suffix.
The kernel-private class indices are no longer tied to the policy
values and thus do not need to skip indices for userspace classes;
thus the kernel class index values are compressed. The flask.h
definitions were regenerated by deleting the userspace classes from
refpolicy's definitions and then regenerating the headers. Going
forward, we can just maintain the flask.h, av_permissions.h, and
classmap.h definitions separately from policy as they are no longer
tied to the policy values. The next patch introduces a utility to
automate generation of flask.h and av_permissions.h from the
classmap.h definitions.
The older kernel class and permission string tables are removed and
replaced by a single security class mapping table that is walked at
policy load to generate the mapping. The old kernel class validation
logic is completely replaced by the mapping logic.
The handle unknown logic is reworked. reject_unknown=1 is handled
when the mappings are computed at policy load time, similar to the old
handling by the class validation logic. allow_unknown=1 is handled
when computing and mapping decisions - if the permission was not able
to be mapped (i.e. undefined, mapped to zero), then it is
automatically added to the allowed vector. If the class was not able
to be mapped (i.e. undefined, mapped to zero), then all permissions
are allowed for it if allow_unknown=1.
avc_audit leverages the new security class mapping table to lookup the
class and permission names from the kernel-private indices.
The mdp program is updated to use the new table when generating the
class definitions and allow rules for a minimal boot policy for the
kernel. It should be noted that this policy will not include any
userspace classes, nor will its policy index values for the kernel
classes correspond with the ones in refpolicy (they will instead match
the kernel-private indices).
Signed-off-by: Stephen Smalley <sds@tycho.nsa.gov>
Signed-off-by: James Morris <jmorris@namei.org>
2009-10-01 01:37:50 +08:00
|
|
|
kfree(map);
|
2005-04-17 06:20:36 +08:00
|
|
|
sidtab_destroy(&newsidtab);
|
|
|
|
policydb_destroy(&newpolicydb);
|
|
|
|
return rc;
|
|
|
|
|
|
|
|
}
|
|
|
|
|
|
|
|
/**
|
|
|
|
* security_port_sid - Obtain the SID for a port.
|
|
|
|
* @protocol: protocol number
|
|
|
|
* @port: port number
|
|
|
|
* @out_sid: security identifier
|
|
|
|
*/
|
2008-04-10 22:48:14 +08:00
|
|
|
int security_port_sid(u8 protocol, u16 port, u32 *out_sid)
|
2005-04-17 06:20:36 +08:00
|
|
|
{
|
|
|
|
struct ocontext *c;
|
|
|
|
int rc = 0;
|
|
|
|
|
2008-06-06 16:40:29 +08:00
|
|
|
read_lock(&policy_rwlock);
|
2005-04-17 06:20:36 +08:00
|
|
|
|
|
|
|
c = policydb.ocontexts[OCON_PORT];
|
|
|
|
while (c) {
|
|
|
|
if (c->u.port.protocol == protocol &&
|
|
|
|
c->u.port.low_port <= port &&
|
|
|
|
c->u.port.high_port >= port)
|
|
|
|
break;
|
|
|
|
c = c->next;
|
|
|
|
}
|
|
|
|
|
|
|
|
if (c) {
|
|
|
|
if (!c->sid[0]) {
|
|
|
|
rc = sidtab_context_to_sid(&sidtab,
|
|
|
|
&c->context[0],
|
|
|
|
&c->sid[0]);
|
|
|
|
if (rc)
|
|
|
|
goto out;
|
|
|
|
}
|
|
|
|
*out_sid = c->sid[0];
|
|
|
|
} else {
|
|
|
|
*out_sid = SECINITSID_PORT;
|
|
|
|
}
|
|
|
|
|
|
|
|
out:
|
2008-06-06 16:40:29 +08:00
|
|
|
read_unlock(&policy_rwlock);
|
2005-04-17 06:20:36 +08:00
|
|
|
return rc;
|
|
|
|
}
|
|
|
|
|
|
|
|
/**
|
|
|
|
* security_netif_sid - Obtain the SID for a network interface.
|
|
|
|
* @name: interface name
|
|
|
|
* @if_sid: interface SID
|
|
|
|
*/
|
2008-01-29 21:38:08 +08:00
|
|
|
int security_netif_sid(char *name, u32 *if_sid)
|
2005-04-17 06:20:36 +08:00
|
|
|
{
|
|
|
|
int rc = 0;
|
|
|
|
struct ocontext *c;
|
|
|
|
|
2008-06-06 16:40:29 +08:00
|
|
|
read_lock(&policy_rwlock);
|
2005-04-17 06:20:36 +08:00
|
|
|
|
|
|
|
c = policydb.ocontexts[OCON_NETIF];
|
|
|
|
while (c) {
|
|
|
|
if (strcmp(name, c->u.name) == 0)
|
|
|
|
break;
|
|
|
|
c = c->next;
|
|
|
|
}
|
|
|
|
|
|
|
|
if (c) {
|
|
|
|
if (!c->sid[0] || !c->sid[1]) {
|
|
|
|
rc = sidtab_context_to_sid(&sidtab,
|
|
|
|
&c->context[0],
|
|
|
|
&c->sid[0]);
|
|
|
|
if (rc)
|
|
|
|
goto out;
|
|
|
|
rc = sidtab_context_to_sid(&sidtab,
|
|
|
|
&c->context[1],
|
|
|
|
&c->sid[1]);
|
|
|
|
if (rc)
|
|
|
|
goto out;
|
|
|
|
}
|
|
|
|
*if_sid = c->sid[0];
|
2008-01-29 21:38:08 +08:00
|
|
|
} else
|
2005-04-17 06:20:36 +08:00
|
|
|
*if_sid = SECINITSID_NETIF;
|
|
|
|
|
|
|
|
out:
|
2008-06-06 16:40:29 +08:00
|
|
|
read_unlock(&policy_rwlock);
|
2005-04-17 06:20:36 +08:00
|
|
|
return rc;
|
|
|
|
}
|
|
|
|
|
|
|
|
static int match_ipv6_addrmask(u32 *input, u32 *addr, u32 *mask)
|
|
|
|
{
|
|
|
|
int i, fail = 0;
|
|
|
|
|
2008-04-19 05:38:33 +08:00
|
|
|
for (i = 0; i < 4; i++)
|
|
|
|
if (addr[i] != (input[i] & mask[i])) {
|
2005-04-17 06:20:36 +08:00
|
|
|
fail = 1;
|
|
|
|
break;
|
|
|
|
}
|
|
|
|
|
|
|
|
return !fail;
|
|
|
|
}
|
|
|
|
|
|
|
|
/**
|
|
|
|
* security_node_sid - Obtain the SID for a node (host).
|
|
|
|
* @domain: communication domain aka address family
|
|
|
|
* @addrp: address
|
|
|
|
* @addrlen: address length in bytes
|
|
|
|
* @out_sid: security identifier
|
|
|
|
*/
|
|
|
|
int security_node_sid(u16 domain,
|
|
|
|
void *addrp,
|
|
|
|
u32 addrlen,
|
|
|
|
u32 *out_sid)
|
|
|
|
{
|
|
|
|
int rc = 0;
|
|
|
|
struct ocontext *c;
|
|
|
|
|
2008-06-06 16:40:29 +08:00
|
|
|
read_lock(&policy_rwlock);
|
2005-04-17 06:20:36 +08:00
|
|
|
|
|
|
|
switch (domain) {
|
|
|
|
case AF_INET: {
|
|
|
|
u32 addr;
|
|
|
|
|
|
|
|
if (addrlen != sizeof(u32)) {
|
|
|
|
rc = -EINVAL;
|
|
|
|
goto out;
|
|
|
|
}
|
|
|
|
|
|
|
|
addr = *((u32 *)addrp);
|
|
|
|
|
|
|
|
c = policydb.ocontexts[OCON_NODE];
|
|
|
|
while (c) {
|
|
|
|
if (c->u.node.addr == (addr & c->u.node.mask))
|
|
|
|
break;
|
|
|
|
c = c->next;
|
|
|
|
}
|
|
|
|
break;
|
|
|
|
}
|
|
|
|
|
|
|
|
case AF_INET6:
|
|
|
|
if (addrlen != sizeof(u64) * 2) {
|
|
|
|
rc = -EINVAL;
|
|
|
|
goto out;
|
|
|
|
}
|
|
|
|
c = policydb.ocontexts[OCON_NODE6];
|
|
|
|
while (c) {
|
|
|
|
if (match_ipv6_addrmask(addrp, c->u.node6.addr,
|
|
|
|
c->u.node6.mask))
|
|
|
|
break;
|
|
|
|
c = c->next;
|
|
|
|
}
|
|
|
|
break;
|
|
|
|
|
|
|
|
default:
|
|
|
|
*out_sid = SECINITSID_NODE;
|
|
|
|
goto out;
|
|
|
|
}
|
|
|
|
|
|
|
|
if (c) {
|
|
|
|
if (!c->sid[0]) {
|
|
|
|
rc = sidtab_context_to_sid(&sidtab,
|
|
|
|
&c->context[0],
|
|
|
|
&c->sid[0]);
|
|
|
|
if (rc)
|
|
|
|
goto out;
|
|
|
|
}
|
|
|
|
*out_sid = c->sid[0];
|
|
|
|
} else {
|
|
|
|
*out_sid = SECINITSID_NODE;
|
|
|
|
}
|
|
|
|
|
|
|
|
out:
|
2008-06-06 16:40:29 +08:00
|
|
|
read_unlock(&policy_rwlock);
|
2005-04-17 06:20:36 +08:00
|
|
|
return rc;
|
|
|
|
}
|
|
|
|
|
|
|
|
#define SIDS_NEL 25
|
|
|
|
|
|
|
|
/**
|
|
|
|
* security_get_user_sids - Obtain reachable SIDs for a user.
|
|
|
|
* @fromsid: starting SID
|
|
|
|
* @username: username
|
|
|
|
* @sids: array of reachable SIDs for user
|
|
|
|
* @nel: number of elements in @sids
|
|
|
|
*
|
|
|
|
* Generate the set of SIDs for legal security contexts
|
|
|
|
* for a given user that can be reached by @fromsid.
|
|
|
|
* Set *@sids to point to a dynamically allocated
|
|
|
|
* array containing the set of SIDs. Set *@nel to the
|
|
|
|
* number of elements in the array.
|
|
|
|
*/
|
|
|
|
|
|
|
|
int security_get_user_sids(u32 fromsid,
|
2008-04-19 05:38:33 +08:00
|
|
|
char *username,
|
2005-04-17 06:20:36 +08:00
|
|
|
u32 **sids,
|
|
|
|
u32 *nel)
|
|
|
|
{
|
|
|
|
struct context *fromcon, usercon;
|
2007-06-08 03:34:10 +08:00
|
|
|
u32 *mysids = NULL, *mysids2, sid;
|
2005-04-17 06:20:36 +08:00
|
|
|
u32 mynel = 0, maxnel = SIDS_NEL;
|
|
|
|
struct user_datum *user;
|
|
|
|
struct role_datum *role;
|
2005-09-04 06:55:16 +08:00
|
|
|
struct ebitmap_node *rnode, *tnode;
|
2005-04-17 06:20:36 +08:00
|
|
|
int rc = 0, i, j;
|
|
|
|
|
2007-06-08 03:34:10 +08:00
|
|
|
*sids = NULL;
|
|
|
|
*nel = 0;
|
|
|
|
|
|
|
|
if (!ss_initialized)
|
2005-04-17 06:20:36 +08:00
|
|
|
goto out;
|
|
|
|
|
2008-06-06 16:40:29 +08:00
|
|
|
read_lock(&policy_rwlock);
|
2005-04-17 06:20:36 +08:00
|
|
|
|
2008-05-08 01:03:20 +08:00
|
|
|
context_init(&usercon);
|
|
|
|
|
2005-04-17 06:20:36 +08:00
|
|
|
fromcon = sidtab_search(&sidtab, fromsid);
|
|
|
|
if (!fromcon) {
|
|
|
|
rc = -EINVAL;
|
|
|
|
goto out_unlock;
|
|
|
|
}
|
|
|
|
|
|
|
|
user = hashtab_search(policydb.p_users.table, username);
|
|
|
|
if (!user) {
|
|
|
|
rc = -EINVAL;
|
|
|
|
goto out_unlock;
|
|
|
|
}
|
|
|
|
usercon.user = user->value;
|
|
|
|
|
2005-10-31 06:59:21 +08:00
|
|
|
mysids = kcalloc(maxnel, sizeof(*mysids), GFP_ATOMIC);
|
2005-04-17 06:20:36 +08:00
|
|
|
if (!mysids) {
|
|
|
|
rc = -ENOMEM;
|
|
|
|
goto out_unlock;
|
|
|
|
}
|
|
|
|
|
SELinux: improve performance when AVC misses.
* We add ebitmap_for_each_positive_bit() which enables to walk on
any positive bit on the given ebitmap, to improve its performance
using common bit-operations defined in linux/bitops.h.
In the previous version, this logic was implemented using a combination
of ebitmap_for_each_bit() and ebitmap_node_get_bit(), but is was worse
in performance aspect.
This logic is most frequestly used to compute a new AVC entry,
so this patch can improve SELinux performance when AVC misses are happen.
* struct ebitmap_node is redefined as an array of "unsigned long", to get
suitable for using find_next_bit() which is fasted than iteration of
shift and logical operation, and to maximize memory usage allocated
from general purpose slab.
* Any ebitmap_for_each_bit() are repleced by the new implementation
in ss/service.c and ss/mls.c. Some of related implementation are
changed, however, there is no incompatibility with the previous
version.
* The width of any new line are less or equal than 80-chars.
The following benchmark shows the effect of this patch, when we
access many files which have different security context one after
another. The number is more than /selinux/avc/cache_threshold, so
any access always causes AVC misses.
selinux-2.6 selinux-2.6-ebitmap
AVG: 22.763 [s] 8.750 [s]
STD: 0.265 0.019
------------------------------------------
1st: 22.558 [s] 8.786 [s]
2nd: 22.458 [s] 8.750 [s]
3rd: 22.478 [s] 8.754 [s]
4th: 22.724 [s] 8.745 [s]
5th: 22.918 [s] 8.748 [s]
6th: 22.905 [s] 8.764 [s]
7th: 23.238 [s] 8.726 [s]
8th: 22.822 [s] 8.729 [s]
Signed-off-by: KaiGai Kohei <kaigai@ak.jp.nec.com>
Acked-by: Stephen Smalley <sds@tycho.nsa.gov>
Signed-off-by: James Morris <jmorris@namei.org>
2007-09-29 01:20:55 +08:00
|
|
|
ebitmap_for_each_positive_bit(&user->roles, rnode, i) {
|
2005-04-17 06:20:36 +08:00
|
|
|
role = policydb.role_val_to_struct[i];
|
2010-04-09 19:30:29 +08:00
|
|
|
usercon.role = i + 1;
|
SELinux: improve performance when AVC misses.
* We add ebitmap_for_each_positive_bit() which enables to walk on
any positive bit on the given ebitmap, to improve its performance
using common bit-operations defined in linux/bitops.h.
In the previous version, this logic was implemented using a combination
of ebitmap_for_each_bit() and ebitmap_node_get_bit(), but is was worse
in performance aspect.
This logic is most frequestly used to compute a new AVC entry,
so this patch can improve SELinux performance when AVC misses are happen.
* struct ebitmap_node is redefined as an array of "unsigned long", to get
suitable for using find_next_bit() which is fasted than iteration of
shift and logical operation, and to maximize memory usage allocated
from general purpose slab.
* Any ebitmap_for_each_bit() are repleced by the new implementation
in ss/service.c and ss/mls.c. Some of related implementation are
changed, however, there is no incompatibility with the previous
version.
* The width of any new line are less or equal than 80-chars.
The following benchmark shows the effect of this patch, when we
access many files which have different security context one after
another. The number is more than /selinux/avc/cache_threshold, so
any access always causes AVC misses.
selinux-2.6 selinux-2.6-ebitmap
AVG: 22.763 [s] 8.750 [s]
STD: 0.265 0.019
------------------------------------------
1st: 22.558 [s] 8.786 [s]
2nd: 22.458 [s] 8.750 [s]
3rd: 22.478 [s] 8.754 [s]
4th: 22.724 [s] 8.745 [s]
5th: 22.918 [s] 8.748 [s]
6th: 22.905 [s] 8.764 [s]
7th: 23.238 [s] 8.726 [s]
8th: 22.822 [s] 8.729 [s]
Signed-off-by: KaiGai Kohei <kaigai@ak.jp.nec.com>
Acked-by: Stephen Smalley <sds@tycho.nsa.gov>
Signed-off-by: James Morris <jmorris@namei.org>
2007-09-29 01:20:55 +08:00
|
|
|
ebitmap_for_each_positive_bit(&role->types, tnode, j) {
|
2010-04-09 19:30:29 +08:00
|
|
|
usercon.type = j + 1;
|
2005-04-17 06:20:36 +08:00
|
|
|
|
|
|
|
if (mls_setup_user_range(fromcon, user, &usercon))
|
|
|
|
continue;
|
|
|
|
|
|
|
|
rc = sidtab_context_to_sid(&sidtab, &usercon, &sid);
|
2007-06-08 03:34:10 +08:00
|
|
|
if (rc)
|
2005-04-17 06:20:36 +08:00
|
|
|
goto out_unlock;
|
|
|
|
if (mynel < maxnel) {
|
|
|
|
mysids[mynel++] = sid;
|
|
|
|
} else {
|
|
|
|
maxnel += SIDS_NEL;
|
2005-10-31 06:59:21 +08:00
|
|
|
mysids2 = kcalloc(maxnel, sizeof(*mysids2), GFP_ATOMIC);
|
2005-04-17 06:20:36 +08:00
|
|
|
if (!mysids2) {
|
|
|
|
rc = -ENOMEM;
|
|
|
|
goto out_unlock;
|
|
|
|
}
|
|
|
|
memcpy(mysids2, mysids, mynel * sizeof(*mysids2));
|
|
|
|
kfree(mysids);
|
|
|
|
mysids = mysids2;
|
|
|
|
mysids[mynel++] = sid;
|
|
|
|
}
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
out_unlock:
|
2008-06-06 16:40:29 +08:00
|
|
|
read_unlock(&policy_rwlock);
|
2007-06-08 03:34:10 +08:00
|
|
|
if (rc || !mynel) {
|
|
|
|
kfree(mysids);
|
|
|
|
goto out;
|
|
|
|
}
|
|
|
|
|
|
|
|
mysids2 = kcalloc(mynel, sizeof(*mysids2), GFP_KERNEL);
|
|
|
|
if (!mysids2) {
|
|
|
|
rc = -ENOMEM;
|
|
|
|
kfree(mysids);
|
|
|
|
goto out;
|
|
|
|
}
|
|
|
|
for (i = 0, j = 0; i < mynel; i++) {
|
|
|
|
rc = avc_has_perm_noaudit(fromsid, mysids[i],
|
selinux: dynamic class/perm discovery
Modify SELinux to dynamically discover class and permission values
upon policy load, based on the dynamic object class/perm discovery
logic from libselinux. A mapping is created between kernel-private
class and permission indices used outside the security server and the
policy values used within the security server.
The mappings are only applied upon kernel-internal computations;
similar mappings for the private indices of userspace object managers
is handled on a per-object manager basis by the userspace AVC. The
interfaces for compute_av and transition_sid are split for kernel
vs. userspace; the userspace functions are distinguished by a _user
suffix.
The kernel-private class indices are no longer tied to the policy
values and thus do not need to skip indices for userspace classes;
thus the kernel class index values are compressed. The flask.h
definitions were regenerated by deleting the userspace classes from
refpolicy's definitions and then regenerating the headers. Going
forward, we can just maintain the flask.h, av_permissions.h, and
classmap.h definitions separately from policy as they are no longer
tied to the policy values. The next patch introduces a utility to
automate generation of flask.h and av_permissions.h from the
classmap.h definitions.
The older kernel class and permission string tables are removed and
replaced by a single security class mapping table that is walked at
policy load to generate the mapping. The old kernel class validation
logic is completely replaced by the mapping logic.
The handle unknown logic is reworked. reject_unknown=1 is handled
when the mappings are computed at policy load time, similar to the old
handling by the class validation logic. allow_unknown=1 is handled
when computing and mapping decisions - if the permission was not able
to be mapped (i.e. undefined, mapped to zero), then it is
automatically added to the allowed vector. If the class was not able
to be mapped (i.e. undefined, mapped to zero), then all permissions
are allowed for it if allow_unknown=1.
avc_audit leverages the new security class mapping table to lookup the
class and permission names from the kernel-private indices.
The mdp program is updated to use the new table when generating the
class definitions and allow rules for a minimal boot policy for the
kernel. It should be noted that this policy will not include any
userspace classes, nor will its policy index values for the kernel
classes correspond with the ones in refpolicy (they will instead match
the kernel-private indices).
Signed-off-by: Stephen Smalley <sds@tycho.nsa.gov>
Signed-off-by: James Morris <jmorris@namei.org>
2009-10-01 01:37:50 +08:00
|
|
|
SECCLASS_PROCESS, /* kernel value */
|
2007-06-08 03:34:10 +08:00
|
|
|
PROCESS__TRANSITION, AVC_STRICT,
|
|
|
|
NULL);
|
|
|
|
if (!rc)
|
|
|
|
mysids2[j++] = mysids[i];
|
|
|
|
cond_resched();
|
|
|
|
}
|
|
|
|
rc = 0;
|
|
|
|
kfree(mysids);
|
|
|
|
*sids = mysids2;
|
|
|
|
*nel = j;
|
2005-04-17 06:20:36 +08:00
|
|
|
out:
|
|
|
|
return rc;
|
|
|
|
}
|
|
|
|
|
|
|
|
/**
|
|
|
|
* security_genfs_sid - Obtain a SID for a file in a filesystem
|
|
|
|
* @fstype: filesystem type
|
|
|
|
* @path: path from root of mount
|
|
|
|
* @sclass: file security class
|
|
|
|
* @sid: SID for path
|
|
|
|
*
|
|
|
|
* Obtain a SID to use for a file in a filesystem that
|
|
|
|
* cannot support xattr or use a fixed labeling behavior like
|
|
|
|
* transition SIDs or task SIDs.
|
|
|
|
*/
|
|
|
|
int security_genfs_sid(const char *fstype,
|
2008-04-19 05:38:33 +08:00
|
|
|
char *path,
|
selinux: dynamic class/perm discovery
Modify SELinux to dynamically discover class and permission values
upon policy load, based on the dynamic object class/perm discovery
logic from libselinux. A mapping is created between kernel-private
class and permission indices used outside the security server and the
policy values used within the security server.
The mappings are only applied upon kernel-internal computations;
similar mappings for the private indices of userspace object managers
is handled on a per-object manager basis by the userspace AVC. The
interfaces for compute_av and transition_sid are split for kernel
vs. userspace; the userspace functions are distinguished by a _user
suffix.
The kernel-private class indices are no longer tied to the policy
values and thus do not need to skip indices for userspace classes;
thus the kernel class index values are compressed. The flask.h
definitions were regenerated by deleting the userspace classes from
refpolicy's definitions and then regenerating the headers. Going
forward, we can just maintain the flask.h, av_permissions.h, and
classmap.h definitions separately from policy as they are no longer
tied to the policy values. The next patch introduces a utility to
automate generation of flask.h and av_permissions.h from the
classmap.h definitions.
The older kernel class and permission string tables are removed and
replaced by a single security class mapping table that is walked at
policy load to generate the mapping. The old kernel class validation
logic is completely replaced by the mapping logic.
The handle unknown logic is reworked. reject_unknown=1 is handled
when the mappings are computed at policy load time, similar to the old
handling by the class validation logic. allow_unknown=1 is handled
when computing and mapping decisions - if the permission was not able
to be mapped (i.e. undefined, mapped to zero), then it is
automatically added to the allowed vector. If the class was not able
to be mapped (i.e. undefined, mapped to zero), then all permissions
are allowed for it if allow_unknown=1.
avc_audit leverages the new security class mapping table to lookup the
class and permission names from the kernel-private indices.
The mdp program is updated to use the new table when generating the
class definitions and allow rules for a minimal boot policy for the
kernel. It should be noted that this policy will not include any
userspace classes, nor will its policy index values for the kernel
classes correspond with the ones in refpolicy (they will instead match
the kernel-private indices).
Signed-off-by: Stephen Smalley <sds@tycho.nsa.gov>
Signed-off-by: James Morris <jmorris@namei.org>
2009-10-01 01:37:50 +08:00
|
|
|
u16 orig_sclass,
|
2005-04-17 06:20:36 +08:00
|
|
|
u32 *sid)
|
|
|
|
{
|
|
|
|
int len;
|
selinux: dynamic class/perm discovery
Modify SELinux to dynamically discover class and permission values
upon policy load, based on the dynamic object class/perm discovery
logic from libselinux. A mapping is created between kernel-private
class and permission indices used outside the security server and the
policy values used within the security server.
The mappings are only applied upon kernel-internal computations;
similar mappings for the private indices of userspace object managers
is handled on a per-object manager basis by the userspace AVC. The
interfaces for compute_av and transition_sid are split for kernel
vs. userspace; the userspace functions are distinguished by a _user
suffix.
The kernel-private class indices are no longer tied to the policy
values and thus do not need to skip indices for userspace classes;
thus the kernel class index values are compressed. The flask.h
definitions were regenerated by deleting the userspace classes from
refpolicy's definitions and then regenerating the headers. Going
forward, we can just maintain the flask.h, av_permissions.h, and
classmap.h definitions separately from policy as they are no longer
tied to the policy values. The next patch introduces a utility to
automate generation of flask.h and av_permissions.h from the
classmap.h definitions.
The older kernel class and permission string tables are removed and
replaced by a single security class mapping table that is walked at
policy load to generate the mapping. The old kernel class validation
logic is completely replaced by the mapping logic.
The handle unknown logic is reworked. reject_unknown=1 is handled
when the mappings are computed at policy load time, similar to the old
handling by the class validation logic. allow_unknown=1 is handled
when computing and mapping decisions - if the permission was not able
to be mapped (i.e. undefined, mapped to zero), then it is
automatically added to the allowed vector. If the class was not able
to be mapped (i.e. undefined, mapped to zero), then all permissions
are allowed for it if allow_unknown=1.
avc_audit leverages the new security class mapping table to lookup the
class and permission names from the kernel-private indices.
The mdp program is updated to use the new table when generating the
class definitions and allow rules for a minimal boot policy for the
kernel. It should be noted that this policy will not include any
userspace classes, nor will its policy index values for the kernel
classes correspond with the ones in refpolicy (they will instead match
the kernel-private indices).
Signed-off-by: Stephen Smalley <sds@tycho.nsa.gov>
Signed-off-by: James Morris <jmorris@namei.org>
2009-10-01 01:37:50 +08:00
|
|
|
u16 sclass;
|
2005-04-17 06:20:36 +08:00
|
|
|
struct genfs *genfs;
|
|
|
|
struct ocontext *c;
|
|
|
|
int rc = 0, cmp = 0;
|
|
|
|
|
2008-01-26 02:03:42 +08:00
|
|
|
while (path[0] == '/' && path[1] == '/')
|
|
|
|
path++;
|
|
|
|
|
2008-06-06 16:40:29 +08:00
|
|
|
read_lock(&policy_rwlock);
|
2005-04-17 06:20:36 +08:00
|
|
|
|
selinux: dynamic class/perm discovery
Modify SELinux to dynamically discover class and permission values
upon policy load, based on the dynamic object class/perm discovery
logic from libselinux. A mapping is created between kernel-private
class and permission indices used outside the security server and the
policy values used within the security server.
The mappings are only applied upon kernel-internal computations;
similar mappings for the private indices of userspace object managers
is handled on a per-object manager basis by the userspace AVC. The
interfaces for compute_av and transition_sid are split for kernel
vs. userspace; the userspace functions are distinguished by a _user
suffix.
The kernel-private class indices are no longer tied to the policy
values and thus do not need to skip indices for userspace classes;
thus the kernel class index values are compressed. The flask.h
definitions were regenerated by deleting the userspace classes from
refpolicy's definitions and then regenerating the headers. Going
forward, we can just maintain the flask.h, av_permissions.h, and
classmap.h definitions separately from policy as they are no longer
tied to the policy values. The next patch introduces a utility to
automate generation of flask.h and av_permissions.h from the
classmap.h definitions.
The older kernel class and permission string tables are removed and
replaced by a single security class mapping table that is walked at
policy load to generate the mapping. The old kernel class validation
logic is completely replaced by the mapping logic.
The handle unknown logic is reworked. reject_unknown=1 is handled
when the mappings are computed at policy load time, similar to the old
handling by the class validation logic. allow_unknown=1 is handled
when computing and mapping decisions - if the permission was not able
to be mapped (i.e. undefined, mapped to zero), then it is
automatically added to the allowed vector. If the class was not able
to be mapped (i.e. undefined, mapped to zero), then all permissions
are allowed for it if allow_unknown=1.
avc_audit leverages the new security class mapping table to lookup the
class and permission names from the kernel-private indices.
The mdp program is updated to use the new table when generating the
class definitions and allow rules for a minimal boot policy for the
kernel. It should be noted that this policy will not include any
userspace classes, nor will its policy index values for the kernel
classes correspond with the ones in refpolicy (they will instead match
the kernel-private indices).
Signed-off-by: Stephen Smalley <sds@tycho.nsa.gov>
Signed-off-by: James Morris <jmorris@namei.org>
2009-10-01 01:37:50 +08:00
|
|
|
sclass = unmap_class(orig_sclass);
|
|
|
|
|
2005-04-17 06:20:36 +08:00
|
|
|
for (genfs = policydb.genfs; genfs; genfs = genfs->next) {
|
|
|
|
cmp = strcmp(fstype, genfs->fstype);
|
|
|
|
if (cmp <= 0)
|
|
|
|
break;
|
|
|
|
}
|
|
|
|
|
|
|
|
if (!genfs || cmp) {
|
|
|
|
*sid = SECINITSID_UNLABELED;
|
|
|
|
rc = -ENOENT;
|
|
|
|
goto out;
|
|
|
|
}
|
|
|
|
|
|
|
|
for (c = genfs->head; c; c = c->next) {
|
|
|
|
len = strlen(c->u.name);
|
|
|
|
if ((!c->v.sclass || sclass == c->v.sclass) &&
|
|
|
|
(strncmp(c->u.name, path, len) == 0))
|
|
|
|
break;
|
|
|
|
}
|
|
|
|
|
|
|
|
if (!c) {
|
|
|
|
*sid = SECINITSID_UNLABELED;
|
|
|
|
rc = -ENOENT;
|
|
|
|
goto out;
|
|
|
|
}
|
|
|
|
|
|
|
|
if (!c->sid[0]) {
|
|
|
|
rc = sidtab_context_to_sid(&sidtab,
|
|
|
|
&c->context[0],
|
|
|
|
&c->sid[0]);
|
|
|
|
if (rc)
|
|
|
|
goto out;
|
|
|
|
}
|
|
|
|
|
|
|
|
*sid = c->sid[0];
|
|
|
|
out:
|
2008-06-06 16:40:29 +08:00
|
|
|
read_unlock(&policy_rwlock);
|
2005-04-17 06:20:36 +08:00
|
|
|
return rc;
|
|
|
|
}
|
|
|
|
|
|
|
|
/**
|
|
|
|
* security_fs_use - Determine how to handle labeling for a filesystem.
|
|
|
|
* @fstype: filesystem type
|
|
|
|
* @behavior: labeling behavior
|
|
|
|
* @sid: SID for filesystem (superblock)
|
|
|
|
*/
|
|
|
|
int security_fs_use(
|
|
|
|
const char *fstype,
|
|
|
|
unsigned int *behavior,
|
2008-07-15 16:32:49 +08:00
|
|
|
u32 *sid)
|
2005-04-17 06:20:36 +08:00
|
|
|
{
|
|
|
|
int rc = 0;
|
|
|
|
struct ocontext *c;
|
|
|
|
|
2008-06-06 16:40:29 +08:00
|
|
|
read_lock(&policy_rwlock);
|
2005-04-17 06:20:36 +08:00
|
|
|
|
|
|
|
c = policydb.ocontexts[OCON_FSUSE];
|
|
|
|
while (c) {
|
|
|
|
if (strcmp(fstype, c->u.name) == 0)
|
|
|
|
break;
|
|
|
|
c = c->next;
|
|
|
|
}
|
|
|
|
|
|
|
|
if (c) {
|
|
|
|
*behavior = c->v.behavior;
|
|
|
|
if (!c->sid[0]) {
|
|
|
|
rc = sidtab_context_to_sid(&sidtab,
|
|
|
|
&c->context[0],
|
|
|
|
&c->sid[0]);
|
|
|
|
if (rc)
|
|
|
|
goto out;
|
|
|
|
}
|
|
|
|
*sid = c->sid[0];
|
|
|
|
} else {
|
2008-07-15 16:32:49 +08:00
|
|
|
rc = security_genfs_sid(fstype, "/", SECCLASS_DIR, sid);
|
|
|
|
if (rc) {
|
|
|
|
*behavior = SECURITY_FS_USE_NONE;
|
|
|
|
rc = 0;
|
|
|
|
} else {
|
|
|
|
*behavior = SECURITY_FS_USE_GENFS;
|
|
|
|
}
|
2005-04-17 06:20:36 +08:00
|
|
|
}
|
|
|
|
|
|
|
|
out:
|
2008-06-06 16:40:29 +08:00
|
|
|
read_unlock(&policy_rwlock);
|
2005-04-17 06:20:36 +08:00
|
|
|
return rc;
|
|
|
|
}
|
|
|
|
|
|
|
|
int security_get_bools(int *len, char ***names, int **values)
|
|
|
|
{
|
|
|
|
int i, rc = -ENOMEM;
|
|
|
|
|
2008-06-06 16:40:29 +08:00
|
|
|
read_lock(&policy_rwlock);
|
2005-04-17 06:20:36 +08:00
|
|
|
*names = NULL;
|
|
|
|
*values = NULL;
|
|
|
|
|
|
|
|
*len = policydb.p_bools.nprim;
|
|
|
|
if (!*len) {
|
|
|
|
rc = 0;
|
|
|
|
goto out;
|
|
|
|
}
|
|
|
|
|
2008-04-19 05:38:33 +08:00
|
|
|
*names = kcalloc(*len, sizeof(char *), GFP_ATOMIC);
|
2005-04-17 06:20:36 +08:00
|
|
|
if (!*names)
|
|
|
|
goto err;
|
|
|
|
|
2006-01-10 12:54:46 +08:00
|
|
|
*values = kcalloc(*len, sizeof(int), GFP_ATOMIC);
|
2005-04-17 06:20:36 +08:00
|
|
|
if (!*values)
|
|
|
|
goto err;
|
|
|
|
|
|
|
|
for (i = 0; i < *len; i++) {
|
|
|
|
size_t name_len;
|
|
|
|
(*values)[i] = policydb.bool_val_to_struct[i]->state;
|
|
|
|
name_len = strlen(policydb.p_bool_val_to_name[i]) + 1;
|
2008-04-19 05:38:33 +08:00
|
|
|
(*names)[i] = kmalloc(sizeof(char) * name_len, GFP_ATOMIC);
|
2005-04-17 06:20:36 +08:00
|
|
|
if (!(*names)[i])
|
|
|
|
goto err;
|
|
|
|
strncpy((*names)[i], policydb.p_bool_val_to_name[i], name_len);
|
|
|
|
(*names)[i][name_len - 1] = 0;
|
|
|
|
}
|
|
|
|
rc = 0;
|
|
|
|
out:
|
2008-06-06 16:40:29 +08:00
|
|
|
read_unlock(&policy_rwlock);
|
2005-04-17 06:20:36 +08:00
|
|
|
return rc;
|
|
|
|
err:
|
|
|
|
if (*names) {
|
|
|
|
for (i = 0; i < *len; i++)
|
2005-06-26 05:58:51 +08:00
|
|
|
kfree((*names)[i]);
|
2005-04-17 06:20:36 +08:00
|
|
|
}
|
2005-06-26 05:58:51 +08:00
|
|
|
kfree(*values);
|
2005-04-17 06:20:36 +08:00
|
|
|
goto out;
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
|
|
int security_set_bools(int len, int *values)
|
|
|
|
{
|
|
|
|
int i, rc = 0;
|
|
|
|
int lenp, seqno = 0;
|
|
|
|
struct cond_node *cur;
|
|
|
|
|
2008-06-06 16:40:29 +08:00
|
|
|
write_lock_irq(&policy_rwlock);
|
2005-04-17 06:20:36 +08:00
|
|
|
|
|
|
|
lenp = policydb.p_bools.nprim;
|
|
|
|
if (len != lenp) {
|
|
|
|
rc = -EFAULT;
|
|
|
|
goto out;
|
|
|
|
}
|
|
|
|
|
|
|
|
for (i = 0; i < len; i++) {
|
2006-01-04 22:08:39 +08:00
|
|
|
if (!!values[i] != policydb.bool_val_to_struct[i]->state) {
|
|
|
|
audit_log(current->audit_context, GFP_ATOMIC,
|
|
|
|
AUDIT_MAC_CONFIG_CHANGE,
|
2008-01-08 23:06:53 +08:00
|
|
|
"bool=%s val=%d old_val=%d auid=%u ses=%u",
|
2006-01-04 22:08:39 +08:00
|
|
|
policydb.p_bool_val_to_name[i],
|
|
|
|
!!values[i],
|
|
|
|
policydb.bool_val_to_struct[i]->state,
|
2008-01-08 23:06:53 +08:00
|
|
|
audit_get_loginuid(current),
|
|
|
|
audit_get_sessionid(current));
|
2006-01-04 22:08:39 +08:00
|
|
|
}
|
2008-04-19 05:38:33 +08:00
|
|
|
if (values[i])
|
2005-04-17 06:20:36 +08:00
|
|
|
policydb.bool_val_to_struct[i]->state = 1;
|
2008-04-19 05:38:33 +08:00
|
|
|
else
|
2005-04-17 06:20:36 +08:00
|
|
|
policydb.bool_val_to_struct[i]->state = 0;
|
|
|
|
}
|
|
|
|
|
2008-08-07 08:18:20 +08:00
|
|
|
for (cur = policydb.cond_list; cur; cur = cur->next) {
|
2005-04-17 06:20:36 +08:00
|
|
|
rc = evaluate_cond_node(&policydb, cur);
|
|
|
|
if (rc)
|
|
|
|
goto out;
|
|
|
|
}
|
|
|
|
|
|
|
|
seqno = ++latest_granting;
|
|
|
|
|
|
|
|
out:
|
2008-06-06 16:40:29 +08:00
|
|
|
write_unlock_irq(&policy_rwlock);
|
2005-04-17 06:20:36 +08:00
|
|
|
if (!rc) {
|
|
|
|
avc_ss_reset(seqno);
|
|
|
|
selnl_notify_policyload(seqno);
|
2007-01-27 11:03:48 +08:00
|
|
|
selinux_xfrm_notify_policyload();
|
2005-04-17 06:20:36 +08:00
|
|
|
}
|
|
|
|
return rc;
|
|
|
|
}
|
|
|
|
|
|
|
|
int security_get_bool_value(int bool)
|
|
|
|
{
|
|
|
|
int rc = 0;
|
|
|
|
int len;
|
|
|
|
|
2008-06-06 16:40:29 +08:00
|
|
|
read_lock(&policy_rwlock);
|
2005-04-17 06:20:36 +08:00
|
|
|
|
|
|
|
len = policydb.p_bools.nprim;
|
|
|
|
if (bool >= len) {
|
|
|
|
rc = -EFAULT;
|
|
|
|
goto out;
|
|
|
|
}
|
|
|
|
|
|
|
|
rc = policydb.bool_val_to_struct[bool]->state;
|
|
|
|
out:
|
2008-06-06 16:40:29 +08:00
|
|
|
read_unlock(&policy_rwlock);
|
2005-04-17 06:20:36 +08:00
|
|
|
return rc;
|
|
|
|
}
|
2006-02-25 05:44:05 +08:00
|
|
|
|
2007-04-20 02:16:19 +08:00
|
|
|
static int security_preserve_bools(struct policydb *p)
|
|
|
|
{
|
|
|
|
int rc, nbools = 0, *bvalues = NULL, i;
|
|
|
|
char **bnames = NULL;
|
|
|
|
struct cond_bool_datum *booldatum;
|
|
|
|
struct cond_node *cur;
|
|
|
|
|
|
|
|
rc = security_get_bools(&nbools, &bnames, &bvalues);
|
|
|
|
if (rc)
|
|
|
|
goto out;
|
|
|
|
for (i = 0; i < nbools; i++) {
|
|
|
|
booldatum = hashtab_search(p->p_bools.table, bnames[i]);
|
|
|
|
if (booldatum)
|
|
|
|
booldatum->state = bvalues[i];
|
|
|
|
}
|
2008-08-07 08:18:20 +08:00
|
|
|
for (cur = p->cond_list; cur; cur = cur->next) {
|
2007-04-20 02:16:19 +08:00
|
|
|
rc = evaluate_cond_node(p, cur);
|
|
|
|
if (rc)
|
|
|
|
goto out;
|
|
|
|
}
|
|
|
|
|
|
|
|
out:
|
|
|
|
if (bnames) {
|
|
|
|
for (i = 0; i < nbools; i++)
|
|
|
|
kfree(bnames[i]);
|
|
|
|
}
|
|
|
|
kfree(bnames);
|
|
|
|
kfree(bvalues);
|
|
|
|
return rc;
|
|
|
|
}
|
|
|
|
|
2006-07-25 14:27:16 +08:00
|
|
|
/*
|
|
|
|
* security_sid_mls_copy() - computes a new sid based on the given
|
|
|
|
* sid and the mls portion of mls_sid.
|
|
|
|
*/
|
|
|
|
int security_sid_mls_copy(u32 sid, u32 mls_sid, u32 *new_sid)
|
|
|
|
{
|
|
|
|
struct context *context1;
|
|
|
|
struct context *context2;
|
|
|
|
struct context newcon;
|
|
|
|
char *s;
|
|
|
|
u32 len;
|
|
|
|
int rc = 0;
|
|
|
|
|
2010-02-03 23:40:20 +08:00
|
|
|
if (!ss_initialized || !policydb.mls_enabled) {
|
2006-07-25 14:27:16 +08:00
|
|
|
*new_sid = sid;
|
|
|
|
goto out;
|
|
|
|
}
|
|
|
|
|
|
|
|
context_init(&newcon);
|
|
|
|
|
2008-06-06 16:40:29 +08:00
|
|
|
read_lock(&policy_rwlock);
|
2006-07-25 14:27:16 +08:00
|
|
|
context1 = sidtab_search(&sidtab, sid);
|
|
|
|
if (!context1) {
|
2008-04-17 23:52:44 +08:00
|
|
|
printk(KERN_ERR "SELinux: %s: unrecognized SID %d\n",
|
|
|
|
__func__, sid);
|
2006-07-25 14:27:16 +08:00
|
|
|
rc = -EINVAL;
|
|
|
|
goto out_unlock;
|
|
|
|
}
|
|
|
|
|
|
|
|
context2 = sidtab_search(&sidtab, mls_sid);
|
|
|
|
if (!context2) {
|
2008-04-17 23:52:44 +08:00
|
|
|
printk(KERN_ERR "SELinux: %s: unrecognized SID %d\n",
|
|
|
|
__func__, mls_sid);
|
2006-07-25 14:27:16 +08:00
|
|
|
rc = -EINVAL;
|
|
|
|
goto out_unlock;
|
|
|
|
}
|
|
|
|
|
|
|
|
newcon.user = context1->user;
|
|
|
|
newcon.role = context1->role;
|
|
|
|
newcon.type = context1->type;
|
2006-12-13 03:02:41 +08:00
|
|
|
rc = mls_context_cpy(&newcon, context2);
|
2006-07-25 14:27:16 +08:00
|
|
|
if (rc)
|
|
|
|
goto out_unlock;
|
|
|
|
|
|
|
|
/* Check the validity of the new context. */
|
|
|
|
if (!policydb_context_isvalid(&policydb, &newcon)) {
|
|
|
|
rc = convert_context_handle_invalid_context(&newcon);
|
|
|
|
if (rc)
|
|
|
|
goto bad;
|
|
|
|
}
|
|
|
|
|
|
|
|
rc = sidtab_context_to_sid(&sidtab, &newcon, new_sid);
|
|
|
|
goto out_unlock;
|
|
|
|
|
|
|
|
bad:
|
|
|
|
if (!context_struct_to_string(&newcon, &s, &len)) {
|
|
|
|
audit_log(current->audit_context, GFP_ATOMIC, AUDIT_SELINUX_ERR,
|
|
|
|
"security_sid_mls_copy: invalid context %s", s);
|
|
|
|
kfree(s);
|
|
|
|
}
|
|
|
|
|
|
|
|
out_unlock:
|
2008-06-06 16:40:29 +08:00
|
|
|
read_unlock(&policy_rwlock);
|
2006-07-25 14:27:16 +08:00
|
|
|
context_destroy(&newcon);
|
|
|
|
out:
|
|
|
|
return rc;
|
|
|
|
}
|
|
|
|
|
2008-01-29 21:38:23 +08:00
|
|
|
/**
|
|
|
|
* security_net_peersid_resolve - Compare and resolve two network peer SIDs
|
|
|
|
* @nlbl_sid: NetLabel SID
|
|
|
|
* @nlbl_type: NetLabel labeling protocol type
|
|
|
|
* @xfrm_sid: XFRM SID
|
|
|
|
*
|
|
|
|
* Description:
|
|
|
|
* Compare the @nlbl_sid and @xfrm_sid values and if the two SIDs can be
|
|
|
|
* resolved into a single SID it is returned via @peer_sid and the function
|
|
|
|
* returns zero. Otherwise @peer_sid is set to SECSID_NULL and the function
|
|
|
|
* returns a negative value. A table summarizing the behavior is below:
|
|
|
|
*
|
|
|
|
* | function return | @sid
|
|
|
|
* ------------------------------+-----------------+-----------------
|
|
|
|
* no peer labels | 0 | SECSID_NULL
|
|
|
|
* single peer label | 0 | <peer_label>
|
|
|
|
* multiple, consistent labels | 0 | <peer_label>
|
|
|
|
* multiple, inconsistent labels | -<errno> | SECSID_NULL
|
|
|
|
*
|
|
|
|
*/
|
|
|
|
int security_net_peersid_resolve(u32 nlbl_sid, u32 nlbl_type,
|
|
|
|
u32 xfrm_sid,
|
|
|
|
u32 *peer_sid)
|
|
|
|
{
|
|
|
|
int rc;
|
|
|
|
struct context *nlbl_ctx;
|
|
|
|
struct context *xfrm_ctx;
|
|
|
|
|
|
|
|
/* handle the common (which also happens to be the set of easy) cases
|
|
|
|
* right away, these two if statements catch everything involving a
|
|
|
|
* single or absent peer SID/label */
|
|
|
|
if (xfrm_sid == SECSID_NULL) {
|
|
|
|
*peer_sid = nlbl_sid;
|
|
|
|
return 0;
|
|
|
|
}
|
|
|
|
/* NOTE: an nlbl_type == NETLBL_NLTYPE_UNLABELED is a "fallback" label
|
|
|
|
* and is treated as if nlbl_sid == SECSID_NULL when a XFRM SID/label
|
|
|
|
* is present */
|
|
|
|
if (nlbl_sid == SECSID_NULL || nlbl_type == NETLBL_NLTYPE_UNLABELED) {
|
|
|
|
*peer_sid = xfrm_sid;
|
|
|
|
return 0;
|
|
|
|
}
|
|
|
|
|
|
|
|
/* we don't need to check ss_initialized here since the only way both
|
|
|
|
* nlbl_sid and xfrm_sid are not equal to SECSID_NULL would be if the
|
|
|
|
* security server was initialized and ss_initialized was true */
|
2010-02-03 23:40:20 +08:00
|
|
|
if (!policydb.mls_enabled) {
|
2008-01-29 21:38:23 +08:00
|
|
|
*peer_sid = SECSID_NULL;
|
|
|
|
return 0;
|
|
|
|
}
|
|
|
|
|
2008-06-06 16:40:29 +08:00
|
|
|
read_lock(&policy_rwlock);
|
2008-01-29 21:38:23 +08:00
|
|
|
|
|
|
|
nlbl_ctx = sidtab_search(&sidtab, nlbl_sid);
|
|
|
|
if (!nlbl_ctx) {
|
2008-04-17 23:52:44 +08:00
|
|
|
printk(KERN_ERR "SELinux: %s: unrecognized SID %d\n",
|
|
|
|
__func__, nlbl_sid);
|
2008-01-29 21:38:23 +08:00
|
|
|
rc = -EINVAL;
|
|
|
|
goto out_slowpath;
|
|
|
|
}
|
|
|
|
xfrm_ctx = sidtab_search(&sidtab, xfrm_sid);
|
|
|
|
if (!xfrm_ctx) {
|
2008-04-17 23:52:44 +08:00
|
|
|
printk(KERN_ERR "SELinux: %s: unrecognized SID %d\n",
|
|
|
|
__func__, xfrm_sid);
|
2008-01-29 21:38:23 +08:00
|
|
|
rc = -EINVAL;
|
|
|
|
goto out_slowpath;
|
|
|
|
}
|
|
|
|
rc = (mls_context_cmp(nlbl_ctx, xfrm_ctx) ? 0 : -EACCES);
|
|
|
|
|
|
|
|
out_slowpath:
|
2008-06-06 16:40:29 +08:00
|
|
|
read_unlock(&policy_rwlock);
|
2008-01-29 21:38:23 +08:00
|
|
|
if (rc == 0)
|
|
|
|
/* at present NetLabel SIDs/labels really only carry MLS
|
|
|
|
* information so if the MLS portion of the NetLabel SID
|
|
|
|
* matches the MLS portion of the labeled XFRM SID/label
|
|
|
|
* then pass along the XFRM SID as it is the most
|
|
|
|
* expressive */
|
|
|
|
*peer_sid = xfrm_sid;
|
|
|
|
else
|
|
|
|
*peer_sid = SECSID_NULL;
|
|
|
|
return rc;
|
|
|
|
}
|
|
|
|
|
2007-05-23 21:12:06 +08:00
|
|
|
static int get_classes_callback(void *k, void *d, void *args)
|
|
|
|
{
|
|
|
|
struct class_datum *datum = d;
|
|
|
|
char *name = k, **classes = args;
|
|
|
|
int value = datum->value - 1;
|
|
|
|
|
|
|
|
classes[value] = kstrdup(name, GFP_ATOMIC);
|
|
|
|
if (!classes[value])
|
|
|
|
return -ENOMEM;
|
|
|
|
|
|
|
|
return 0;
|
|
|
|
}
|
|
|
|
|
|
|
|
int security_get_classes(char ***classes, int *nclasses)
|
|
|
|
{
|
|
|
|
int rc = -ENOMEM;
|
|
|
|
|
2008-06-06 16:40:29 +08:00
|
|
|
read_lock(&policy_rwlock);
|
2007-05-23 21:12:06 +08:00
|
|
|
|
|
|
|
*nclasses = policydb.p_classes.nprim;
|
2009-12-06 17:16:51 +08:00
|
|
|
*classes = kcalloc(*nclasses, sizeof(**classes), GFP_ATOMIC);
|
2007-05-23 21:12:06 +08:00
|
|
|
if (!*classes)
|
|
|
|
goto out;
|
|
|
|
|
|
|
|
rc = hashtab_map(policydb.p_classes.table, get_classes_callback,
|
|
|
|
*classes);
|
|
|
|
if (rc < 0) {
|
|
|
|
int i;
|
|
|
|
for (i = 0; i < *nclasses; i++)
|
|
|
|
kfree((*classes)[i]);
|
|
|
|
kfree(*classes);
|
|
|
|
}
|
|
|
|
|
|
|
|
out:
|
2008-06-06 16:40:29 +08:00
|
|
|
read_unlock(&policy_rwlock);
|
2007-05-23 21:12:06 +08:00
|
|
|
return rc;
|
|
|
|
}
|
|
|
|
|
|
|
|
static int get_permissions_callback(void *k, void *d, void *args)
|
|
|
|
{
|
|
|
|
struct perm_datum *datum = d;
|
|
|
|
char *name = k, **perms = args;
|
|
|
|
int value = datum->value - 1;
|
|
|
|
|
|
|
|
perms[value] = kstrdup(name, GFP_ATOMIC);
|
|
|
|
if (!perms[value])
|
|
|
|
return -ENOMEM;
|
|
|
|
|
|
|
|
return 0;
|
|
|
|
}
|
|
|
|
|
|
|
|
int security_get_permissions(char *class, char ***perms, int *nperms)
|
|
|
|
{
|
|
|
|
int rc = -ENOMEM, i;
|
|
|
|
struct class_datum *match;
|
|
|
|
|
2008-06-06 16:40:29 +08:00
|
|
|
read_lock(&policy_rwlock);
|
2007-05-23 21:12:06 +08:00
|
|
|
|
|
|
|
match = hashtab_search(policydb.p_classes.table, class);
|
|
|
|
if (!match) {
|
2008-04-17 23:52:44 +08:00
|
|
|
printk(KERN_ERR "SELinux: %s: unrecognized class %s\n",
|
2008-03-06 07:03:59 +08:00
|
|
|
__func__, class);
|
2007-05-23 21:12:06 +08:00
|
|
|
rc = -EINVAL;
|
|
|
|
goto out;
|
|
|
|
}
|
|
|
|
|
|
|
|
*nperms = match->permissions.nprim;
|
2009-12-06 17:16:51 +08:00
|
|
|
*perms = kcalloc(*nperms, sizeof(**perms), GFP_ATOMIC);
|
2007-05-23 21:12:06 +08:00
|
|
|
if (!*perms)
|
|
|
|
goto out;
|
|
|
|
|
|
|
|
if (match->comdatum) {
|
|
|
|
rc = hashtab_map(match->comdatum->permissions.table,
|
|
|
|
get_permissions_callback, *perms);
|
|
|
|
if (rc < 0)
|
|
|
|
goto err;
|
|
|
|
}
|
|
|
|
|
|
|
|
rc = hashtab_map(match->permissions.table, get_permissions_callback,
|
|
|
|
*perms);
|
|
|
|
if (rc < 0)
|
|
|
|
goto err;
|
|
|
|
|
|
|
|
out:
|
2008-06-06 16:40:29 +08:00
|
|
|
read_unlock(&policy_rwlock);
|
2007-05-23 21:12:06 +08:00
|
|
|
return rc;
|
|
|
|
|
|
|
|
err:
|
2008-06-06 16:40:29 +08:00
|
|
|
read_unlock(&policy_rwlock);
|
2007-05-23 21:12:06 +08:00
|
|
|
for (i = 0; i < *nperms; i++)
|
|
|
|
kfree((*perms)[i]);
|
|
|
|
kfree(*perms);
|
|
|
|
return rc;
|
|
|
|
}
|
|
|
|
|
2007-09-22 02:37:10 +08:00
|
|
|
int security_get_reject_unknown(void)
|
|
|
|
{
|
|
|
|
return policydb.reject_unknown;
|
|
|
|
}
|
|
|
|
|
|
|
|
int security_get_allow_unknown(void)
|
|
|
|
{
|
|
|
|
return policydb.allow_unknown;
|
|
|
|
}
|
|
|
|
|
2008-01-29 21:38:19 +08:00
|
|
|
/**
|
|
|
|
* security_policycap_supported - Check for a specific policy capability
|
|
|
|
* @req_cap: capability
|
|
|
|
*
|
|
|
|
* Description:
|
|
|
|
* This function queries the currently loaded policy to see if it supports the
|
|
|
|
* capability specified by @req_cap. Returns true (1) if the capability is
|
|
|
|
* supported, false (0) if it isn't supported.
|
|
|
|
*
|
|
|
|
*/
|
|
|
|
int security_policycap_supported(unsigned int req_cap)
|
|
|
|
{
|
|
|
|
int rc;
|
|
|
|
|
2008-06-06 16:40:29 +08:00
|
|
|
read_lock(&policy_rwlock);
|
2008-01-29 21:38:19 +08:00
|
|
|
rc = ebitmap_get_bit(&policydb.policycaps, req_cap);
|
2008-06-06 16:40:29 +08:00
|
|
|
read_unlock(&policy_rwlock);
|
2008-01-29 21:38:19 +08:00
|
|
|
|
|
|
|
return rc;
|
|
|
|
}
|
|
|
|
|
2006-02-25 05:44:05 +08:00
|
|
|
struct selinux_audit_rule {
|
|
|
|
u32 au_seqno;
|
|
|
|
struct context au_ctxt;
|
|
|
|
};
|
|
|
|
|
2008-03-02 04:03:14 +08:00
|
|
|
void selinux_audit_rule_free(void *vrule)
|
2006-02-25 05:44:05 +08:00
|
|
|
{
|
2008-03-02 04:03:14 +08:00
|
|
|
struct selinux_audit_rule *rule = vrule;
|
|
|
|
|
2006-02-25 05:44:05 +08:00
|
|
|
if (rule) {
|
|
|
|
context_destroy(&rule->au_ctxt);
|
|
|
|
kfree(rule);
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2008-03-02 04:03:14 +08:00
|
|
|
int selinux_audit_rule_init(u32 field, u32 op, char *rulestr, void **vrule)
|
2006-02-25 05:44:05 +08:00
|
|
|
{
|
|
|
|
struct selinux_audit_rule *tmprule;
|
|
|
|
struct role_datum *roledatum;
|
|
|
|
struct type_datum *typedatum;
|
|
|
|
struct user_datum *userdatum;
|
2008-03-02 04:03:14 +08:00
|
|
|
struct selinux_audit_rule **rule = (struct selinux_audit_rule **)vrule;
|
2006-02-25 05:44:05 +08:00
|
|
|
int rc = 0;
|
|
|
|
|
|
|
|
*rule = NULL;
|
|
|
|
|
|
|
|
if (!ss_initialized)
|
2007-08-15 03:50:46 +08:00
|
|
|
return -EOPNOTSUPP;
|
2006-02-25 05:44:05 +08:00
|
|
|
|
|
|
|
switch (field) {
|
2006-06-30 05:56:39 +08:00
|
|
|
case AUDIT_SUBJ_USER:
|
|
|
|
case AUDIT_SUBJ_ROLE:
|
|
|
|
case AUDIT_SUBJ_TYPE:
|
2006-06-30 05:57:08 +08:00
|
|
|
case AUDIT_OBJ_USER:
|
|
|
|
case AUDIT_OBJ_ROLE:
|
|
|
|
case AUDIT_OBJ_TYPE:
|
2006-02-25 05:44:05 +08:00
|
|
|
/* only 'equals' and 'not equals' fit user, role, and type */
|
2008-12-16 18:59:26 +08:00
|
|
|
if (op != Audit_equal && op != Audit_not_equal)
|
2006-02-25 05:44:05 +08:00
|
|
|
return -EINVAL;
|
|
|
|
break;
|
2006-06-30 05:56:39 +08:00
|
|
|
case AUDIT_SUBJ_SEN:
|
|
|
|
case AUDIT_SUBJ_CLR:
|
2006-06-30 05:57:08 +08:00
|
|
|
case AUDIT_OBJ_LEV_LOW:
|
|
|
|
case AUDIT_OBJ_LEV_HIGH:
|
2006-02-25 05:44:05 +08:00
|
|
|
/* we do not allow a range, indicated by the presense of '-' */
|
|
|
|
if (strchr(rulestr, '-'))
|
|
|
|
return -EINVAL;
|
|
|
|
break;
|
|
|
|
default:
|
|
|
|
/* only the above fields are valid */
|
|
|
|
return -EINVAL;
|
|
|
|
}
|
|
|
|
|
|
|
|
tmprule = kzalloc(sizeof(struct selinux_audit_rule), GFP_KERNEL);
|
|
|
|
if (!tmprule)
|
|
|
|
return -ENOMEM;
|
|
|
|
|
|
|
|
context_init(&tmprule->au_ctxt);
|
|
|
|
|
2008-06-06 16:40:29 +08:00
|
|
|
read_lock(&policy_rwlock);
|
2006-02-25 05:44:05 +08:00
|
|
|
|
|
|
|
tmprule->au_seqno = latest_granting;
|
|
|
|
|
|
|
|
switch (field) {
|
2006-06-30 05:56:39 +08:00
|
|
|
case AUDIT_SUBJ_USER:
|
2006-06-30 05:57:08 +08:00
|
|
|
case AUDIT_OBJ_USER:
|
2006-02-25 05:44:05 +08:00
|
|
|
userdatum = hashtab_search(policydb.p_users.table, rulestr);
|
|
|
|
if (!userdatum)
|
|
|
|
rc = -EINVAL;
|
|
|
|
else
|
|
|
|
tmprule->au_ctxt.user = userdatum->value;
|
|
|
|
break;
|
2006-06-30 05:56:39 +08:00
|
|
|
case AUDIT_SUBJ_ROLE:
|
2006-06-30 05:57:08 +08:00
|
|
|
case AUDIT_OBJ_ROLE:
|
2006-02-25 05:44:05 +08:00
|
|
|
roledatum = hashtab_search(policydb.p_roles.table, rulestr);
|
|
|
|
if (!roledatum)
|
|
|
|
rc = -EINVAL;
|
|
|
|
else
|
|
|
|
tmprule->au_ctxt.role = roledatum->value;
|
|
|
|
break;
|
2006-06-30 05:56:39 +08:00
|
|
|
case AUDIT_SUBJ_TYPE:
|
2006-06-30 05:57:08 +08:00
|
|
|
case AUDIT_OBJ_TYPE:
|
2006-02-25 05:44:05 +08:00
|
|
|
typedatum = hashtab_search(policydb.p_types.table, rulestr);
|
|
|
|
if (!typedatum)
|
|
|
|
rc = -EINVAL;
|
|
|
|
else
|
|
|
|
tmprule->au_ctxt.type = typedatum->value;
|
|
|
|
break;
|
2006-06-30 05:56:39 +08:00
|
|
|
case AUDIT_SUBJ_SEN:
|
|
|
|
case AUDIT_SUBJ_CLR:
|
2006-06-30 05:57:08 +08:00
|
|
|
case AUDIT_OBJ_LEV_LOW:
|
|
|
|
case AUDIT_OBJ_LEV_HIGH:
|
2006-02-25 05:44:05 +08:00
|
|
|
rc = mls_from_string(rulestr, &tmprule->au_ctxt, GFP_ATOMIC);
|
|
|
|
break;
|
|
|
|
}
|
|
|
|
|
2008-06-06 16:40:29 +08:00
|
|
|
read_unlock(&policy_rwlock);
|
2006-02-25 05:44:05 +08:00
|
|
|
|
|
|
|
if (rc) {
|
|
|
|
selinux_audit_rule_free(tmprule);
|
|
|
|
tmprule = NULL;
|
|
|
|
}
|
|
|
|
|
|
|
|
*rule = tmprule;
|
|
|
|
|
|
|
|
return rc;
|
|
|
|
}
|
|
|
|
|
2008-03-02 04:03:14 +08:00
|
|
|
/* Check to see if the rule contains any selinux fields */
|
|
|
|
int selinux_audit_rule_known(struct audit_krule *rule)
|
|
|
|
{
|
|
|
|
int i;
|
|
|
|
|
|
|
|
for (i = 0; i < rule->field_count; i++) {
|
|
|
|
struct audit_field *f = &rule->fields[i];
|
|
|
|
switch (f->type) {
|
|
|
|
case AUDIT_SUBJ_USER:
|
|
|
|
case AUDIT_SUBJ_ROLE:
|
|
|
|
case AUDIT_SUBJ_TYPE:
|
|
|
|
case AUDIT_SUBJ_SEN:
|
|
|
|
case AUDIT_SUBJ_CLR:
|
|
|
|
case AUDIT_OBJ_USER:
|
|
|
|
case AUDIT_OBJ_ROLE:
|
|
|
|
case AUDIT_OBJ_TYPE:
|
|
|
|
case AUDIT_OBJ_LEV_LOW:
|
|
|
|
case AUDIT_OBJ_LEV_HIGH:
|
|
|
|
return 1;
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
return 0;
|
|
|
|
}
|
|
|
|
|
|
|
|
int selinux_audit_rule_match(u32 sid, u32 field, u32 op, void *vrule,
|
2008-05-14 23:27:45 +08:00
|
|
|
struct audit_context *actx)
|
2006-02-25 05:44:05 +08:00
|
|
|
{
|
|
|
|
struct context *ctxt;
|
|
|
|
struct mls_level *level;
|
2008-03-02 04:03:14 +08:00
|
|
|
struct selinux_audit_rule *rule = vrule;
|
2006-02-25 05:44:05 +08:00
|
|
|
int match = 0;
|
|
|
|
|
|
|
|
if (!rule) {
|
|
|
|
audit_log(actx, GFP_ATOMIC, AUDIT_SELINUX_ERR,
|
2008-04-19 05:38:33 +08:00
|
|
|
"selinux_audit_rule_match: missing rule\n");
|
2006-02-25 05:44:05 +08:00
|
|
|
return -ENOENT;
|
|
|
|
}
|
|
|
|
|
2008-06-06 16:40:29 +08:00
|
|
|
read_lock(&policy_rwlock);
|
2006-02-25 05:44:05 +08:00
|
|
|
|
|
|
|
if (rule->au_seqno < latest_granting) {
|
|
|
|
audit_log(actx, GFP_ATOMIC, AUDIT_SELINUX_ERR,
|
2008-04-19 05:38:33 +08:00
|
|
|
"selinux_audit_rule_match: stale rule\n");
|
2006-02-25 05:44:05 +08:00
|
|
|
match = -ESTALE;
|
|
|
|
goto out;
|
|
|
|
}
|
|
|
|
|
2006-09-26 14:31:58 +08:00
|
|
|
ctxt = sidtab_search(&sidtab, sid);
|
2006-02-25 05:44:05 +08:00
|
|
|
if (!ctxt) {
|
|
|
|
audit_log(actx, GFP_ATOMIC, AUDIT_SELINUX_ERR,
|
2008-04-19 05:38:33 +08:00
|
|
|
"selinux_audit_rule_match: unrecognized SID %d\n",
|
|
|
|
sid);
|
2006-02-25 05:44:05 +08:00
|
|
|
match = -ENOENT;
|
|
|
|
goto out;
|
|
|
|
}
|
|
|
|
|
|
|
|
/* a field/op pair that is not caught here will simply fall through
|
|
|
|
without a match */
|
|
|
|
switch (field) {
|
2006-06-30 05:56:39 +08:00
|
|
|
case AUDIT_SUBJ_USER:
|
2006-06-30 05:57:08 +08:00
|
|
|
case AUDIT_OBJ_USER:
|
2006-02-25 05:44:05 +08:00
|
|
|
switch (op) {
|
2008-12-16 18:59:26 +08:00
|
|
|
case Audit_equal:
|
2006-02-25 05:44:05 +08:00
|
|
|
match = (ctxt->user == rule->au_ctxt.user);
|
|
|
|
break;
|
2008-12-16 18:59:26 +08:00
|
|
|
case Audit_not_equal:
|
2006-02-25 05:44:05 +08:00
|
|
|
match = (ctxt->user != rule->au_ctxt.user);
|
|
|
|
break;
|
|
|
|
}
|
|
|
|
break;
|
2006-06-30 05:56:39 +08:00
|
|
|
case AUDIT_SUBJ_ROLE:
|
2006-06-30 05:57:08 +08:00
|
|
|
case AUDIT_OBJ_ROLE:
|
2006-02-25 05:44:05 +08:00
|
|
|
switch (op) {
|
2008-12-16 18:59:26 +08:00
|
|
|
case Audit_equal:
|
2006-02-25 05:44:05 +08:00
|
|
|
match = (ctxt->role == rule->au_ctxt.role);
|
|
|
|
break;
|
2008-12-16 18:59:26 +08:00
|
|
|
case Audit_not_equal:
|
2006-02-25 05:44:05 +08:00
|
|
|
match = (ctxt->role != rule->au_ctxt.role);
|
|
|
|
break;
|
|
|
|
}
|
|
|
|
break;
|
2006-06-30 05:56:39 +08:00
|
|
|
case AUDIT_SUBJ_TYPE:
|
2006-06-30 05:57:08 +08:00
|
|
|
case AUDIT_OBJ_TYPE:
|
2006-02-25 05:44:05 +08:00
|
|
|
switch (op) {
|
2008-12-16 18:59:26 +08:00
|
|
|
case Audit_equal:
|
2006-02-25 05:44:05 +08:00
|
|
|
match = (ctxt->type == rule->au_ctxt.type);
|
|
|
|
break;
|
2008-12-16 18:59:26 +08:00
|
|
|
case Audit_not_equal:
|
2006-02-25 05:44:05 +08:00
|
|
|
match = (ctxt->type != rule->au_ctxt.type);
|
|
|
|
break;
|
|
|
|
}
|
|
|
|
break;
|
2006-06-30 05:56:39 +08:00
|
|
|
case AUDIT_SUBJ_SEN:
|
|
|
|
case AUDIT_SUBJ_CLR:
|
2006-06-30 05:57:08 +08:00
|
|
|
case AUDIT_OBJ_LEV_LOW:
|
|
|
|
case AUDIT_OBJ_LEV_HIGH:
|
|
|
|
level = ((field == AUDIT_SUBJ_SEN ||
|
2008-04-19 05:38:33 +08:00
|
|
|
field == AUDIT_OBJ_LEV_LOW) ?
|
|
|
|
&ctxt->range.level[0] : &ctxt->range.level[1]);
|
2006-02-25 05:44:05 +08:00
|
|
|
switch (op) {
|
2008-12-16 18:59:26 +08:00
|
|
|
case Audit_equal:
|
2006-02-25 05:44:05 +08:00
|
|
|
match = mls_level_eq(&rule->au_ctxt.range.level[0],
|
2008-04-19 05:38:33 +08:00
|
|
|
level);
|
2006-02-25 05:44:05 +08:00
|
|
|
break;
|
2008-12-16 18:59:26 +08:00
|
|
|
case Audit_not_equal:
|
2006-02-25 05:44:05 +08:00
|
|
|
match = !mls_level_eq(&rule->au_ctxt.range.level[0],
|
2008-04-19 05:38:33 +08:00
|
|
|
level);
|
2006-02-25 05:44:05 +08:00
|
|
|
break;
|
2008-12-16 18:59:26 +08:00
|
|
|
case Audit_lt:
|
2006-02-25 05:44:05 +08:00
|
|
|
match = (mls_level_dom(&rule->au_ctxt.range.level[0],
|
2008-04-19 05:38:33 +08:00
|
|
|
level) &&
|
|
|
|
!mls_level_eq(&rule->au_ctxt.range.level[0],
|
|
|
|
level));
|
2006-02-25 05:44:05 +08:00
|
|
|
break;
|
2008-12-16 18:59:26 +08:00
|
|
|
case Audit_le:
|
2006-02-25 05:44:05 +08:00
|
|
|
match = mls_level_dom(&rule->au_ctxt.range.level[0],
|
2008-04-19 05:38:33 +08:00
|
|
|
level);
|
2006-02-25 05:44:05 +08:00
|
|
|
break;
|
2008-12-16 18:59:26 +08:00
|
|
|
case Audit_gt:
|
2006-02-25 05:44:05 +08:00
|
|
|
match = (mls_level_dom(level,
|
2008-04-19 05:38:33 +08:00
|
|
|
&rule->au_ctxt.range.level[0]) &&
|
|
|
|
!mls_level_eq(level,
|
|
|
|
&rule->au_ctxt.range.level[0]));
|
2006-02-25 05:44:05 +08:00
|
|
|
break;
|
2008-12-16 18:59:26 +08:00
|
|
|
case Audit_ge:
|
2006-02-25 05:44:05 +08:00
|
|
|
match = mls_level_dom(level,
|
2008-04-19 05:38:33 +08:00
|
|
|
&rule->au_ctxt.range.level[0]);
|
2006-02-25 05:44:05 +08:00
|
|
|
break;
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
out:
|
2008-06-06 16:40:29 +08:00
|
|
|
read_unlock(&policy_rwlock);
|
2006-02-25 05:44:05 +08:00
|
|
|
return match;
|
|
|
|
}
|
|
|
|
|
2008-03-02 04:03:14 +08:00
|
|
|
static int (*aurule_callback)(void) = audit_update_lsm_rules;
|
2006-02-25 05:44:05 +08:00
|
|
|
|
|
|
|
static int aurule_avc_callback(u32 event, u32 ssid, u32 tsid,
|
2008-05-14 23:27:45 +08:00
|
|
|
u16 class, u32 perms, u32 *retained)
|
2006-02-25 05:44:05 +08:00
|
|
|
{
|
|
|
|
int err = 0;
|
|
|
|
|
|
|
|
if (event == AVC_CALLBACK_RESET && aurule_callback)
|
|
|
|
err = aurule_callback();
|
|
|
|
return err;
|
|
|
|
}
|
|
|
|
|
|
|
|
static int __init aurule_init(void)
|
|
|
|
{
|
|
|
|
int err;
|
|
|
|
|
|
|
|
err = avc_add_callback(aurule_avc_callback, AVC_CALLBACK_RESET,
|
2008-04-19 05:38:33 +08:00
|
|
|
SECSID_NULL, SECSID_NULL, SECCLASS_NULL, 0);
|
2006-02-25 05:44:05 +08:00
|
|
|
if (err)
|
|
|
|
panic("avc_add_callback() failed, error %d\n", err);
|
|
|
|
|
|
|
|
return err;
|
|
|
|
}
|
|
|
|
__initcall(aurule_init);
|
|
|
|
|
2006-08-05 14:17:57 +08:00
|
|
|
#ifdef CONFIG_NETLABEL
|
|
|
|
/**
|
2007-03-01 04:14:22 +08:00
|
|
|
* security_netlbl_cache_add - Add an entry to the NetLabel cache
|
|
|
|
* @secattr: the NetLabel packet security attributes
|
2008-01-29 21:44:18 +08:00
|
|
|
* @sid: the SELinux SID
|
2006-08-05 14:17:57 +08:00
|
|
|
*
|
|
|
|
* Description:
|
|
|
|
* Attempt to cache the context in @ctx, which was derived from the packet in
|
2007-03-01 04:14:22 +08:00
|
|
|
* @skb, in the NetLabel subsystem cache. This function assumes @secattr has
|
|
|
|
* already been initialized.
|
2006-08-05 14:17:57 +08:00
|
|
|
*
|
|
|
|
*/
|
2007-03-01 04:14:22 +08:00
|
|
|
static void security_netlbl_cache_add(struct netlbl_lsm_secattr *secattr,
|
2008-01-29 21:44:18 +08:00
|
|
|
u32 sid)
|
2006-08-05 14:17:57 +08:00
|
|
|
{
|
2008-01-29 21:44:18 +08:00
|
|
|
u32 *sid_cache;
|
2006-08-05 14:17:57 +08:00
|
|
|
|
2008-01-29 21:44:18 +08:00
|
|
|
sid_cache = kmalloc(sizeof(*sid_cache), GFP_ATOMIC);
|
|
|
|
if (sid_cache == NULL)
|
2007-03-01 04:14:22 +08:00
|
|
|
return;
|
2008-01-29 21:44:18 +08:00
|
|
|
secattr->cache = netlbl_secattr_cache_alloc(GFP_ATOMIC);
|
|
|
|
if (secattr->cache == NULL) {
|
|
|
|
kfree(sid_cache);
|
2007-03-01 04:14:22 +08:00
|
|
|
return;
|
2007-07-21 06:12:44 +08:00
|
|
|
}
|
2006-08-05 14:17:57 +08:00
|
|
|
|
2008-01-29 21:44:18 +08:00
|
|
|
*sid_cache = sid;
|
|
|
|
secattr->cache->free = kfree;
|
|
|
|
secattr->cache->data = sid_cache;
|
2007-03-01 04:14:22 +08:00
|
|
|
secattr->flags |= NETLBL_SECATTR_CACHE;
|
2006-08-05 14:17:57 +08:00
|
|
|
}
|
|
|
|
|
|
|
|
/**
|
2007-03-01 04:14:22 +08:00
|
|
|
* security_netlbl_secattr_to_sid - Convert a NetLabel secattr to a SELinux SID
|
2006-08-05 14:17:57 +08:00
|
|
|
* @secattr: the NetLabel packet security attributes
|
|
|
|
* @sid: the SELinux SID
|
|
|
|
*
|
|
|
|
* Description:
|
2007-03-01 04:14:22 +08:00
|
|
|
* Convert the given NetLabel security attributes in @secattr into a
|
2006-08-05 14:17:57 +08:00
|
|
|
* SELinux SID. If the @secattr field does not contain a full SELinux
|
2008-01-29 21:44:18 +08:00
|
|
|
* SID/context then use SECINITSID_NETMSG as the foundation. If possibile the
|
|
|
|
* 'cache' field of @secattr is set and the CACHE flag is set; this is to
|
|
|
|
* allow the @secattr to be used by NetLabel to cache the secattr to SID
|
|
|
|
* conversion for future lookups. Returns zero on success, negative values on
|
|
|
|
* failure.
|
2006-08-05 14:17:57 +08:00
|
|
|
*
|
|
|
|
*/
|
2007-03-01 04:14:22 +08:00
|
|
|
int security_netlbl_secattr_to_sid(struct netlbl_lsm_secattr *secattr,
|
|
|
|
u32 *sid)
|
2006-08-05 14:17:57 +08:00
|
|
|
{
|
|
|
|
int rc = -EIDRM;
|
|
|
|
struct context *ctx;
|
|
|
|
struct context ctx_new;
|
2007-03-01 04:14:22 +08:00
|
|
|
|
|
|
|
if (!ss_initialized) {
|
|
|
|
*sid = SECSID_NULL;
|
|
|
|
return 0;
|
|
|
|
}
|
2006-08-05 14:17:57 +08:00
|
|
|
|
2008-06-06 16:40:29 +08:00
|
|
|
read_lock(&policy_rwlock);
|
2006-08-05 14:17:57 +08:00
|
|
|
|
2006-11-18 06:38:46 +08:00
|
|
|
if (secattr->flags & NETLBL_SECATTR_CACHE) {
|
2008-01-29 21:44:18 +08:00
|
|
|
*sid = *(u32 *)secattr->cache->data;
|
|
|
|
rc = 0;
|
2008-01-29 21:37:59 +08:00
|
|
|
} else if (secattr->flags & NETLBL_SECATTR_SECID) {
|
|
|
|
*sid = secattr->attr.secid;
|
|
|
|
rc = 0;
|
2006-11-18 06:38:46 +08:00
|
|
|
} else if (secattr->flags & NETLBL_SECATTR_MLS_LVL) {
|
2008-01-29 21:44:18 +08:00
|
|
|
ctx = sidtab_search(&sidtab, SECINITSID_NETMSG);
|
2006-08-05 14:17:57 +08:00
|
|
|
if (ctx == NULL)
|
|
|
|
goto netlbl_secattr_to_sid_return;
|
|
|
|
|
2008-10-03 22:51:15 +08:00
|
|
|
context_init(&ctx_new);
|
2006-08-05 14:17:57 +08:00
|
|
|
ctx_new.user = ctx->user;
|
|
|
|
ctx_new.role = ctx->role;
|
|
|
|
ctx_new.type = ctx->type;
|
2006-11-30 02:18:18 +08:00
|
|
|
mls_import_netlbl_lvl(&ctx_new, secattr);
|
2006-11-18 06:38:46 +08:00
|
|
|
if (secattr->flags & NETLBL_SECATTR_MLS_CAT) {
|
2006-11-30 02:18:18 +08:00
|
|
|
if (ebitmap_netlbl_import(&ctx_new.range.level[0].cat,
|
2008-01-29 21:37:59 +08:00
|
|
|
secattr->attr.mls.cat) != 0)
|
2006-08-05 14:17:57 +08:00
|
|
|
goto netlbl_secattr_to_sid_return;
|
2008-10-03 22:51:15 +08:00
|
|
|
memcpy(&ctx_new.range.level[1].cat,
|
|
|
|
&ctx_new.range.level[0].cat,
|
|
|
|
sizeof(ctx_new.range.level[0].cat));
|
2006-08-05 14:17:57 +08:00
|
|
|
}
|
|
|
|
if (mls_context_isvalid(&policydb, &ctx_new) != 1)
|
|
|
|
goto netlbl_secattr_to_sid_return_cleanup;
|
|
|
|
|
|
|
|
rc = sidtab_context_to_sid(&sidtab, &ctx_new, sid);
|
|
|
|
if (rc != 0)
|
|
|
|
goto netlbl_secattr_to_sid_return_cleanup;
|
|
|
|
|
2008-01-29 21:44:18 +08:00
|
|
|
security_netlbl_cache_add(secattr, *sid);
|
2007-03-01 04:14:22 +08:00
|
|
|
|
2006-08-05 14:17:57 +08:00
|
|
|
ebitmap_destroy(&ctx_new.range.level[0].cat);
|
|
|
|
} else {
|
2006-10-06 06:28:24 +08:00
|
|
|
*sid = SECSID_NULL;
|
2006-08-05 14:17:57 +08:00
|
|
|
rc = 0;
|
|
|
|
}
|
|
|
|
|
|
|
|
netlbl_secattr_to_sid_return:
|
2008-06-06 16:40:29 +08:00
|
|
|
read_unlock(&policy_rwlock);
|
2006-08-05 14:17:57 +08:00
|
|
|
return rc;
|
|
|
|
netlbl_secattr_to_sid_return_cleanup:
|
|
|
|
ebitmap_destroy(&ctx_new.range.level[0].cat);
|
|
|
|
goto netlbl_secattr_to_sid_return;
|
|
|
|
}
|
|
|
|
|
|
|
|
/**
|
2007-03-01 04:14:22 +08:00
|
|
|
* security_netlbl_sid_to_secattr - Convert a SELinux SID to a NetLabel secattr
|
|
|
|
* @sid: the SELinux SID
|
|
|
|
* @secattr: the NetLabel packet security attributes
|
2006-08-05 14:17:57 +08:00
|
|
|
*
|
|
|
|
* Description:
|
2007-03-01 04:14:22 +08:00
|
|
|
* Convert the given SELinux SID in @sid into a NetLabel security attribute.
|
|
|
|
* Returns zero on success, negative values on failure.
|
2006-08-05 14:17:57 +08:00
|
|
|
*
|
|
|
|
*/
|
2007-03-01 04:14:22 +08:00
|
|
|
int security_netlbl_sid_to_secattr(u32 sid, struct netlbl_lsm_secattr *secattr)
|
2006-08-05 14:17:57 +08:00
|
|
|
{
|
2008-10-10 22:16:30 +08:00
|
|
|
int rc;
|
2006-08-05 14:17:57 +08:00
|
|
|
struct context *ctx;
|
|
|
|
|
|
|
|
if (!ss_initialized)
|
|
|
|
return 0;
|
|
|
|
|
2008-06-06 16:40:29 +08:00
|
|
|
read_lock(&policy_rwlock);
|
2006-08-05 14:17:57 +08:00
|
|
|
ctx = sidtab_search(&sidtab, sid);
|
2008-10-10 22:16:30 +08:00
|
|
|
if (ctx == NULL) {
|
|
|
|
rc = -ENOENT;
|
2007-03-01 04:14:22 +08:00
|
|
|
goto netlbl_sid_to_secattr_failure;
|
2008-10-10 22:16:30 +08:00
|
|
|
}
|
2007-03-01 04:14:22 +08:00
|
|
|
secattr->domain = kstrdup(policydb.p_type_val_to_name[ctx->type - 1],
|
|
|
|
GFP_ATOMIC);
|
2008-10-10 22:16:30 +08:00
|
|
|
if (secattr->domain == NULL) {
|
|
|
|
rc = -ENOMEM;
|
|
|
|
goto netlbl_sid_to_secattr_failure;
|
|
|
|
}
|
2008-10-10 22:16:33 +08:00
|
|
|
secattr->attr.secid = sid;
|
|
|
|
secattr->flags |= NETLBL_SECATTR_DOMAIN_CPY | NETLBL_SECATTR_SECID;
|
2007-03-01 04:14:22 +08:00
|
|
|
mls_export_netlbl_lvl(ctx, secattr);
|
|
|
|
rc = mls_export_netlbl_cat(ctx, secattr);
|
2006-10-12 07:10:48 +08:00
|
|
|
if (rc != 0)
|
2007-03-01 04:14:22 +08:00
|
|
|
goto netlbl_sid_to_secattr_failure;
|
2008-06-06 16:40:29 +08:00
|
|
|
read_unlock(&policy_rwlock);
|
2006-08-30 08:53:48 +08:00
|
|
|
|
2007-03-01 04:14:22 +08:00
|
|
|
return 0;
|
2006-10-31 07:22:15 +08:00
|
|
|
|
2007-03-01 04:14:22 +08:00
|
|
|
netlbl_sid_to_secattr_failure:
|
2008-06-06 16:40:29 +08:00
|
|
|
read_unlock(&policy_rwlock);
|
2006-10-31 07:22:15 +08:00
|
|
|
return rc;
|
|
|
|
}
|
2006-08-05 14:17:57 +08:00
|
|
|
#endif /* CONFIG_NETLABEL */
|