Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1226444

[PATCH v3 7/7] selinux: Add support for unprivileged mounts from user namespaces

From Seth Forshee <seth.forshee@canonical.com>
Newsgroups linux.kernel
Subject [PATCH v3 7/7] selinux: Add support for unprivileged mounts from user namespaces
Date 2015-09-16 22:10 +0200
Message-ID <q9rbJ-6jD-37@gated-at.bofh.it> (permalink)
References <q9rbI-6jD-9@gated-at.bofh.it>
Organization linux.* mail to news gateway

Show all headers | View raw


Security labels from unprivileged mounts in user namespaces must
be ignored. Force superblocks from user namespaces whose labeling
behavior is to use xattrs to use mountpoint labeling instead.
For the mountpoint label, default to converting the current task
context into a form suitable for file objects, but also allow the
policy writer to specify a different label through policy
transition rules.

Pieced together from code snippets provided by Stephen Smalley.

Signed-off-by: Seth Forshee <seth.forshee@canonical.com>
---
 security/selinux/hooks.c | 23 +++++++++++++++++++++++
 1 file changed, 23 insertions(+)

diff --git a/security/selinux/hooks.c b/security/selinux/hooks.c
index de05207eb665..09be1dc21e58 100644
--- a/security/selinux/hooks.c
+++ b/security/selinux/hooks.c
@@ -756,6 +756,28 @@ static int selinux_set_mnt_opts(struct super_block *sb,
 			goto out;
 		}
 	}
+
+	/*
+	 * If this is a user namespace mount, no contexts are allowed
+	 * on the command line and security labels must be ignored.
+	 */
+	if (sb->s_user_ns != &init_user_ns) {
+		if (context_sid || fscontext_sid || rootcontext_sid ||
+		    defcontext_sid) {
+			rc = -EACCES;
+			goto out;
+		}
+		if (sbsec->behavior == SECURITY_FS_USE_XATTR) {
+			sbsec->behavior = SECURITY_FS_USE_MNTPOINT;
+			rc = security_transition_sid(current_sid(), current_sid(),
+						     SECCLASS_FILE, NULL,
+						     &sbsec->mntpoint_sid);
+			if (rc)
+				goto out;
+		}
+		goto out_set_opts;
+	}
+
 	/* sets the context of the superblock for the fs being mounted. */
 	if (fscontext_sid) {
 		rc = may_context_mount_sb_relabel(fscontext_sid, sbsec, cred);
@@ -824,6 +846,7 @@ static int selinux_set_mnt_opts(struct super_block *sb,
 		sbsec->def_sid = defcontext_sid;
 	}
 
+out_set_opts:
 	rc = sb_finish_set_opts(sb);
 out:
 	mutex_unlock(&sbsec->lock);
-- 
1.9.1

--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

Back to linux.kernel | Previous | NextPrevious in thread | Find similar | Unroll thread


Thread

[PATCH v3 0/7] Initial support for user namespace owned mounts Seth Forshee <seth.forshee@canonical.com> - 2015-09-16 22:10 +0200
  [PATCH v3 1/7] fs: Add user namesapace member to struct super_block Seth Forshee <seth.forshee@canonical.com> - 2015-09-16 22:10 +0200
  [PATCH v3 6/7] Smack: Add support for unprivileged mounts from user namespaces Seth Forshee <seth.forshee@canonical.com> - 2015-09-16 22:10 +0200
    Re: [PATCH v3 6/7] Smack: Add support for unprivileged mounts from  user namespaces Casey Schaufler <casey@schaufler-ca.com> - 2015-09-16 22:40 +0200
      Re: [PATCH v3 6/7] Smack: Add support for unprivileged mounts from  user namespaces Seth Forshee <seth.forshee@canonical.com> - 2015-09-17 15:00 +0200
  [PATCH v3 2/7] userns: Simpilify MNT_NODEV handling. Seth Forshee <seth.forshee@canonical.com> - 2015-09-16 22:10 +0200
    Re: [PATCH v3 2/7] userns: Simpilify MNT_NODEV handling. Andy Lutomirski <luto@amacapital.net> - 2015-09-17 02:30 +0200
      Re: [PATCH v3 2/7] userns: Simpilify MNT_NODEV handling. ebiederm@xmission.com (Eric W. Biederman) - 2015-09-17 03:10 +0200
        Re: [PATCH v3 2/7] userns: Simpilify MNT_NODEV handling. Andy Lutomirski <luto@amacapital.net> - 2015-09-18 00:20 +0200
  [PATCH v3 3/7] fs: Verify access of user towards block device file when mounting Seth Forshee <seth.forshee@canonical.com> - 2015-09-16 22:10 +0200
  [PATCH v3 7/7] selinux: Add support for unprivileged mounts from user namespaces Seth Forshee <seth.forshee@canonical.com> - 2015-09-16 22:10 +0200

csiph-web