Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1285962

[PATCH v2 04/18] selinux: Add support for unprivileged mounts from user namespaces

From Seth Forshee <seth.forshee@canonical.com>
Newsgroups linux.kernel
Subject [PATCH v2 04/18] selinux: Add support for unprivileged mounts from user namespaces
Date 2015-12-07 22:40 +0100
Message-ID <qDbFM-1D6-15@gated-at.bofh.it> (permalink)
References <qDbw5-1y2-3@gated-at.bofh.it>
Organization linux.* mail to news gateway

Show all headers | View raw


Security labels from unprivileged mounts in user namespaces must
be ignored. Force superblocks from user namespaces whose labeling
behavior is to use xattrs to use mountpoint labeling instead.
For the mountpoint label, default to converting the current task
context into a form suitable for file objects, but also allow the
policy writer to specify a different label through policy
transition rules.

Pieced together from code snippets provided by Stephen Smalley.

Signed-off-by: Seth Forshee <seth.forshee@canonical.com>
Acked-by: Stephen Smalley <sds@tycho.nsa.gov>
Acked-by: James Morris <james.l.morris@oracle.com>
---
 security/selinux/hooks.c | 23 +++++++++++++++++++++++
 1 file changed, 23 insertions(+)

diff --git a/security/selinux/hooks.c b/security/selinux/hooks.c
index a5b93df6553f..5fedc36dd6b2 100644
--- a/security/selinux/hooks.c
+++ b/security/selinux/hooks.c
@@ -756,6 +756,28 @@ static int selinux_set_mnt_opts(struct super_block *sb,
 			goto out;
 		}
 	}
+
+	/*
+	 * If this is a user namespace mount, no contexts are allowed
+	 * on the command line and security labels must be ignored.
+	 */
+	if (sb->s_user_ns != &init_user_ns) {
+		if (context_sid || fscontext_sid || rootcontext_sid ||
+		    defcontext_sid) {
+			rc = -EACCES;
+			goto out;
+		}
+		if (sbsec->behavior == SECURITY_FS_USE_XATTR) {
+			sbsec->behavior = SECURITY_FS_USE_MNTPOINT;
+			rc = security_transition_sid(current_sid(), current_sid(),
+						     SECCLASS_FILE, NULL,
+						     &sbsec->mntpoint_sid);
+			if (rc)
+				goto out;
+		}
+		goto out_set_opts;
+	}
+
 	/* sets the context of the superblock for the fs being mounted. */
 	if (fscontext_sid) {
 		rc = may_context_mount_sb_relabel(fscontext_sid, sbsec, cred);
@@ -824,6 +846,7 @@ static int selinux_set_mnt_opts(struct super_block *sb,
 		sbsec->def_sid = defcontext_sid;
 	}
 
+out_set_opts:
 	rc = sb_finish_set_opts(sb);
 out:
 	mutex_unlock(&sbsec->lock);
-- 
1.9.1

--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

Back to linux.kernel | Previous | NextPrevious in thread | Next in thread | Find similar | Unroll thread


Thread

[PATCH v2 00/19] Support fuse mounts in user namespaces Seth Forshee <seth.forshee@canonical.com> - 2015-12-07 22:30 +0100
  [PATCH v2 15/18] fuse: Add support for pid namespaces Seth Forshee <seth.forshee@canonical.com> - 2015-12-07 22:30 +0100
  [PATCH v2 13/18] fs: Allow superblock owner to access do_remount_sb() Seth Forshee <seth.forshee@canonical.com> - 2015-12-07 22:30 +0100
  [PATCH v2 17/18] fuse: Restrict allow_other to the superblock's namespace or a descendant Seth Forshee <seth.forshee@canonical.com> - 2015-12-07 22:30 +0100
  [PATCH v2 10/18] fs: Update posix_acl support to handle user namespace mounts Seth Forshee <seth.forshee@canonical.com> - 2015-12-07 22:30 +0100
  [PATCH v2 04/18] selinux: Add support for unprivileged mounts from user namespaces Seth Forshee <seth.forshee@canonical.com> - 2015-12-07 22:40 +0100
  [PATCH v2 05/18] userns: Replace in_userns with current_in_userns Seth Forshee <seth.forshee@canonical.com> - 2015-12-07 22:40 +0100
  [PATCH v2 09/18] fs: Refuse uid/gid changes which don't map into s_user_ns Seth Forshee <seth.forshee@canonical.com> - 2015-12-07 22:40 +0100
  [PATCH v2 06/18] Smack: Handle labels consistently in untrusted mounts Seth Forshee <seth.forshee@canonical.com> - 2015-12-07 22:40 +0100
  [PATCH v2 01/18] block_dev: Support checking inode permissions in lookup_bdev() Seth Forshee <seth.forshee@canonical.com> - 2015-12-07 22:40 +0100
  [PATCH v2 02/18] block_dev: Check permissions towards block device inode when mounting Seth Forshee <seth.forshee@canonical.com> - 2015-12-07 22:40 +0100

csiph-web