Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1588953

Re: [Regression?] 1ea0ce4069 ("selinux: allow changing labels for cgroupfs") stops Android from booting

From Stephen Smalley <sds@tycho.nsa.gov>
Newsgroups linux.kernel
Subject Re: [Regression?] 1ea0ce4069 ("selinux: allow changing labels for cgroupfs") stops Android from booting
Date 2017-02-27 22:40 +0100
Message-ID <tfBbr-31m-1@gated-at.bofh.it> (permalink)
References (1 earlier) <tebCp-hQ-11@gated-at.bofh.it> <tfzsZ-1N7-13@gated-at.bofh.it> <tfBbr-31m-3@gated-at.bofh.it> <tfBbr-31m-5@gated-at.bofh.it> <tfBbr-31m-7@gated-at.bofh.it>
Organization National Security Agency

Show all headers | View raw


On Mon, 2017-02-27 at 16:23 -0500, Stephen Smalley wrote:
> On Mon, 2017-02-27 at 12:48 -0800, Nick Kralevich wrote:
> > 
> > On Mon, Feb 27, 2017 at 11:53 AM, Stephen Smalley <sds@tycho.nsa.go
> > v>
> > wrote:
> > > 
> > > 
> > > > 
> > > > 
> > > > I can reproduce it on angler (with a back-port of just that
> > > > patch),
> > > > although I am unclear on the cause.  The patch is only supposed
> > > > to
> > > > enable explicit setting of security labels by userspace on
> > > > cgroup
> > > > files, so it isn't supposed to cause any breakage under
> > > > existing
> > > > policy.  Prior to the patch, the kernel would always just
> > > > return
> > > > -1
> > > > with errno EOPNOTSUPP upon attempts to set security labels on
> > > > cgroup
> > > > files; with the patch, the kernel may instead return -1 with
> > > > errno
> > > > EACCES if not allowed.  So I suppose if userspace was
> > > > explicitly
> > > > testing for EOPNOTSUPP and not failing hard in that case, it
> > > > might
> > > > cause breakage.  Not sure why existing userspace would be
> > > > trying
> > > > to
> > > > relabel cgroup files, unless it is just a recursive restorecon
> > > > that
> > > > happens to traverse into a cgroup mount (and in that case, not
> > > > sure
> > > > why
> > > > it would be fatal).  Other possible interaction would be use of
> > > > setfscreatecon() prior to creating a file in cgroup.
> > > 
> > > Oh, I see - it is the latter.
> > > 
> > > For example, init.rc does mkdir /dev/cpuctl/bg_non_interactive,
> > > which
> > > internally looks up the context for that directory from
> > > file_contexts
> > > and does a setfscreatecon() followed by a mkdir().  Previously,
> > > that
> > > was ignored because cgroup did not support anything other than
> > > the
> > > policy-defined label.  But now it will try to use that label,
> > > which
> > > in
> > > turn will trigger a denial in enforcing mode and the create will
> > > fail.
> > > 
> > > So this is an incompatible change and needs to be reverted.
> > > We'll need to wrap it up with a policy capability or something to
> > > allow
> > > it to be enabled only if the policy correctly supports it.  Even
> > > better, we should instead just allow the policy to specify which
> > > filesystems should support this behavior (already on the issues
> > > list).
> > > 
> > 
> > If Android is the only system affected by this bug, I would prefer
> > to
> > just fix Android to allow for this patch, rather than having
> > additional kernel complexity.
> 
> Well, it does break userspace (even if it happens to only affect
> Android, which isn't clear, e.g. possibly a distribution would
> likewise
> suffer breakage under a tighter policy), and we already have a long-
> standing open issue to replace the current set of whitelisted
> filesystem types with something configuration-driven.  So I'm ok with
> reverting it and requiring it to be done in a more general way.  The
> latter is something we want regardless.

Also, I'm not sure it can be fixed cleanly just by policy, or at least
not just via kernel policy.  You wouldn't want to allow creation of
cgroup files in the contexts presently specified via file_contexts; you
would need to modify file_contexts to correctly specify the cgroup file
contexts.  And that in turn raises another existing issue:
distinguishing the label for the mountpoint directory versus the
mounted directory.

Back to linux.kernel | Previous | NextPrevious in thread | Next in thread | Find similar | Unroll thread


Thread

[Regression?] 1ea0ce4069 ("selinux: allow changing labels for  cgroupfs") stops Android from booting John Stultz <john.stultz@linaro.org> - 2017-02-23 20:00 +0100
  Re: [Regression?] 1ea0ce4069 ("selinux: allow changing labels for  cgroupfs") stops Android from booting Paul Moore <paul@paul-moore.com> - 2017-02-24 01:10 +0100
    Re: [Regression?] 1ea0ce4069 ("selinux: allow changing labels for  cgroupfs") stops Android from booting John Stultz <john.stultz@linaro.org> - 2017-02-25 03:10 +0100
      Re: [Regression?] 1ea0ce4069 ("selinux: allow changing labels for  cgroupfs") stops Android from booting Nick Kralevich <nnk@google.com> - 2017-02-25 04:50 +0100
      Re: [Regression?] 1ea0ce4069 ("selinux: allow changing labels for  cgroupfs") stops Android from booting John Stultz <john.stultz@linaro.org> - 2017-02-25 05:40 +0100
    Re: [Regression?] 1ea0ce4069 ("selinux: allow changing labels for  cgroupfs") stops Android from booting Stephen Smalley <sds@tycho.nsa.gov> - 2017-02-27 20:50 +0100
      Re: [Regression?] 1ea0ce4069 ("selinux: allow changing labels for  cgroupfs") stops Android from booting Stephen Smalley <sds@tycho.nsa.gov> - 2017-02-27 22:40 +0100
      Re: [Regression?] 1ea0ce4069 ("selinux: allow changing labels for  cgroupfs") stops Android from booting Nick Kralevich <nnk@google.com> - 2017-02-28 02:00 +0100
        Re: [Regression?] 1ea0ce4069 ("selinux: allow changing labels for  cgroupfs") stops Android from booting Stephen Smalley <sds@tycho.nsa.gov> - 2017-02-28 02:10 +0100
          Re: [Regression?] 1ea0ce4069 ("selinux: allow changing labels for  cgroupfs") stops Android from booting Paul Moore <paul@paul-moore.com> - 2017-02-28 04:30 +0100
            Re: [Regression?] 1ea0ce4069 ("selinux: allow changing labels for  cgroupfs") stops Android from booting Stephen Smalley <sds@tycho.nsa.gov> - 2017-02-28 16:30 +0100
              Re: [Regression?] 1ea0ce4069 ("selinux: allow changing labels for  cgroupfs") stops Android from booting Paul Moore <paul@paul-moore.com> - 2017-02-28 18:30 +0100
      Re: [Regression?] 1ea0ce4069 ("selinux: allow changing labels for  cgroupfs") stops Android from booting Stephen Smalley <sds@tycho.nsa.gov> - 2017-02-28 02:40 +0100

csiph-web