Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1245920 > unrolled thread

[PATCH v2 5/7] selinux: Add support for unprivileged mounts from user namespaces

Started bySeth Forshee <seth.forshee@canonical.com>
First post2015-10-13 19:10 +0200
Last post2015-10-13 22:30 +0200
Articles 2 — 2 participants

Back to article view | Back to linux.kernel

This discussion starts older than the indexed window; earlier articles aren't shown. The article labeled Started by below is the oldest one visible, not the original post.


Contents

  [PATCH v2 5/7] selinux: Add support for unprivileged mounts from user namespaces Seth Forshee <seth.forshee@canonical.com> - 2015-10-13 19:10 +0200
    Re: [PATCH v2 5/7] selinux: Add support for unprivileged mounts from  user namespaces Stephen Smalley <sds@tycho.nsa.gov> - 2015-10-13 22:30 +0200

#1245920 — [PATCH v2 5/7] selinux: Add support for unprivileged mounts from user namespaces

FromSeth Forshee <seth.forshee@canonical.com>
Date2015-10-13 19:10 +0200
Subject[PATCH v2 5/7] selinux: Add support for unprivileged mounts from user namespaces
Message-ID<qjbfk-4vf-17@gated-at.bofh.it>
Security labels from unprivileged mounts in user namespaces must
be ignored. Force superblocks from user namespaces whose labeling
behavior is to use xattrs to use mountpoint labeling instead.
For the mountpoint label, default to converting the current task
context into a form suitable for file objects, but also allow the
policy writer to specify a different label through policy
transition rules.

Pieced together from code snippets provided by Stephen Smalley.

Signed-off-by: Seth Forshee <seth.forshee@canonical.com>
---
 security/selinux/hooks.c | 23 +++++++++++++++++++++++
 1 file changed, 23 insertions(+)

diff --git a/security/selinux/hooks.c b/security/selinux/hooks.c
index de05207eb665..09be1dc21e58 100644
--- a/security/selinux/hooks.c
+++ b/security/selinux/hooks.c
@@ -756,6 +756,28 @@ static int selinux_set_mnt_opts(struct super_block *sb,
 			goto out;
 		}
 	}
+
+	/*
+	 * If this is a user namespace mount, no contexts are allowed
+	 * on the command line and security labels must be ignored.
+	 */
+	if (sb->s_user_ns != &init_user_ns) {
+		if (context_sid || fscontext_sid || rootcontext_sid ||
+		    defcontext_sid) {
+			rc = -EACCES;
+			goto out;
+		}
+		if (sbsec->behavior == SECURITY_FS_USE_XATTR) {
+			sbsec->behavior = SECURITY_FS_USE_MNTPOINT;
+			rc = security_transition_sid(current_sid(), current_sid(),
+						     SECCLASS_FILE, NULL,
+						     &sbsec->mntpoint_sid);
+			if (rc)
+				goto out;
+		}
+		goto out_set_opts;
+	}
+
 	/* sets the context of the superblock for the fs being mounted. */
 	if (fscontext_sid) {
 		rc = may_context_mount_sb_relabel(fscontext_sid, sbsec, cred);
@@ -824,6 +846,7 @@ static int selinux_set_mnt_opts(struct super_block *sb,
 		sbsec->def_sid = defcontext_sid;
 	}
 
+out_set_opts:
 	rc = sb_finish_set_opts(sb);
 out:
 	mutex_unlock(&sbsec->lock);
-- 
1.9.1

--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

[toc] | [next] | [standalone]


#1246116 — Re: [PATCH v2 5/7] selinux: Add support for unprivileged mounts from user namespaces

FromStephen Smalley <sds@tycho.nsa.gov>
Date2015-10-13 22:30 +0200
SubjectRe: [PATCH v2 5/7] selinux: Add support for unprivileged mounts from user namespaces
Message-ID<qjemR-AL-1@gated-at.bofh.it>
In reply to#1245920
On 10/13/2015 01:04 PM, Seth Forshee wrote:
> Security labels from unprivileged mounts in user namespaces must
> be ignored. Force superblocks from user namespaces whose labeling
> behavior is to use xattrs to use mountpoint labeling instead.
> For the mountpoint label, default to converting the current task
> context into a form suitable for file objects, but also allow the
> policy writer to specify a different label through policy
> transition rules.
>
> Pieced together from code snippets provided by Stephen Smalley.
>
> Signed-off-by: Seth Forshee <seth.forshee@canonical.com>

Acked-by: Stephen Smalley <sds@tycho.nsa.gov>

> ---
>   security/selinux/hooks.c | 23 +++++++++++++++++++++++
>   1 file changed, 23 insertions(+)
>
> diff --git a/security/selinux/hooks.c b/security/selinux/hooks.c
> index de05207eb665..09be1dc21e58 100644
> --- a/security/selinux/hooks.c
> +++ b/security/selinux/hooks.c
> @@ -756,6 +756,28 @@ static int selinux_set_mnt_opts(struct super_block *sb,
>   			goto out;
>   		}
>   	}
> +
> +	/*
> +	 * If this is a user namespace mount, no contexts are allowed
> +	 * on the command line and security labels must be ignored.
> +	 */
> +	if (sb->s_user_ns != &init_user_ns) {
> +		if (context_sid || fscontext_sid || rootcontext_sid ||
> +		    defcontext_sid) {
> +			rc = -EACCES;
> +			goto out;
> +		}
> +		if (sbsec->behavior == SECURITY_FS_USE_XATTR) {
> +			sbsec->behavior = SECURITY_FS_USE_MNTPOINT;
> +			rc = security_transition_sid(current_sid(), current_sid(),
> +						     SECCLASS_FILE, NULL,
> +						     &sbsec->mntpoint_sid);
> +			if (rc)
> +				goto out;
> +		}
> +		goto out_set_opts;
> +	}
> +
>   	/* sets the context of the superblock for the fs being mounted. */
>   	if (fscontext_sid) {
>   		rc = may_context_mount_sb_relabel(fscontext_sid, sbsec, cred);
> @@ -824,6 +846,7 @@ static int selinux_set_mnt_opts(struct super_block *sb,
>   		sbsec->def_sid = defcontext_sid;
>   	}
>
> +out_set_opts:
>   	rc = sb_finish_set_opts(sb);
>   out:
>   	mutex_unlock(&sbsec->lock);
>

--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

[toc] | [prev] | [standalone]


Back to top | Article view | linux.kernel


csiph-web