Re: SELinux: Granting kernel_t (kdevtmpfs) manage rights on /dev/*

Luis Ressel <[email protected]> Wed, 4 Mar 2015 23:04:34 +0100
Newsgroups gmane.linux.gentoo.hardened
Message-ID <[email protected]>
On Wed, 4 Mar 2015 20:21:08 +0000
Sven Vermeulen <[email protected]> wrote:

> 1. I can temporarily ignore the issue, perhaps hiding the cosmetic
> denial behind dontaudit statements
> 2. I can restrictively add to kernel_t those rules that do not
> trigger the neverallow rules and ignore/dontaudit the rest
> 3. I can break isolation a bit and explicitly add kernel_t to the
> neverallow rule exemption
> 4. I can move the necessary attributes and statements into the devices
>    module (which is part of the base)
> 5. I can move forward with the storage-becomes-base approach

I've been allowing this in my local policy since 2013. I'm sure it was
neccessary for something to work, however I don't recall what for. But
that means 1. is not really an option.

For now, I'd just wait for more feedback on the refpolicy ML. This is
not an urgent problem, so I'd prefer not to diverge further from
upstream if we can avoid it.

5. seems to be the cleanest solution, but I've got to dig around a bit
in the refpolicy to estimate the amount of work it'd require.

If we want a temporary fix, I'd go with 3. It's only a tiny change, so
it wouldn't cause too much confusing upstream divergence.



-- 
Luis Ressel <[email protected]>
GPG fpr: F08D 2AF6 655E 25DE 52BC  E53D 08F5 7F90 3029 B5BD
signature.asc (application/pgp-signature, 949 B)
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2

iQJ8BAEBCgBmBQJU94FyXxSAAAAAAC4AKGlzc3Vlci1mcHJAbm90YXRpb25zLm9w
ZW5wZ3AuZmlmdGhob3JzZW1hbi5uZXRBMjU3MDBFQTc5QkYzMkY4NEQzMTFGNDlD
NzE4OTFBNkEwRUZCN0U5AAoJEMcYkaag77fpQwIQAMPBptNLem9CB/EbTLbTwCuv
rCIdlege2rxVMEWDQSl/5IA66Cs8E/ngpslFtEmINbqAjPi+g/SzF4tm+xL0+uKa
1rzyEDgp28wC9XPkg94Pa5Qy2pjm7WSlcrjbopOoyPDPP+Y4jbqT8l2S/LSjpAtB
pD09B+btMQGROE+loWijhE7TivX9fC+jJcZX83QepFpu7Z6CoyTcib4jJCEp4pno
8P7EX6ImFV2Ea1LWffUdWnUUJYjEgyGMnufHubfOvmXjJWZaxfys6IVnTVk8MSXA
p/6rCwtepQn+X5IzBK28clANyk8XaV9z4Sp970rbjPy1dJPCRPNTAIGCCvjimC6x
Wdyc0wf3Mm3Spgbv3+MryTdkjXMptIlImzepcrGCa9IX5l4+ir2Yp96OEWCkNGa+
CmnXuwsHKKgcFSqnO6YL3C2ysl83cpQJ+rRGPsAYfy1MO3bIi0zizAhdWYILvbFe
c5hLa2ergMq5whYELF3KWHJfT7C+Rzp4+hEMZZvwYbPVucJx5B7bqDiwGR4ibZwA
1TxKKBgBemXQlO3t+LWoS8SZhQP+HyHdq2Bt2xDEu3HFefV4ek069ntvDBBWgQ4t
veCkEtx+vlRFjSTSSKzyAsGepXAaLE2O6tyLv+joxYXgAZikLl6Rx0+Q8O/cTKhT
OWq2YV3aLv1xmMn/EYiv
=Waf0
-----END PGP SIGNATURE-----