Re: selinux_init() is not executed in booting in kernel 5.15

Henry Zhang <[email protected]> Tue, 8 Aug 2023 07:26:38 -0700
Newsgroups gmane.linux.redhat.fedora.selinux
Message-ID <CANTW0yqy0fBMSwk9GgUZLYheFz_fv0sAOeAJ2o7dL19MwaGu1w@mail.gmail.com>
--===============6820124258846490405==
Content-Type: multipart/alternative; boundary="00000000000053a0e406026a279d"

--00000000000053a0e406026a279d
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

Ondrej,

Thanks for your help!
I am using Yocto embedded to compile. The kernel config file is copied from
/proc/config.gz in my linux device.
The kernel function selinux_init() is not triggered when booting up.

---henry


On Tue, Aug 8, 2023 at 1:17=E2=80=AFAM Ondrej Mosnacek <[email protected]=
> wrote:

> That is not a kernel config file. How are you building/installing the
> kernel? What Linux distribution (Fedora/CentOS/Ubuntu/...) is this on?
>
> On Mon, Aug 7, 2023 at 6:29=E2=80=AFPM Henry Zhang <[email protected]=
m> wrote:
> >
> > Ondrej,
> >
> > Attached is my kernel configuration file.
> > ~# cat /etc/selinux/config
> > # This file controls the state of SELinux on the system.
> > # SELINUX=3D can take one of these three values:
> > #     enforcing - SELinux security policy is enforced.
> > #     permissive - SELinux prints warnings instead of enforcing.
> > #     disabled - No SELinux policy is loaded.
> > SELINUX=3Denforcing
> > # SELINUXTYPE=3D can take one of these values:
> > #     minimum - Minimum Security protection.
> > #     standard - Standard Security protection.
> > #     mls - Multi Level Security protection.
> > #     targeted - Targeted processes are protected.
> > #     mcs - Multi Category Security protection.
> > SELINUXTYPE=3Dmcs
> >
> > # sestatus
> > SELinux status:                 disabled
> >
> > # getenforce
> > Disabled
> >
> > # setenforce 1
> > setenforce: SELinux is disabled
> >
> > # dmesg|grep SELi
> > [    5.604171] systemd[1]: Starting SELinux init for /dev service
> loading...
> >
> > # dmesg|grep SELI
> > [    4.180494] systemd[1]: systemd 250.5+ running in system mode (+PAM
> +AUDIT +SELINUX -APPARMOR +IMA -SMACK +SECCOMP -GCRYPT -GNUTLS -OPENSSL
> +ACL +BLKID -CURL -ELFUTILS -FIDO2 -IDN2 -IDN -IPTC +KMOD -LIBCRYPTSETUP)
> >
> > "SELInux: Initializing" is not seen in dmesg.
> >
> > Please comment on what is missing?
> > On Sat, Aug 5, 2023 at 1:12=E2=80=AFAM Ondrej Mosnacek <omosnace@redhat=
.com>
> wrote:
> >>
> >> On Sat, Aug 5, 2023 at 2:53=E2=80=AFAM Henry Zhang <henryzhang62@gmail=
.com>
> wrote:
> >> >
> >> > Hi guys,
> >> >
> >> > I am porting selinux from kernel 4.14 to 5.15. Everything works fine
> in kernel 4.14.
> >> > keep same /etc/selinux/conf and kernel parameters to enable SELinux.
> >> >
> >> > But the selinux_init() is not executed when kernel 5.15 boots becaus=
e
> no "SELinux: Initializing" is seen in dmesg.
> >> >
> >> > This selinux_init() is defined in
> http://tomoyo.osdn.jp/cgi-bin/lxr/source/security/selinux/hooks.c
> >> >
> >> >  DEFINE_LSM(selinux) =3D {
> >> > 7288         .name =3D "selinux",
> >> > 7289         .flags =3D LSM_FLAG_LEGACY_MAJOR | LSM_FLAG_EXCLUSIVE,
> >> > 7290         .enabled =3D &selinux_enabled_boot,
> >> > 7291         .blobs =3D &selinux_blob_sizes,
> >> > 7292         .init =3D selinux_init,
> >> > 7293 };
> >> >
> >> > My question is why the selinux_init() is not called when kernel 5.15
> boots up?
> >>
> >> Hi Henry,
> >>
> >> Can you share your kernel build config? If you don't know what it is
> >> or how to get it, then the next question would be: How did you
> >> obtain/build the kernel in question?
> >>
> >> --
> >> Ondrej Mosnacek
> >> Senior Software Engineer, Linux Security - SELinux kernel
> >> Red Hat, Inc.
> >>
>
>
> --
> Ondrej Mosnacek
> Senior Software Engineer, Linux Security - SELinux kernel
> Red Hat, Inc.
>
>

--00000000000053a0e406026a279d
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><div>Ondrej,</div><div><br></div><div>Thanks for your help=
!<br></div><div>I am using Yocto embedded to compile. The kernel config fil=
e is copied from /proc/config.gz in my linux device.</div><div>The kernel f=
unction selinux_init() is not triggered when booting up.</div><div><br></di=
v><div>---henry<br></div><div><br></div></div><br><div class=3D"gmail_quote=
"><div dir=3D"ltr" class=3D"gmail_attr">On Tue, Aug 8, 2023 at 1:17=E2=80=
=AFAM Ondrej Mosnacek &lt;<a href=3D"mailto:[email protected]">omosnace@r=
edhat.com</a>&gt; wrote:<br></div><blockquote class=3D"gmail_quote" style=
=3D"margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding=
-left:1ex">That is not a kernel config file. How are you building/installin=
g the<br>
kernel? What Linux distribution (Fedora/CentOS/Ubuntu/...) is this on?<br>
<br>
On Mon, Aug 7, 2023 at 6:29=E2=80=AFPM Henry Zhang &lt;<a href=3D"mailto:he=
[email protected]" target=3D"_blank">[email protected]</a>&gt; wrot=
e:<br>
&gt;<br>
&gt; Ondrej,<br>
&gt;<br>
&gt; Attached is my kernel configuration file.<br>
&gt; ~# cat /etc/selinux/config<br>
&gt; # This file controls the state of SELinux on the system.<br>
&gt; # SELINUX=3D can take one of these three values:<br>
&gt; #=C2=A0 =C2=A0 =C2=A0enforcing - SELinux security policy is enforced.<=
br>
&gt; #=C2=A0 =C2=A0 =C2=A0permissive - SELinux prints warnings instead of e=
nforcing.<br>
&gt; #=C2=A0 =C2=A0 =C2=A0disabled - No SELinux policy is loaded.<br>
&gt; SELINUX=3Denforcing<br>
&gt; # SELINUXTYPE=3D can take one of these values:<br>
&gt; #=C2=A0 =C2=A0 =C2=A0minimum - Minimum Security protection.<br>
&gt; #=C2=A0 =C2=A0 =C2=A0standard - Standard Security protection.<br>
&gt; #=C2=A0 =C2=A0 =C2=A0mls - Multi Level Security protection.<br>
&gt; #=C2=A0 =C2=A0 =C2=A0targeted - Targeted processes are protected.<br>
&gt; #=C2=A0 =C2=A0 =C2=A0mcs - Multi Category Security protection.<br>
&gt; SELINUXTYPE=3Dmcs<br>
&gt;<br>
&gt; # sestatus<br>
&gt; SELinux status:=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0=
 =C2=A0disabled<br>
&gt;<br>
&gt; # getenforce<br>
&gt; Disabled<br>
&gt;<br>
&gt; # setenforce 1<br>
&gt; setenforce: SELinux is disabled<br>
&gt;<br>
&gt; # dmesg|grep SELi<br>
&gt; [=C2=A0 =C2=A0 5.604171] systemd[1]: Starting SELinux init for /dev se=
rvice loading...<br>
&gt;<br>
&gt; # dmesg|grep SELI<br>
&gt; [=C2=A0 =C2=A0 4.180494] systemd[1]: systemd 250.5+ running in system =
mode (+PAM +AUDIT +SELINUX -APPARMOR +IMA -SMACK +SECCOMP -GCRYPT -GNUTLS -=
OPENSSL +ACL +BLKID -CURL -ELFUTILS -FIDO2 -IDN2 -IDN -IPTC +KMOD -LIBCRYPT=
SETUP)<br>
&gt;<br>
&gt; &quot;SELInux: Initializing&quot; is not seen in dmesg.<br>
&gt;<br>
&gt; Please comment on what is missing?<br>
&gt; On Sat, Aug 5, 2023 at 1:12=E2=80=AFAM Ondrej Mosnacek &lt;<a href=3D"=
mailto:[email protected]" target=3D"_blank">[email protected]</a>&gt; w=
rote:<br>
&gt;&gt;<br>
&gt;&gt; On Sat, Aug 5, 2023 at 2:53=E2=80=AFAM Henry Zhang &lt;<a href=3D"=
mailto:[email protected]" target=3D"_blank">[email protected]</a>=
&gt; wrote:<br>
&gt;&gt; &gt;<br>
&gt;&gt; &gt; Hi guys,<br>
&gt;&gt; &gt;<br>
&gt;&gt; &gt; I am porting selinux from kernel 4.14 to 5.15. Everything wor=
ks fine in kernel 4.14.<br>
&gt;&gt; &gt; keep same /etc/selinux/conf and kernel parameters to enable S=
ELinux.<br>
&gt;&gt; &gt;<br>
&gt;&gt; &gt; But the selinux_init() is not executed when kernel 5.15 boots=
 because no &quot;SELinux: Initializing&quot; is seen in dmesg.<br>
&gt;&gt; &gt;<br>
&gt;&gt; &gt; This selinux_init() is defined in <a href=3D"http://tomoyo.os=
dn.jp/cgi-bin/lxr/source/security/selinux/hooks.c" rel=3D"noreferrer" targe=
t=3D"_blank">http://tomoyo.osdn.jp/cgi-bin/lxr/source/security/selinux/hook=
s.c</a><br>
&gt;&gt; &gt;<br>
&gt;&gt; &gt;=C2=A0 DEFINE_LSM(selinux) =3D {<br>
&gt;&gt; &gt; 7288=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0.name =3D &quot;selinux=
&quot;,<br>
&gt;&gt; &gt; 7289=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0.flags =3D LSM_FLAG_LEG=
ACY_MAJOR | LSM_FLAG_EXCLUSIVE,<br>
&gt;&gt; &gt; 7290=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0.enabled =3D &amp;selin=
ux_enabled_boot,<br>
&gt;&gt; &gt; 7291=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0.blobs =3D &amp;selinux=
_blob_sizes,<br>
&gt;&gt; &gt; 7292=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0.init =3D selinux_init,=
<br>
&gt;&gt; &gt; 7293 };<br>
&gt;&gt; &gt;<br>
&gt;&gt; &gt; My question is why the selinux_init() is not called when kern=
el 5.15 boots up?<br>
&gt;&gt;<br>
&gt;&gt; Hi Henry,<br>
&gt;&gt;<br>
&gt;&gt; Can you share your kernel build config? If you don&#39;t know what=
 it is<br>
&gt;&gt; or how to get it, then the next question would be: How did you<br>
&gt;&gt; obtain/build the kernel in question?<br>
&gt;&gt;<br>
&gt;&gt; --<br>
&gt;&gt; Ondrej Mosnacek<br>
&gt;&gt; Senior Software Engineer, Linux Security - SELinux kernel<br>
&gt;&gt; Red Hat, Inc.<br>
&gt;&gt;<br>
<br>
<br>
-- <br>
Ondrej Mosnacek<br>
Senior Software Engineer, Linux Security - SELinux kernel<br>
Red Hat, Inc.<br>
<br>
</blockquote></div>

--00000000000053a0e406026a279d--

--===============6820124258846490405==
Content-Type: text/plain; charset="utf-8"
MIME-Version: 1.0
Content-Transfer-Encoding: base64
Content-Disposition: inline

X19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX18Kc2VsaW51eCBt
YWlsaW5nIGxpc3QgLS0gc2VsaW51eEBsaXN0cy5mZWRvcmFwcm9qZWN0Lm9yZwpUbyB1bnN1YnNj
cmliZSBzZW5kIGFuIGVtYWlsIHRvIHNlbGludXgtbGVhdmVAbGlzdHMuZmVkb3JhcHJvamVjdC5v
cmcKRmVkb3JhIENvZGUgb2YgQ29uZHVjdDogaHR0cHM6Ly9kb2NzLmZlZG9yYXByb2plY3Qub3Jn
L2VuLVVTL3Byb2plY3QvY29kZS1vZi1jb25kdWN0LwpMaXN0IEd1aWRlbGluZXM6IGh0dHBzOi8v
ZmVkb3JhcHJvamVjdC5vcmcvd2lraS9NYWlsaW5nX2xpc3RfZ3VpZGVsaW5lcwpMaXN0IEFyY2hp
dmVzOiBodHRwczovL2xpc3RzLmZlZG9yYXByb2plY3Qub3JnL2FyY2hpdmVzL2xpc3Qvc2VsaW51
eEBsaXN0cy5mZWRvcmFwcm9qZWN0Lm9yZwpEbyBub3QgcmVwbHkgdG8gc3BhbSwgcmVwb3J0IGl0
OiBodHRwczovL3BhZ3VyZS5pby9mZWRvcmEtaW5mcmFzdHJ1Y3R1cmUvbmV3X2lzc3VlCg==

--===============6820124258846490405==--