Re: restorecon ignoring my policy
Sam Varshavchik via selinux <[email protected]> Sun, 29 Dec 2024 11:44:43 -0500
| Newsgroups | gmane.linux.redhat.fedora.selinux |
|---|---|
| Message-ID | <[email protected]> |
This is a MIME GnuPG-signed message. If you see this text, it means that
your E-mail or Usenet software does not support MIME signed messages.
The Internet standard for MIME PGP messages, RFC 2015, was published in 1996.
To open this message correctly you will need to install E-mail or Usenet
software that supports modern Internet standards.
--===============4964024144112415061==
Content-Type: multipart/signed;
boundary="=_ripper.email-scan.com-209723-1735490683-0001";
micalg=pgp-sha1; protocol="application/pgp-signature"
This is a MIME GnuPG-signed message. If you see this text, it means that
your E-mail or Usenet software does not support MIME signed messages.
The Internet standard for MIME PGP messages, RFC 2015, was published in 1996.
To open this message correctly you will need to install E-mail or Usenet
software that supports modern Internet standards.
--=_ripper.email-scan.com-209723-1735490683-0001
Content-Type: text/plain; format=flowed; delsp=yes; charset=utf-8
Content-Transfer-Encoding: quoted-printable
Content-Disposition: inline
David Sastre Medina via selinux writes:
> Contexts potentially affected:
>
>
> ```
> $ rg ^/usr/sbin /etc/selinux/targeted/contexts/files/file_contexts
> 4104:/usr/sbin/tlshd =C2=A0 =C2=A0-- =C2=A0 =C2=A0 =C2=A0system_u:objec=
t_r:ktlshd_exec_t:s0
> 4304:/usr/sbin/nbdkit =C2=A0 -- =C2=A0 =C2=A0 =C2=A0system_u:object_r:n=
bdkit_exec_t:s0
> 4305:/usr/sbin/smartd =C2=A0 -- =C2=A0 =C2=A0 =C2=A0system_u:object_r:f=
sdaemon_exec_t:s0
> 5663:/usr/sbin/rhel-push-plugin -- =C2=A0 =C2=A0 =20
> =C2=A0system_u:object_r:container_runtime_exec_t:s0
> 5749:/usr/sbin/pcm-sensor-server =C2=A0 =C2=A0 =C2=A0 =C2=A0-- =C2=A0 =C2=
=A0 =20
> =C2=A0system_u:object_r:pcmsensor_exec_t:s0
>
> ```
>
>
>
> And the culprit would be an aliasing rule:
>
>
>
> ```
> $ rg bin /etc/selinux/targeted/contexts/files/file_contexts.subs_dist
> 29:/sbin =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0/usr/bi=
n
> 33:/bin =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 /usr/bi=
n
> 34:/usr/sbin =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0/usr/bin # <-----=
------
> Assuming (I haven't checked, I could be wrong) `restorecon` uses labels =20
> returned by `selabel_lookup`, it makes sense it thinks the context is =20
> correct.
Something other than restorecon got changed. I did not start getting AVCs =20
until I installed a week's worth of updates.
dnf history shows that I installed version 0:41.27-1 of selinux policy =20
packages. I had no issues prior to installing this update.
It appears that many packages are already aware of this =E2=80=A6feature. =
The abrt-=20
dbus package, for example, installs /usr/sbin/abrt-dbus, but includes a =20
label for:
[root@jack ~]# semanage fcontext --list | grep abrt_exec_t
/usr/bin/abrt-dbus regular file sys=
tem_u:object_r:abrt_exec_t:s0
This is very confusing.
--=_ripper.email-scan.com-209723-1735490683-0001
Content-Type: application/pgp-signature
Content-Transfer-Encoding: 7bit
-----BEGIN PGP SIGNATURE-----
iHUEABYKAB0WIQRupkKLJP96aW75pIOKYPgoojZS4gUCZ3F8ewAKCRCKYPgoojZS
4gyTAQDfZpR8DR+xW7u2h7FdnWlCRDtuTAcZ0tL0rbffUuu8hQEAxsImeTPe66DI
//scl6niSvAvx1eNhkWVSQ82wehjuAY=
=rP/g
-----END PGP SIGNATURE-----
--=_ripper.email-scan.com-209723-1735490683-0001--
--===============4964024144112415061==
Content-Type: text/plain; charset="utf-8"
MIME-Version: 1.0
Content-Transfer-Encoding: base64
Content-Disposition: inline
LS0gCl9fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fCnNlbGlu
dXggbWFpbGluZyBsaXN0IC0tIHNlbGludXhAbGlzdHMuZmVkb3JhcHJvamVjdC5vcmcKVG8gdW5z
dWJzY3JpYmUgc2VuZCBhbiBlbWFpbCB0byBzZWxpbnV4LWxlYXZlQGxpc3RzLmZlZG9yYXByb2pl
Y3Qub3JnCkZlZG9yYSBDb2RlIG9mIENvbmR1Y3Q6IGh0dHBzOi8vZG9jcy5mZWRvcmFwcm9qZWN0
Lm9yZy9lbi1VUy9wcm9qZWN0L2NvZGUtb2YtY29uZHVjdC8KTGlzdCBHdWlkZWxpbmVzOiBodHRw
czovL2ZlZG9yYXByb2plY3Qub3JnL3dpa2kvTWFpbGluZ19saXN0X2d1aWRlbGluZXMKTGlzdCBB
cmNoaXZlczogaHR0cHM6Ly9saXN0cy5mZWRvcmFwcm9qZWN0Lm9yZy9hcmNoaXZlcy9saXN0L3Nl
bGludXhAbGlzdHMuZmVkb3JhcHJvamVjdC5vcmcKRG8gbm90IHJlcGx5IHRvIHNwYW0sIHJlcG9y
dCBpdDogaHR0cHM6Ly9wYWd1cmUuaW8vZmVkb3JhLWluZnJhc3RydWN0dXJlL25ld19pc3N1ZQo=
--===============4964024144112415061==--