Re: restorecon ignoring my policy

Sam Varshavchik via selinux <[email protected]> Sun, 29 Dec 2024 16:02:14 -0500
Newsgroups gmane.linux.redhat.fedora.selinux
Message-ID <[email protected]>
This is a MIME GnuPG-signed message.  If you see this text, it means that
your E-mail or Usenet software does not support MIME signed messages.
The Internet standard for MIME PGP messages, RFC 2015, was published in 1996.
To open this message correctly you will need to install E-mail or Usenet
software that supports modern Internet standards.

--===============9090795038670929554==
Content-Type: multipart/signed;
    boundary="=_ripper.email-scan.com-212396-1735506134-0001";
    micalg=pgp-sha1; protocol="application/pgp-signature"

This is a MIME GnuPG-signed message.  If you see this text, it means that
your E-mail or Usenet software does not support MIME signed messages.
The Internet standard for MIME PGP messages, RFC 2015, was published in 1996.
To open this message correctly you will need to install E-mail or Usenet
software that supports modern Internet standards.

--=_ripper.email-scan.com-212396-1735506134-0001
Content-Type: text/plain; format=flowed; delsp=yes; charset=utf-8
Content-Transfer-Encoding: quoted-printable
Content-Disposition: inline

David Sastre Medina via selinux writes:

> I think the /usr/sbin -> /usr/bin addition to file_contexts.subs_dist i=
s =20
> related to <URL:https://discussion.fedoraproject.org/t/f40-change-propo=
sal-=20
> unify-usr-bin-and-usr-sbin-system-wide/=20
> 99853>https://discussion.fedoraproject.org/t/f40-change-proposal-unify-=
usr-=20
> bin-and-usr-sbin-system-wide/99853

I remembered that while I was trying to figure out this Scooby Doo myster=
y, =20
yesterday. I checked and /usr/sbin is not a symlink yet, as was proposed =20
there, so I figured that the proposal wasn't fully baked.

Still, this nagged in my mind. I decided to see what "semanage fcontext" =20
knows about /usr/sbin/* and, it didn't seem to know much. I looked there. =
I =20
saw plenty of stuff with labels. Digging through what "semanage fcontext" =20
was telling me I found those labels had entries with the /usr/bin prefix, =20
which were, of course, referring to nonexistent files. I tried setting th=
e =20
label for my /usr/sbin binary via /usr/bin and it worked. I felt dirty.

I did see, early in my adventures, that fcontext terminated its braindump =20
with "/usr/sbin =3D /usr/bin". I could not find anything in the semanage-=20
fcontext man page that explained the output, but it sort of gave me a vag=
ue, =20
general idea, of something like that, which prompted me to look closer at =20
the rules, and eventually figure it out.

> Reading the changelog of the selinux-policy RPM, you can read that:
> - Alias /usr/sbin to /usr/bin and change all /usr/sbin paths to /usr/bi=
n =C2=A0 =C2=A0 =20
> =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=
=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =
=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=
=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0
>
> was implemented in 41.4-1. Depending on which version you upgraded from=
, that =20
> may be proof.

According to dnf history I updated from 41.26. I can only say that I star=
ted =20
to get AVCs after this update and I am pretty confident of that. The =20
consequence of the AVC was an hourly spam in my mailbox, which was pretty =20
loud, and it definitely started then, and not whenever I updated from 41.=
4.

The alias might've been introduced in that version, but up until the late=
st =20
update it seems that the alias's handling was much more robust, and it's =
now =20
=E2=80=A6less robust. In addition to selinux-policy, I updated glibc and =
the kernel.

I almost forgot to mention: my /var/run labels were also broken in my pol=
icy =20
module. For an almost identical reason (except that /var/run is a real =20
symlink to /run, so this alias at least makes a little bit more sense).


--=_ripper.email-scan.com-212396-1735506134-0001
Content-Type: application/pgp-signature
Content-Transfer-Encoding: 7bit

-----BEGIN PGP SIGNATURE-----

iHUEABYKAB0WIQRupkKLJP96aW75pIOKYPgoojZS4gUCZ3G41gAKCRCKYPgoojZS
4o+zAP0Qqf+ag5S3cgRgT66IIikfRpFtAHq2RiQOxj4uJVLxEQEAjHcGhbY/RfmQ
tkB1S//1lX6VR8jA2jfQGpS+IDYrTQQ=
=xHT4
-----END PGP SIGNATURE-----

--=_ripper.email-scan.com-212396-1735506134-0001--

--===============9090795038670929554==
Content-Type: text/plain; charset="utf-8"
MIME-Version: 1.0
Content-Transfer-Encoding: base64
Content-Disposition: inline

LS0gCl9fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fCnNlbGlu
dXggbWFpbGluZyBsaXN0IC0tIHNlbGludXhAbGlzdHMuZmVkb3JhcHJvamVjdC5vcmcKVG8gdW5z
dWJzY3JpYmUgc2VuZCBhbiBlbWFpbCB0byBzZWxpbnV4LWxlYXZlQGxpc3RzLmZlZG9yYXByb2pl
Y3Qub3JnCkZlZG9yYSBDb2RlIG9mIENvbmR1Y3Q6IGh0dHBzOi8vZG9jcy5mZWRvcmFwcm9qZWN0
Lm9yZy9lbi1VUy9wcm9qZWN0L2NvZGUtb2YtY29uZHVjdC8KTGlzdCBHdWlkZWxpbmVzOiBodHRw
czovL2ZlZG9yYXByb2plY3Qub3JnL3dpa2kvTWFpbGluZ19saXN0X2d1aWRlbGluZXMKTGlzdCBB
cmNoaXZlczogaHR0cHM6Ly9saXN0cy5mZWRvcmFwcm9qZWN0Lm9yZy9hcmNoaXZlcy9saXN0L3Nl
bGludXhAbGlzdHMuZmVkb3JhcHJvamVjdC5vcmcKRG8gbm90IHJlcGx5IHRvIHNwYW0sIHJlcG9y
dCBpdDogaHR0cHM6Ly9wYWd1cmUuaW8vZmVkb3JhLWluZnJhc3RydWN0dXJlL25ld19pc3N1ZQo=

--===============9090795038670929554==--