Re: restorecon ignoring my policy
Zdenek Pytela via selinux <[email protected]> Fri, 3 Jan 2025 17:49:04 +0100
| Newsgroups | gmane.linux.redhat.fedora.selinux |
|---|---|
| Message-ID | <CAO4UijDDZgEjLrhcGp2f91XCOyTqAWHUd=u37htYxxUGP1BJdQ@mail.gmail.com> |
--===============2653587862480686601== Content-Type: multipart/alternative; boundary="0000000000001d58be062ad00f3e" --0000000000001d58be062ad00f3e Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable On Sun, Dec 29, 2024 at 10:02=E2=80=AFPM Sam Varshavchik via selinux < [email protected]> wrote: > David Sastre Medina via selinux writes: > > > I think the /usr/sbin -> /usr/bin addition to file_contexts.subs_dist > is > > related to <URL: > https://discussion.fedoraproject.org/t/f40-change-proposal- > > unify-usr-bin-and-usr-sbin-system-wide/ > > 99853> > https://discussion.fedoraproject.org/t/f40-change-proposal-unify-usr- > > bin-and-usr-sbin-system-wide/99853 > Correct, the active link for the change is https://fedoraproject.org/wiki/Changes/Unify_bin_and_sbin selinux-policy complies to this since Fedora 41 (June to September). A part of the package there is a script to convert local entries to a selinux module. It can be debugged with DEBUG=3Dyes /usr/libexec/selinux/binsbin-convert.sh targeted and subsequently the content of /run/selinux-policy checked. If the script does not work, please report a bug. Anyway, the long term solution is to change the entries to use /usr/bin. > I remembered that while I was trying to figure out this Scooby Doo > mystery, > yesterday. I checked and /usr/sbin is not a symlink yet, as was proposed > there, so I figured that the proposal wasn't fully baked. > > Still, this nagged in my mind. I decided to see what "semanage fcontext" > knows about /usr/sbin/* and, it didn't seem to know much. I looked there. > I > saw plenty of stuff with labels. Digging through what "semanage fcontext" > was telling me I found those labels had entries with the /usr/bin prefix, > which were, of course, referring to nonexistent files. I tried setting > the > label for my /usr/sbin binary via /usr/bin and it worked. I felt dirty. > > I did see, early in my adventures, that fcontext terminated its braindump > with "/usr/sbin =3D /usr/bin". I could not find anything in the semanage- > fcontext man page that explained the output, but it sort of gave me a > vague, > general idea, of something like that, which prompted me to look closer at > the rules, and eventually figure it out. > > > Reading the changelog of the selinux-policy RPM, you can read that: > > - Alias /usr/sbin to /usr/bin and change all /usr/sbin paths to /usr/bi= n > > > > > > > was implemented in 41.4-1. Depending on which version you upgraded from= , > that > > may be proof. > > According to dnf history I updated from 41.26. I can only say that I > started > to get AVCs after this update and I am pretty confident of that. The > consequence of the AVC was an hourly spam in my mailbox, which was pretty > loud, and it definitely started then, and not whenever I updated from 41.= 4. > > The alias might've been introduced in that version, but up until the > latest > update it seems that the alias's handling was much more robust, and it's > now > =E2=80=A6less robust. In addition to selinux-policy, I updated glibc and = the > kernel. > > I almost forgot to mention: my /var/run labels were also broken in my > policy > module. For an almost identical reason (except that /var/run is a real > symlink to /run, so this alias at least makes a little bit more sense). > Similarly, the /var/run=3D/run equivalency was inverted and all entries wer= e changed in F40 before its GA and there also is a conversion script in place. Local policy should use /run. > -- > _______________________________________________ > selinux mailing list -- [email protected] > To unsubscribe send an email to [email protected] > Fedora Code of Conduct: > https://docs.fedoraproject.org/en-US/project/code-of-conduct/ > List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines > List Archives: > https://lists.fedoraproject.org/archives/list/[email protected]= .org > Do not reply to spam, report it: > https://pagure.io/fedora-infrastructure/new_issue > --=20 Zdenek Pytela Security SELinux team --0000000000001d58be062ad00f3e Content-Type: text/html; charset="UTF-8" Content-Transfer-Encoding: quoted-printable <div dir=3D"ltr"><div dir=3D"ltr"><br></div><br><div class=3D"gmail_quote g= mail_quote_container"><div dir=3D"ltr" class=3D"gmail_attr">On Sun, Dec 29,= 2024 at 10:02=E2=80=AFPM Sam Varshavchik via selinux <<a href=3D"mailto= :[email protected]">[email protected]</a>> w= rote:<br></div><blockquote class=3D"gmail_quote" style=3D"margin:0px 0px 0p= x 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">David Sast= re Medina via selinux writes:<br> <br> > I think the /usr/sbin -> /usr/bin addition to file_contexts.subs_di= st is=C2=A0 <br> > related to <URL:<a href=3D"https://discussion.fedoraproject.org/t/f= 40-change-proposal-" rel=3D"noreferrer" target=3D"_blank">https://discussio= n.fedoraproject.org/t/f40-change-proposal-</a> <br> > unify-usr-bin-and-usr-sbin-system-wide/ <br> > 99853><a href=3D"https://discussion.fedoraproject.org/t/f40-change-= proposal-unify-usr-" rel=3D"noreferrer" target=3D"_blank">https://discussio= n.fedoraproject.org/t/f40-change-proposal-unify-usr-</a> <br> > bin-and-usr-sbin-system-wide/99853<br></blockquote><div>Correct, the a= ctive link for the change is=C2=A0</div><div><a href=3D"https://fedoraproje= ct.org/wiki/Changes/Unify_bin_and_sbin">https://fedoraproject.org/wiki/Chan= ges/Unify_bin_and_sbin</a></div><div><br></div><div>selinux-policy complies= to this since Fedora 41 (June to September).</div><div>A part of the packa= ge there is a script to convert local entries to a selinux module. It can b= e debugged with</div><div><br></div><div><span style=3D"font-family:monospa= ce"><span style=3D"color:rgb(0,0,0);background-color:rgb(255,255,255)"> =C2= =A0=C2=A0 DEBUG=3Dyes /usr/libexec/selinux/bin</span><span style=3D"color:r= gb(255,255,255);background-color:rgb(0,0,0)">sbin</span><span style=3D"colo= r:rgb(0,0,0);background-color:rgb(255,255,255)">-convert.sh targeted</span>= <br><span style=3D"color:rgb(0,0,0);background-color:rgb(255,255,255)"> </span><br></span></div><div><span style=3D"font-family:arial,sans-serif">a= nd subsequently the content of /run/selinux-policy checked. If the script d= oes not work, please report a bug.</span></div><div><span style=3D"font-fam= ily:arial,sans-serif">Anyway, the long term solution is to change the entri= es to use /usr/bin.</span></div><div><span style=3D"font-family:arial,sans-= serif"><br></span></div><blockquote class=3D"gmail_quote" style=3D"margin:0= px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"> <br> I remembered that while I was trying to figure out this Scooby Doo mystery,= =C2=A0 <br> yesterday. I checked and /usr/sbin is not a symlink yet, as was proposed=C2= =A0 <br> there, so I figured that the proposal wasn't fully baked.<br> <br> Still, this nagged in my mind. I decided to see what "semanage fcontex= t"=C2=A0 <br> knows about /usr/sbin/* and, it didn't seem to know much. I looked ther= e. I=C2=A0 <br> saw plenty of stuff with labels. Digging through what "semanage fconte= xt"=C2=A0 <br> was telling me I found those labels had entries with the /usr/bin prefix,= =C2=A0 <br> which were, of course, referring to nonexistent files. I tried setting the= =C2=A0 <br> label for my /usr/sbin binary via /usr/bin and it worked. I felt dirty.<br> <br> I did see, early in my adventures, that fcontext terminated its braindump= =C2=A0 <br> with "/usr/sbin =3D /usr/bin". I could not find anything in the s= emanage- <br> fcontext man page that explained the output, but it sort of gave me a vague= ,=C2=A0 <br> general idea, of something like that, which prompted me to look closer at= =C2=A0 <br> the rules, and eventually figure it out.<br> <br> > Reading the changelog of the selinux-policy RPM, you can read that:<br= > > - Alias /usr/sbin to /usr/bin and change all /usr/sbin paths to /usr/b= in =C2=A0 =C2=A0=C2=A0 <br> > =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 = =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2= =A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 = =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0<br> ><br> > was implemented in 41.4-1. Depending on which version you upgraded fro= m, that=C2=A0 <br> > may be proof.<br> <br> According to dnf history I updated from 41.26. I can only say that I starte= d=C2=A0 <br> to get AVCs after this update and I am pretty confident of that. The=C2=A0 = <br> consequence of the AVC was an hourly spam in my mailbox, which was pretty= =C2=A0 <br> loud, and it definitely started then, and not whenever I updated from 41.4.= <br> <br> The alias might've been introduced in that version, but up until the la= test=C2=A0 <br> update it seems that the alias's handling was much more robust, and it&= #39;s now=C2=A0 <br> =E2=80=A6less robust. In addition to selinux-policy, I updated glibc and th= e kernel.<br> <br> I almost forgot to mention: my /var/run labels were also broken in my polic= y=C2=A0 <br> module. For an almost identical reason (except that /var/run is a real=C2= =A0 <br> symlink to /run, so this alias at least makes a little bit more sense).<br>= </blockquote><div>Similarly, the /var/run=3D/run equivalency was inverted a= nd all entries were changed in F40 before its GA</div><div>and there also i= s a conversion script in place.</div><div>Local policy should use /run.<br>= </div><div><br></div><blockquote class=3D"gmail_quote" style=3D"margin:0px = 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"> <br> -- <br> _______________________________________________<br> selinux mailing list -- <a href=3D"mailto:[email protected]" = target=3D"_blank">[email protected]</a><br> To unsubscribe send an email to <a href=3D"mailto:[email protected]= aproject.org" target=3D"_blank">[email protected]</a><b= r> Fedora Code of Conduct: <a href=3D"https://docs.fedoraproject.org/en-US/pro= ject/code-of-conduct/" rel=3D"noreferrer" target=3D"_blank">https://docs.fe= doraproject.org/en-US/project/code-of-conduct/</a><br> List Guidelines: <a href=3D"https://fedoraproject.org/wiki/Mailing_list_gui= delines" rel=3D"noreferrer" target=3D"_blank">https://fedoraproject.org/wik= i/Mailing_list_guidelines</a><br> List Archives: <a href=3D"https://lists.fedoraproject.org/archives/list/sel= [email protected]" rel=3D"noreferrer" target=3D"_blank">https://= lists.fedoraproject.org/archives/list/[email protected]</a><b= r> Do not reply to spam, report it: <a href=3D"https://pagure.io/fedora-infras= tructure/new_issue" rel=3D"noreferrer" target=3D"_blank">https://pagure.io/= fedora-infrastructure/new_issue</a><br> </blockquote></div><div><br clear=3D"all"></div><br><span class=3D"gmail_si= gnature_prefix">-- </span><br><div dir=3D"ltr" class=3D"gmail_signature"><d= iv dir=3D"ltr"><div><div dir=3D"ltr"><div><div dir=3D"ltr"><div><div dir=3D= "ltr"><div><div dir=3D"ltr"><div><div dir=3D"ltr"><div><div dir=3D"ltr"><br= > Zdenek Pytela</div><div dir=3D"ltr">Security SELinux team</div></div></div>= </div></div></div></div></div></div></div></div></div></div></div></div> --0000000000001d58be062ad00f3e-- --===============2653587862480686601== Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: base64 Content-Disposition: inline LS0gCl9fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fCnNlbGlu dXggbWFpbGluZyBsaXN0IC0tIHNlbGludXhAbGlzdHMuZmVkb3JhcHJvamVjdC5vcmcKVG8gdW5z dWJzY3JpYmUgc2VuZCBhbiBlbWFpbCB0byBzZWxpbnV4LWxlYXZlQGxpc3RzLmZlZG9yYXByb2pl Y3Qub3JnCkZlZG9yYSBDb2RlIG9mIENvbmR1Y3Q6IGh0dHBzOi8vZG9jcy5mZWRvcmFwcm9qZWN0 Lm9yZy9lbi1VUy9wcm9qZWN0L2NvZGUtb2YtY29uZHVjdC8KTGlzdCBHdWlkZWxpbmVzOiBodHRw czovL2ZlZG9yYXByb2plY3Qub3JnL3dpa2kvTWFpbGluZ19saXN0X2d1aWRlbGluZXMKTGlzdCBB cmNoaXZlczogaHR0cHM6Ly9saXN0cy5mZWRvcmFwcm9qZWN0Lm9yZy9hcmNoaXZlcy9saXN0L3Nl bGludXhAbGlzdHMuZmVkb3JhcHJvamVjdC5vcmcKRG8gbm90IHJlcGx5IHRvIHNwYW0sIHJlcG9y dCBpdDogaHR0cHM6Ly9wYWd1cmUuaW8vZmVkb3JhLWluZnJhc3RydWN0dXJlL25ld19pc3N1ZQo= --===============2653587862480686601==--