Re: restorecon ignoring my policy

Zdenek Pytela via selinux <[email protected]> Fri, 3 Jan 2025 17:49:04 +0100
Newsgroups gmane.linux.redhat.fedora.selinux
Message-ID <CAO4UijDDZgEjLrhcGp2f91XCOyTqAWHUd=u37htYxxUGP1BJdQ@mail.gmail.com>
--===============2653587862480686601==
Content-Type: multipart/alternative; boundary="0000000000001d58be062ad00f3e"

--0000000000001d58be062ad00f3e
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

On Sun, Dec 29, 2024 at 10:02=E2=80=AFPM Sam Varshavchik via selinux <
[email protected]> wrote:

> David Sastre Medina via selinux writes:
>
> > I think the /usr/sbin -> /usr/bin addition to file_contexts.subs_dist
> is
> > related to <URL:
> https://discussion.fedoraproject.org/t/f40-change-proposal-
> > unify-usr-bin-and-usr-sbin-system-wide/
> > 99853>
> https://discussion.fedoraproject.org/t/f40-change-proposal-unify-usr-
> > bin-and-usr-sbin-system-wide/99853
>
Correct, the active link for the change is
https://fedoraproject.org/wiki/Changes/Unify_bin_and_sbin

selinux-policy complies to this since Fedora 41 (June to September).
A part of the package there is a script to convert local entries to a
selinux module. It can be debugged with

   DEBUG=3Dyes /usr/libexec/selinux/binsbin-convert.sh targeted

and subsequently the content of /run/selinux-policy checked. If the script
does not work, please report a bug.
Anyway, the long term solution is to change the entries to use /usr/bin.


> I remembered that while I was trying to figure out this Scooby Doo
> mystery,
> yesterday. I checked and /usr/sbin is not a symlink yet, as was proposed
> there, so I figured that the proposal wasn't fully baked.
>
> Still, this nagged in my mind. I decided to see what "semanage fcontext"
> knows about /usr/sbin/* and, it didn't seem to know much. I looked there.
> I
> saw plenty of stuff with labels. Digging through what "semanage fcontext"
> was telling me I found those labels had entries with the /usr/bin prefix,
> which were, of course, referring to nonexistent files. I tried setting
> the
> label for my /usr/sbin binary via /usr/bin and it worked. I felt dirty.
>
> I did see, early in my adventures, that fcontext terminated its braindump
> with "/usr/sbin =3D /usr/bin". I could not find anything in the semanage-
> fcontext man page that explained the output, but it sort of gave me a
> vague,
> general idea, of something like that, which prompted me to look closer at
> the rules, and eventually figure it out.
>
> > Reading the changelog of the selinux-policy RPM, you can read that:
> > - Alias /usr/sbin to /usr/bin and change all /usr/sbin paths to /usr/bi=
n
>
> >
> >
> > was implemented in 41.4-1. Depending on which version you upgraded from=
,
> that
> > may be proof.
>
> According to dnf history I updated from 41.26. I can only say that I
> started
> to get AVCs after this update and I am pretty confident of that. The
> consequence of the AVC was an hourly spam in my mailbox, which was pretty
> loud, and it definitely started then, and not whenever I updated from 41.=
4.
>
> The alias might've been introduced in that version, but up until the
> latest
> update it seems that the alias's handling was much more robust, and it's
> now
> =E2=80=A6less robust. In addition to selinux-policy, I updated glibc and =
the
> kernel.
>
> I almost forgot to mention: my /var/run labels were also broken in my
> policy
> module. For an almost identical reason (except that /var/run is a real
> symlink to /run, so this alias at least makes a little bit more sense).
>
Similarly, the /var/run=3D/run equivalency was inverted and all entries wer=
e
changed in F40 before its GA
and there also is a conversion script in place.
Local policy should use /run.


> --
> _______________________________________________
> selinux mailing list -- [email protected]
> To unsubscribe send an email to [email protected]
> Fedora Code of Conduct:
> https://docs.fedoraproject.org/en-US/project/code-of-conduct/
> List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
> List Archives:
> https://lists.fedoraproject.org/archives/list/[email protected]=
.org
> Do not reply to spam, report it:
> https://pagure.io/fedora-infrastructure/new_issue
>


--=20

Zdenek Pytela
Security SELinux team

--0000000000001d58be062ad00f3e
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><div dir=3D"ltr"><br></div><br><div class=3D"gmail_quote g=
mail_quote_container"><div dir=3D"ltr" class=3D"gmail_attr">On Sun, Dec 29,=
 2024 at 10:02=E2=80=AFPM Sam Varshavchik via selinux &lt;<a href=3D"mailto=
:[email protected]">[email protected]</a>&gt; w=
rote:<br></div><blockquote class=3D"gmail_quote" style=3D"margin:0px 0px 0p=
x 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">David Sast=
re Medina via selinux writes:<br>
<br>
&gt; I think the /usr/sbin -&gt; /usr/bin addition to file_contexts.subs_di=
st is=C2=A0 <br>
&gt; related to &lt;URL:<a href=3D"https://discussion.fedoraproject.org/t/f=
40-change-proposal-" rel=3D"noreferrer" target=3D"_blank">https://discussio=
n.fedoraproject.org/t/f40-change-proposal-</a> <br>
&gt; unify-usr-bin-and-usr-sbin-system-wide/ <br>
&gt; 99853&gt;<a href=3D"https://discussion.fedoraproject.org/t/f40-change-=
proposal-unify-usr-" rel=3D"noreferrer" target=3D"_blank">https://discussio=
n.fedoraproject.org/t/f40-change-proposal-unify-usr-</a> <br>
&gt; bin-and-usr-sbin-system-wide/99853<br></blockquote><div>Correct, the a=
ctive link for the change is=C2=A0</div><div><a href=3D"https://fedoraproje=
ct.org/wiki/Changes/Unify_bin_and_sbin">https://fedoraproject.org/wiki/Chan=
ges/Unify_bin_and_sbin</a></div><div><br></div><div>selinux-policy complies=
 to this since Fedora 41 (June to September).</div><div>A part of the packa=
ge there is a script to convert local entries to a selinux module. It can b=
e debugged with</div><div><br></div><div><span style=3D"font-family:monospa=
ce"><span style=3D"color:rgb(0,0,0);background-color:rgb(255,255,255)"> =C2=
=A0=C2=A0 DEBUG=3Dyes /usr/libexec/selinux/bin</span><span style=3D"color:r=
gb(255,255,255);background-color:rgb(0,0,0)">sbin</span><span style=3D"colo=
r:rgb(0,0,0);background-color:rgb(255,255,255)">-convert.sh targeted</span>=
<br><span style=3D"color:rgb(0,0,0);background-color:rgb(255,255,255)">
</span><br></span></div><div><span style=3D"font-family:arial,sans-serif">a=
nd subsequently the content of /run/selinux-policy checked. If the script d=
oes not work, please report a bug.</span></div><div><span style=3D"font-fam=
ily:arial,sans-serif">Anyway, the long term solution is to change the entri=
es to use /usr/bin.</span></div><div><span style=3D"font-family:arial,sans-=
serif"><br></span></div><blockquote class=3D"gmail_quote" style=3D"margin:0=
px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">
<br>
I remembered that while I was trying to figure out this Scooby Doo mystery,=
=C2=A0 <br>
yesterday. I checked and /usr/sbin is not a symlink yet, as was proposed=C2=
=A0 <br>
there, so I figured that the proposal wasn&#39;t fully baked.<br>
<br>
Still, this nagged in my mind. I decided to see what &quot;semanage fcontex=
t&quot;=C2=A0 <br>
knows about /usr/sbin/* and, it didn&#39;t seem to know much. I looked ther=
e. I=C2=A0 <br>
saw plenty of stuff with labels. Digging through what &quot;semanage fconte=
xt&quot;=C2=A0 <br>
was telling me I found those labels had entries with the /usr/bin prefix,=
=C2=A0 <br>
which were, of course, referring to nonexistent files. I tried setting the=
=C2=A0 <br>
label for my /usr/sbin binary via /usr/bin and it worked. I felt dirty.<br>
<br>
I did see, early in my adventures, that fcontext terminated its braindump=
=C2=A0 <br>
with &quot;/usr/sbin =3D /usr/bin&quot;. I could not find anything in the s=
emanage- <br>
fcontext man page that explained the output, but it sort of gave me a vague=
,=C2=A0 <br>
general idea, of something like that, which prompted me to look closer at=
=C2=A0 <br>
the rules, and eventually figure it out.<br>
<br>
&gt; Reading the changelog of the selinux-policy RPM, you can read that:<br=
>
&gt; - Alias /usr/sbin to /usr/bin and change all /usr/sbin paths to /usr/b=
in =C2=A0 =C2=A0=C2=A0 <br>
&gt; =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =
=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=
=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =
=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0<br>
&gt;<br>
&gt; was implemented in 41.4-1. Depending on which version you upgraded fro=
m, that=C2=A0 <br>
&gt; may be proof.<br>
<br>
According to dnf history I updated from 41.26. I can only say that I starte=
d=C2=A0 <br>
to get AVCs after this update and I am pretty confident of that. The=C2=A0 =
<br>
consequence of the AVC was an hourly spam in my mailbox, which was pretty=
=C2=A0 <br>
loud, and it definitely started then, and not whenever I updated from 41.4.=
<br>
<br>
The alias might&#39;ve been introduced in that version, but up until the la=
test=C2=A0 <br>
update it seems that the alias&#39;s handling was much more robust, and it&=
#39;s now=C2=A0 <br>
=E2=80=A6less robust. In addition to selinux-policy, I updated glibc and th=
e kernel.<br>
<br>
I almost forgot to mention: my /var/run labels were also broken in my polic=
y=C2=A0 <br>
module. For an almost identical reason (except that /var/run is a real=C2=
=A0 <br>
symlink to /run, so this alias at least makes a little bit more sense).<br>=
</blockquote><div>Similarly, the /var/run=3D/run equivalency was inverted a=
nd all entries were changed in F40 before its GA</div><div>and there also i=
s a conversion script in place.</div><div>Local policy should use /run.<br>=
</div><div><br></div><blockquote class=3D"gmail_quote" style=3D"margin:0px =
0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">
<br>
-- <br>
_______________________________________________<br>
selinux mailing list -- <a href=3D"mailto:[email protected]" =
target=3D"_blank">[email protected]</a><br>
To unsubscribe send an email to <a href=3D"mailto:[email protected]=
aproject.org" target=3D"_blank">[email protected]</a><b=
r>
Fedora Code of Conduct: <a href=3D"https://docs.fedoraproject.org/en-US/pro=
ject/code-of-conduct/" rel=3D"noreferrer" target=3D"_blank">https://docs.fe=
doraproject.org/en-US/project/code-of-conduct/</a><br>
List Guidelines: <a href=3D"https://fedoraproject.org/wiki/Mailing_list_gui=
delines" rel=3D"noreferrer" target=3D"_blank">https://fedoraproject.org/wik=
i/Mailing_list_guidelines</a><br>
List Archives: <a href=3D"https://lists.fedoraproject.org/archives/list/sel=
[email protected]" rel=3D"noreferrer" target=3D"_blank">https://=
lists.fedoraproject.org/archives/list/[email protected]</a><b=
r>
Do not reply to spam, report it: <a href=3D"https://pagure.io/fedora-infras=
tructure/new_issue" rel=3D"noreferrer" target=3D"_blank">https://pagure.io/=
fedora-infrastructure/new_issue</a><br>
</blockquote></div><div><br clear=3D"all"></div><br><span class=3D"gmail_si=
gnature_prefix">-- </span><br><div dir=3D"ltr" class=3D"gmail_signature"><d=
iv dir=3D"ltr"><div><div dir=3D"ltr"><div><div dir=3D"ltr"><div><div dir=3D=
"ltr"><div><div dir=3D"ltr"><div><div dir=3D"ltr"><div><div dir=3D"ltr"><br=
>
Zdenek Pytela</div><div dir=3D"ltr">Security SELinux team</div></div></div>=
</div></div></div></div></div></div></div></div></div></div></div></div>

--0000000000001d58be062ad00f3e--


--===============2653587862480686601==
Content-Type: text/plain; charset="utf-8"
MIME-Version: 1.0
Content-Transfer-Encoding: base64
Content-Disposition: inline

LS0gCl9fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fCnNlbGlu
dXggbWFpbGluZyBsaXN0IC0tIHNlbGludXhAbGlzdHMuZmVkb3JhcHJvamVjdC5vcmcKVG8gdW5z
dWJzY3JpYmUgc2VuZCBhbiBlbWFpbCB0byBzZWxpbnV4LWxlYXZlQGxpc3RzLmZlZG9yYXByb2pl
Y3Qub3JnCkZlZG9yYSBDb2RlIG9mIENvbmR1Y3Q6IGh0dHBzOi8vZG9jcy5mZWRvcmFwcm9qZWN0
Lm9yZy9lbi1VUy9wcm9qZWN0L2NvZGUtb2YtY29uZHVjdC8KTGlzdCBHdWlkZWxpbmVzOiBodHRw
czovL2ZlZG9yYXByb2plY3Qub3JnL3dpa2kvTWFpbGluZ19saXN0X2d1aWRlbGluZXMKTGlzdCBB
cmNoaXZlczogaHR0cHM6Ly9saXN0cy5mZWRvcmFwcm9qZWN0Lm9yZy9hcmNoaXZlcy9saXN0L3Nl
bGludXhAbGlzdHMuZmVkb3JhcHJvamVjdC5vcmcKRG8gbm90IHJlcGx5IHRvIHNwYW0sIHJlcG9y
dCBpdDogaHR0cHM6Ly9wYWd1cmUuaW8vZmVkb3JhLWluZnJhc3RydWN0dXJlL25ld19pc3N1ZQo=

--===============2653587862480686601==--