Re: restorecon ignoring my policy

Zdenek Pytela via selinux <[email protected]> Thu, 9 Jan 2025 18:57:04 +0100
Newsgroups gmane.linux.redhat.fedora.selinux
Message-ID <CAO4UijBJN=CS7qGzqZeKBPPaYWG=JeWuGB46OVoFeh8RCDqOSg@mail.gmail.com>
--===============0008342990326112660==
Content-Type: multipart/alternative; boundary="00000000000055415b062b49b5ef"

--00000000000055415b062b49b5ef
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

On Fri, Jan 3, 2025 at 6:01=E2=80=AFPM Sam Varshavchik via selinux <
[email protected]> wrote:

> Zdenek Pytela writes:
>
> > Anyway, the long term solution is to change the entries to use /usr/bin=
.
>
> So, right now:
>
> 1. A package installs stuff in /usr/sbin
> 2. It installs an selinux policy file referencing filenames in /usr/bin
>
> Am I the only one who has =E2=80=A6questions, here?
>
Firstly, there is an equivalency supporting the change:

f42# semanage fcontext -l | grep /usr/sbin.=3D
/usr/sbin =3D /usr/bin
f42# ls -Z /usr/sbin/sshd
system_u:object_r:sshd_exec_t:s0 /usr/sbin/sshd
f42# matchpathcon /usr/sbin/sshd
/usr/sbin/sshd  system_u:object_r:sshd_exec_t:s0

Equivalency is a feature to substitute one path in the policy with another.
Secondly, there is a script to take care of all entries referring to
/usr/sbin, e. g. from a local policy module. Feel free to file a bug report
if an improvement is needed.



> --
> _______________________________________________
> selinux mailing list -- [email protected]
> To unsubscribe send an email to [email protected]
> Fedora Code of Conduct:
> https://docs.fedoraproject.org/en-US/project/code-of-conduct/
> List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
> List Archives:
> https://lists.fedoraproject.org/archives/list/[email protected]=
.org
> Do not reply to spam, report it:
> https://pagure.io/fedora-infrastructure/new_issue
>


--=20

Zdenek Pytela
Security SELinux team

--00000000000055415b062b49b5ef
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><div dir=3D"ltr"><br></div><br><div class=3D"gmail_quote g=
mail_quote_container"><div dir=3D"ltr" class=3D"gmail_attr">On Fri, Jan 3, =
2025 at 6:01=E2=80=AFPM Sam Varshavchik via selinux &lt;<a href=3D"mailto:s=
[email protected]">[email protected]</a>&gt; wro=
te:<br></div><blockquote class=3D"gmail_quote" style=3D"margin:0px 0px 0px =
0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">Zdenek Pytel=
a writes:<br>
<br>
&gt; Anyway, the long term solution is to change the entries to use /usr/bi=
n.<br>
<br>
So, right now:<br>
<br>
1. A package installs stuff in /usr/sbin<br>
2. It installs an selinux policy file referencing filenames in /usr/bin<br>
<br>
Am I the only one who has =E2=80=A6questions, here?<br></blockquote><div>Fi=
rstly, there is an equivalency supporting the change:<br></div><div><span s=
tyle=3D"font-family:monospace"><span style=3D"color:rgb(0,0,0);background-c=
olor:rgb(255,255,255)">
</span><br><span style=3D"color:rgb(0,0,0);background-color:rgb(255,255,255=
)">f42# semanage fcontext -l | grep /usr/sbin.=3D</span><span style=3D"colo=
r:rgb(0,0,0);background-color:rgb(255,255,255)">
</span><br><span style=3D"font-weight:bold;color:rgb(255,84,84);background-=
color:rgb(255,255,255)">/usr/sbin =3D</span><span style=3D"color:rgb(0,0,0)=
;background-color:rgb(255,255,255)"> /usr/bin</span><span style=3D"color:rg=
b(0,0,0);background-color:rgb(255,255,255)">
</span><br><span style=3D"color:rgb(0,0,0);background-color:rgb(255,255,255=
)">f42# ls -Z /usr/sbin/sshd</span><span style=3D"color:rgb(0,0,0);backgrou=
nd-color:rgb(255,255,255)">
</span><br><span style=3D"color:rgb(0,0,0);background-color:rgb(255,255,255=
)">system_u:object_r:sshd_exec_t:s0 </span><span style=3D"font-weight:bold;=
color:rgb(84,255,84);background-color:rgb(255,255,255)">/usr/sbin/sshd</spa=
n><span style=3D"color:rgb(0,0,0);background-color:rgb(255,255,255)">
</span><br><span style=3D"color:rgb(0,0,0);background-color:rgb(255,255,255=
)">f42# </span><span style=3D"color:rgb(0,0,0);background-color:rgb(255,255=
,255)">matchpathcon /usr/sbin/sshd</span><span style=3D"color:rgb(0,0,0);ba=
ckground-color:rgb(255,255,255)">
</span><br><span style=3D"color:rgb(0,0,0);background-color:rgb(255,255,255=
)">/usr/sbin/sshd</span><span style=3D"color:rgb(0,0,0);background-color:rg=
b(255,255,255)"> =C2=A0</span><span style=3D"color:rgb(0,0,0);background-co=
lor:rgb(255,255,255)">system_u:object_r:sshd_exec_t:s0</span><br></span></d=
iv><div><br></div><div>Equivalency is a feature to substitute one path in t=
he policy with another.</div><div>Secondly, there is a script to take care =
of all entries referring to /usr/sbin, e. g. from a local policy module. Fe=
el free to file a bug report if an improvement is needed.</div><div><br></d=
iv><div><br></div><blockquote class=3D"gmail_quote" style=3D"margin:0px 0px=
 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">
<br>
-- <br>
_______________________________________________<br>
selinux mailing list -- <a href=3D"mailto:[email protected]" =
target=3D"_blank">[email protected]</a><br>
To unsubscribe send an email to <a href=3D"mailto:[email protected]=
aproject.org" target=3D"_blank">[email protected]</a><b=
r>
Fedora Code of Conduct: <a href=3D"https://docs.fedoraproject.org/en-US/pro=
ject/code-of-conduct/" rel=3D"noreferrer" target=3D"_blank">https://docs.fe=
doraproject.org/en-US/project/code-of-conduct/</a><br>
List Guidelines: <a href=3D"https://fedoraproject.org/wiki/Mailing_list_gui=
delines" rel=3D"noreferrer" target=3D"_blank">https://fedoraproject.org/wik=
i/Mailing_list_guidelines</a><br>
List Archives: <a href=3D"https://lists.fedoraproject.org/archives/list/sel=
[email protected]" rel=3D"noreferrer" target=3D"_blank">https://=
lists.fedoraproject.org/archives/list/[email protected]</a><b=
r>
Do not reply to spam, report it: <a href=3D"https://pagure.io/fedora-infras=
tructure/new_issue" rel=3D"noreferrer" target=3D"_blank">https://pagure.io/=
fedora-infrastructure/new_issue</a><br>
</blockquote></div><div><br clear=3D"all"></div><br><span class=3D"gmail_si=
gnature_prefix">-- </span><br><div dir=3D"ltr" class=3D"gmail_signature"><d=
iv dir=3D"ltr"><div><div dir=3D"ltr"><div><div dir=3D"ltr"><div><div dir=3D=
"ltr"><div><div dir=3D"ltr"><div><div dir=3D"ltr"><div><div dir=3D"ltr"><br=
>
Zdenek Pytela</div><div dir=3D"ltr">Security SELinux team</div></div></div>=
</div></div></div></div></div></div></div></div></div></div></div></div>

--00000000000055415b062b49b5ef--


--===============0008342990326112660==
Content-Type: text/plain; charset="utf-8"
MIME-Version: 1.0
Content-Transfer-Encoding: base64
Content-Disposition: inline

LS0gCl9fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fCnNlbGlu
dXggbWFpbGluZyBsaXN0IC0tIHNlbGludXhAbGlzdHMuZmVkb3JhcHJvamVjdC5vcmcKVG8gdW5z
dWJzY3JpYmUgc2VuZCBhbiBlbWFpbCB0byBzZWxpbnV4LWxlYXZlQGxpc3RzLmZlZG9yYXByb2pl
Y3Qub3JnCkZlZG9yYSBDb2RlIG9mIENvbmR1Y3Q6IGh0dHBzOi8vZG9jcy5mZWRvcmFwcm9qZWN0
Lm9yZy9lbi1VUy9wcm9qZWN0L2NvZGUtb2YtY29uZHVjdC8KTGlzdCBHdWlkZWxpbmVzOiBodHRw
czovL2ZlZG9yYXByb2plY3Qub3JnL3dpa2kvTWFpbGluZ19saXN0X2d1aWRlbGluZXMKTGlzdCBB
cmNoaXZlczogaHR0cHM6Ly9saXN0cy5mZWRvcmFwcm9qZWN0Lm9yZy9hcmNoaXZlcy9saXN0L3Nl
bGludXhAbGlzdHMuZmVkb3JhcHJvamVjdC5vcmcKRG8gbm90IHJlcGx5IHRvIHNwYW0sIHJlcG9y
dCBpdDogaHR0cHM6Ly9wYWd1cmUuaW8vZmVkb3JhLWluZnJhc3RydWN0dXJlL25ld19pc3N1ZQo=

--===============0008342990326112660==--