Re: [PATCH 2/5] grant permission for rpm to write to audit log

Dominick Grift <[email protected]>
Newsgroups org.kernel.vger.selinux-refpolicy
Message-ID <[email protected]>
On Tue, Jul 02, 2019 at 03:30:30PM +0000, Sugar, David wrote:
> Messages like this are added to the audit log when an rpm is installed:
> type=SOFTWARE_UPDATE msg=audit(1560913896.581:244): pid=1265 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:rpm_t:s0 msg='sw="ntpdate-4.2.6p5-25.el7_3.2.x86_64" sw_type=rpm key_enforce=0 gpg_res=0 root_dir="/" comm="rpm" exe="/usr/bin/rpm" hostname=? addr=?  terminal=? res=success'
> 
> These are the denials that I'm seeing:
> type=AVC msg=audit(1560913896.581:243): avc:  denied  { audit_write } for  pid=1265 comm="rpm" capability=29 scontext=system_u:system_r:rpm_t:s0 tcontext=system_u:system_r:rpm_t:s0 tclass=capability permissive=1
> 
> type=AVC msg=audit(1561298132.446:240): avc:  denied  { create } for pid=1266 comm="rpm" scontext=system_u:system_r:rpm_t:s0 tcontext=system_u:system_r:rpm_t:s0 tclass=netlink_audit_socket permissive=1
> type=AVC msg=audit(1561298132.446:241): avc:  denied  { write } for pid=1266 comm="rpm" scontext=system_u:system_r:rpm_t:s0 tcontext=system_u:system_r:rpm_t:s0 tclass=netlink_audit_socket permissive=1
> type=AVC msg=audit(1561298132.446:241): avc:  denied  { nlmsg_relay } for  pid=1266 comm="rpm" scontext=system_u:system_r:rpm_t:s0 tcontext=system_u:system_r:rpm_t:s0 tclass=netlink_audit_socket permissive=1
> type=AVC msg=audit(1561298132.447:243): avc:  denied  { read } for pid=1266 comm="rpm" scontext=system_u:system_r:rpm_t:s0 tcontext=system_u:system_r:rpm_t:s0 tclass=netlink_audit_socket permissive=1

There is an interface for that: logging_send_audit_msgs(rpm_t)

> 
> Signed-off-by: Dave Sugar <[email protected]>
> ---
>  policy/modules/admin/rpm.te | 3 ++-
>  1 file changed, 2 insertions(+), 1 deletion(-)
> 
> diff --git a/policy/modules/admin/rpm.te b/policy/modules/admin/rpm.te
> index 0e6e9c03..a28a24d3 100644
> --- a/policy/modules/admin/rpm.te
> +++ b/policy/modules/admin/rpm.te
> @@ -73,7 +73,7 @@ files_tmpfs_file(rpm_script_tmpfs_t)
>  # rpm Local policy
>  #
>  
> -allow rpm_t self:capability { chown dac_override fowner fsetid ipc_lock mknod setfcap setgid setuid sys_chroot sys_nice sys_tty_config };
> +allow rpm_t self:capability { audit_write chown dac_override fowner fsetid ipc_lock mknod setfcap setgid setuid sys_chroot sys_nice sys_tty_config };
>  allow rpm_t self:process { transition signal_perms getsched setsched getsession getpgid setpgid getcap setcap share getattr setexec setfscreate noatsecure siginh setrlimit rlimitinh dyntransition execmem setkeycreate setsockcreate getrlimit };
>  allow rpm_t self:fd use;
>  allow rpm_t self:fifo_file rw_fifo_file_perms;
> @@ -87,6 +87,7 @@ allow rpm_t self:msgq create_msgq_perms;
>  allow rpm_t self:msg { send receive };
>  allow rpm_t self:file rw_file_perms;
>  allow rpm_t self:netlink_kobject_uevent_socket create_socket_perms;
> +allow rpm_t self:netlink_audit_socket { nlmsg_relay create_socket_perms };
>  
>  allow rpm_t rpm_log_t:file { append_file_perms create_file_perms setattr_file_perms };
>  logging_log_filetrans(rpm_t, rpm_log_t, file)
> -- 
> 2.21.0
> 

-- 
Key fingerprint = 5F4D 3CDB D3F8 3652 FBD8 02D5 3B6C 5F1D 2C7B 6B02
https://sks-keyservers.net/pks/lookup?op=get&search=0x3B6C5F1D2C7B6B02
Dominick Grift
signature.asc (application/pgp-signature, 659 B)
-----BEGIN PGP SIGNATURE-----

iQGzBAEBCAAdFiEEujmXliIBLFTc2Y4AJXSOVTf5R2kFAl0bgGMACgkQJXSOVTf5
R2k+BAv/dudwUGASFZcXKaGuLiLsdp1CufpwFWdvYuj7GedUOEG/Of+1vAL0Lrx2
VTQWfp/wZLl1zCg1Y5MxRBLaRNMsETvXc1c9rWexPIikufMR0TlUmUyw2goHIA+x
IPaEbJQiywFXP3p6Owv2ZhWPJ+R6JQhLhJWaZCmG4ckiK+LYM1zNRQvg2dESeWTD
Xwv65vYImUmnvtFU6nc8SG5O99syULeYbWf0ekT60o/XHbF61k86ynQAf3BKQfnR
nCFpZ5tJKPI11pWiYjGQbVW1kproRFq3vk7/voP+Eu46ezYfFvyDX3BhTL+1X6S+
T1CbFdKkqTrqZXD/fjpM3dp6VP+3fXOFudKR34XqMr8rEIhnJR7Pzn62XCU6jg6W
xF1wITBM8g4D29TzsWkotb5fXVg7ccKJnq7I39srajDqu/FWIgB7X+YuXMem8pGh
i6eI/Es8Kkb0NznBk6/NCklsqUiXEJ5wlWKieARIPZ/hnOEkOK/ml7+1GJ3VGoUQ
UHHkBDO5
=rbta
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.