Re: [RFC] ssh: remove unconfined_shell_domtrans(sshd_t)

Chris PeBenito <[email protected]>
Newsgroups org.kernel.vger.selinux-refpolicy
Message-ID <[email protected]>
On 8/31/19 1:27 PM, Dominick Grift wrote:
> This call allows sshd_t associated processes with run shell with an automatic domain transition to unconfined_t.
> I was unable to make sense of the commit that added this:
> 
> https://github.com/SELinuxProject/refpolicy/commit/708aab13932bb8830a2d37850cc0a5c72a5d4df4
> 
> Debian's motd dynamic pam module makes sshd run a shell, we want this shell to run with sshd_t instead of unconfined_t
> 
> This patch will make the ssh_sysadm_login boolean apply to unconfined ssh logins.
> To me this makes sense, as unconfined_t is targeted equivalent to the strict sysadm_t.
> The boolean could however be renamed to the more generic ssh_priv_login name.
> 
> Signed-off-by: Dominick Grift <[email protected]>
> ---
>   policy/modules/services/ssh.te | 4 ----
>   1 file changed, 4 deletions(-)
> 
> diff --git a/policy/modules/services/ssh.te b/policy/modules/services/ssh.te
> index 4e75b6e1..a99ad912 100644
> --- a/policy/modules/services/ssh.te
> +++ b/policy/modules/services/ssh.te
> @@ -328,10 +328,6 @@ optional_policy(`
>   	systemd_dbus_chat_logind(sshd_t)
>   ')
>   
> -optional_policy(`
> -	unconfined_shell_domtrans(sshd_t)
> -')
> -
>   optional_policy(`
>   	xserver_domtrans_xauth(sshd_t)
>   	xserver_link_xdm_keys(sshd_t)

I don't have any objections to this.

-- 
Chris PeBenito
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.