Re: Intent to add support for cryfs

Dominick Grift <[email protected]>
Newsgroups org.kernel.vger.selinux-refpolicy
Message-ID <[email protected]>
On Sun, Nov 10, 2019 at 07:32:43PM +0100, Nicolas Iooss wrote:
> Hello,
> I am using CryFS (https://www.cryfs.org/) in order to encrypt some
> files in a shared directory. Before writing a policy for this software
> and upstreaming it to refpolicy, I am wondering how this should be
> handled.

Sounds somewhat like gocryptfs.
This is how i implemented policy for that:
https://defensec.nl/gitweb/dssp2.git/blob/HEAD:/policy/applications/g/gocryptfs.cil


> 
> CryFS is a software that can be run by non-root users that have access
> to /dev/fuse. Its command is directly used to mount a directory
> ("/usr/bin/cryfs basedir mountpoint"), like command "mount".
> Unmounting a mountpoint is done with "fusermount -u mountpoint",
> /usr/bin/fusermount being a setuid-root program labeled mount_exec_t.
> Currently, sysadm_t cannot use CryFS because it is not allowed to open
> and use /dev/fuse (ie. fuse_device_t). Moreover labeling CryFS as
> mount_exec_t makes mount_t require more accesses (reading a
> configuration file from the base directory, reading
> /proc/sys/crypto/fips_enabled, using pipes, etc.).
> 
> Therefore I am thinking of creating a new policy module for cryfs,
> which could be shared with other similar software like EncFS
> (https://vgough.github.io/encfs/). Does this sound like something
> acceptable? Did I miss an existing module that can be extended in
> order to support CryFS?
> 
> Thanks,
> Nicolas
> 

-- 
Key fingerprint = 5F4D 3CDB D3F8 3652 FBD8 02D5 3B6C 5F1D 2C7B 6B02
https://sks-keyservers.net/pks/lookup?op=get&search=0x3B6C5F1D2C7B6B02
Dominick Grift
signature.asc (application/pgp-signature, 659 B)
-----BEGIN PGP SIGNATURE-----

iQGzBAEBCAAdFiEEujmXliIBLFTc2Y4AJXSOVTf5R2kFAl3KiVYACgkQJXSOVTf5
R2kAlgv9HgNwap5KNTYEHRZwJD6sC1V14GbCOvBRxhvLfiadM3Ib/jVP7r23p2aU
2qyHSPpWOs0HCXKYWAd7p0gX5XnabqrJxOYWLyTKd9S/LIoIOlQpi87I81AW4ZoV
vNE4c1j8bCx+bBnOIQmBjOILCywY5fTCyxYKNzp3Fv6zJn22K7E6da4u8ki0UkTH
9Sr5hSJo4HNgGBMNPP7RqBzH1perj35hMjIEc0F9wBO9LKqdGqB5RX5jSZ4PazI0
pGw+u5KZxsJkVMEG3AY782GcIqu8lJqu0fQd/F64810vA/WDWCYbZNbPnDoL2cTM
wCom6jNPNnjy6PhFPN6IQ20rIV5rnhnGKD/lxUN5qSGWbNer5aIbDeNIBUbrNnsu
zLTBRuoVK2e/YUg0zzIzHhW8Ix4zUaSZDLi8gZaXmsGqEPLeKvJRKhLagXcvfHrl
yTBxzVJzZ8C8uuwYFQ0fjoOYcdTgWXTsq+h+eRfzFpWodGL6p0pdL7kW3lJcTxJG
JcQQdhxz
=5Bh4
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.