Re: [PATCH v2] obex: transfer obexd to obex_t

Wei Deng <[email protected]> Fri, 22 May 2026 12:49:47 +0530
Newsgroups org.kernel.vger.selinux-refpolicy
Message-ID <[email protected]>
Hi Chris,

On Tue, 12 May 2026 08:36:52 -0400, Christopher J. PeBenito wrote:
> On 4/29/26 9:41 AM, Wei Deng wrote:
> > obexd was running under init_t instead of obex_t because obex.te
> > only declared userdom_user_application_domain(), which does not
> > set up a domain transition from init_t.  Add init_daemon_domain()
> > so that obexd exec'd by init/systemd correctly transitions to obex_t.
> >
> > Also add the permissions observed to be required when obexd runs
> > as obex_t: read sysfs nodes (dev_read_sysfs), register on the
> > D-Bus system bus (dbus_connect_system_bus), and get attributes
> > of bluetooth var-lib directories via the new
> > bluetooth_getattr_var_lib_dirs() interface.
> >
> > Fixes:
> > avc:  denied  { read } for  pid=1751 comm="obexd" name="enabled" dev="sysfs" ino=21530 scontext=system_u:system_r:obex_t:s0 tcontext=system_u:object_r:sysfs_t:s0 tclass=file permissive=0
> >
> > avc:  denied  { acquire_svc } for service=org.bluez.obex spid=1755 scontext=system_u:system_r:obex_t:s0 tcontext=system_u:system_r:system_dbusd_t:s0 tclass=dbus permissive=0 exe="/usr/bin/dbus-daemon" sauid=998 hostname=? addr=? terminal=?
> >
> > avc:  denied  { getattr } for  pid=1826 comm="obexd" path="/var/lib/bluetooth" dev="sda2" ino=1038914 scontext=system_u:system_r:obex_t:s0 tcontext=system_u:object_r:bluetooth_var_lib_t:s0 tclass=dir permissive=0
> >
> > Signed-off-by: Wei Deng <[email protected]>
> > ---
> > Changes in v2:
> > - Complete rework: investigation showed the AVC denial was not
> >    bluetooth_t -> init_t (systemd), but bluetooth_t -> init_t (obexd
> >    running in the wrong domain because obex.te lacked a domain
> >    transition from init_t).  The v1 fix of adding init_dbus_chat() to
> >    bluetooth.te was therefore incorrect.
> > - Fix the root cause by adding init_daemon_domain() to obex.te so
> >    obexd correctly transitions to obex_t when started by init/systemd.
> > - Add permissions needed by obexd once it runs as obex_t: dev_read_sysfs,
> >    dbus_connect_system_bus, and bluetooth_getattr_var_lib_dirs (new
> >    interface in bluetooth.if).
> >
> >   policy/modules/services/bluetooth.if | 19 +++++++++++++++++++
> >   policy/modules/services/obex.te      |  5 +++++
> >   2 files changed, 24 insertions(+)
> >
> > diff --git a/policy/modules/services/bluetooth.if b/policy/modules/services/bluetooth.if
> > index d0e581426..f8226969f 100644
> > --- a/policy/modules/services/bluetooth.if
> > +++ b/policy/modules/services/bluetooth.if
> > @@ -255,6 +255,25 @@ interface(`bluetooth_admin',`
> >   	admin_pattern($1, bluetooth_runtime_t)
> >   ')
> >   
> > +########################################
> > +## <summary>
> > +##	Get the attributes of bluetooth lib directories.
> > +## </summary>
> > +## <param name="domain">
> > +##	<summary>
> > +##	Domain allowed access.
> > +##	</summary>
> > +## </param>
> > +#
> > +interface(`bluetooth_getattr_var_lib_dirs',`
> > +	gen_require(`
> > +		type bluetooth_var_lib_t;
> > +	')
> > +
> > +	allow $1 bluetooth_var_lib_t:dir getattr_dir_perms;
> > +	files_search_var_lib($1)
> > +')
> > +
> >   ########################################
> >   ## <summary>
> >   ##      Get status of bluetooth_unit_t service
> > diff --git a/policy/modules/services/obex.te b/policy/modules/services/obex.te
> > index 5e2f20578..6803123b1 100644
> > --- a/policy/modules/services/obex.te
> > +++ b/policy/modules/services/obex.te
> > @@ -9,6 +9,7 @@ attribute_role obex_roles;
> >   
> >   type obex_t;
> >   type obex_exec_t;
> > +init_daemon_domain(obex_t, obex_exec_t)
> 
> Please make this tunable, since it is not the common case.

Thank you for the review. I have a question about the tunable approach
before sending v3.

init_daemon_domain() expands to typeattribute and role statements, which
are not legal inside a tunable_policy block — so wrapping it directly
would cause a compile error.

Do you have a recommended pattern for this case? Happy to follow
whatever approach you think fits best.

>
> >   userdom_user_application_domain(obex_t, obex_exec_t)
> >   role obex_roles types obex_t;
> >   
> > @@ -20,6 +21,8 @@ role obex_roles types obex_t;
> >   allow obex_t self:fifo_file rw_fifo_file_perms;
> >   allow obex_t self:socket create_stream_socket_perms;
> >   
> > +dev_read_sysfs(obex_t)
> > +
> 
> Please remove the extra blank line.

Noted, will fix in v3.

> >   dev_read_urand(obex_t)
> >   
> >   files_read_etc_files(obex_t)
> > @@ -32,10 +35,12 @@ userdom_search_user_home_content(obex_t)
> >   
> >   optional_policy(`
> >   	bluetooth_use(obex_t)
> > +	bluetooth_getattr_var_lib_dirs(obex_t)
> >   ')
> >   
> >   optional_policy(`
> >   	dbus_system_bus_client(obex_t)
> > +	dbus_connect_system_bus(obex_t)
> >   
> >   	optional_policy(`
> >   		bluetooth_dbus_chat(obex_t)
> 
> -- 
> Chris PeBenito

-- 
Best Regards,
Wei Deng