From: Topi Miettinen Date: Tue, 18 Feb 2020 11:18:39 +0000 (+0200) Subject: namespace: fix MAC labels of /dev when PrivateDevices=yes X-Git-Tag: v246-rc1~759 X-Git-Url: http://git.ipfire.org/gitweb.cgi?a=commitdiff_plain;h=c3151977d7de70b360a3090004d3beb95137f737;p=thirdparty%2Fsystemd.git namespace: fix MAC labels of /dev when PrivateDevices=yes Without changing the SELinux label for private /dev of a service, it will take a generic file system label: system_u:object_r:tmpfs_t:s0 After this change it is the same as without `PrivateDevices=yes`: system_u:object_r:device_t:s0 This helps writing SELinux policies, as the same rules for `/dev` will apply despite any `PrivateDevices=yes` setting. --- diff --git a/src/basic/label.c b/src/basic/label.c index 12a7fb0945e..1fce7718d4b 100644 --- a/src/basic/label.c +++ b/src/basic/label.c @@ -10,11 +10,11 @@ #include "selinux-util.h" #include "smack-util.h" -int label_fix(const char *path, LabelFixFlags flags) { +int label_fix_container(const char *path, const char *inside_path, LabelFixFlags flags) { int r, q; - r = mac_selinux_fix(path, flags); - q = mac_smack_fix(path, flags); + r = mac_selinux_fix_container(path, inside_path, flags); + q = mac_smack_fix_container(path, inside_path, flags); if (r < 0) return r; diff --git a/src/basic/label.h b/src/basic/label.h index 594fd65974c..a6f9074b281 100644 --- a/src/basic/label.h +++ b/src/basic/label.h @@ -9,7 +9,10 @@ typedef enum LabelFixFlags { LABEL_IGNORE_EROFS = 1 << 1, } LabelFixFlags; -int label_fix(const char *path, LabelFixFlags flags); +int label_fix_container(const char *path, const char *inside_path, LabelFixFlags flags); +static inline int label_fix(const char *path, LabelFixFlags flags) { + return label_fix_container(path, path, flags); +} int mkdir_label(const char *path, mode_t mode); int mkdirat_label(int dirfd, const char *path, mode_t mode); diff --git a/src/basic/selinux-util.c b/src/basic/selinux-util.c index 2b5f757134f..2d5e750ea56 100644 --- a/src/basic/selinux-util.c +++ b/src/basic/selinux-util.c @@ -157,7 +157,7 @@ static int mac_selinux_reload(int seqno) { } #endif -int mac_selinux_fix(const char *path, LabelFixFlags flags) { +int mac_selinux_fix_container(const char *path, const char *inside_path, LabelFixFlags flags) { #if HAVE_SELINUX char procfs_path[STRLEN("/proc/self/fd/") + DECIMAL_STR_MAX(int)]; @@ -187,7 +187,7 @@ int mac_selinux_fix(const char *path, LabelFixFlags flags) { /* Check for policy reload so 'label_hnd' is kept up-to-date by callbacks */ (void) avc_netlink_check_nb(); - if (selabel_lookup_raw(label_hnd, &fcon, path, st.st_mode) < 0) { + if (selabel_lookup_raw(label_hnd, &fcon, inside_path, st.st_mode) < 0) { r = -errno; /* If there's no label to set, then exit without warning */ @@ -221,7 +221,7 @@ int mac_selinux_fix(const char *path, LabelFixFlags flags) { return 0; fail: - log_enforcing_errno(r, "Unable to fix SELinux security context of %s: %m", path); + log_enforcing_errno(r, "Unable to fix SELinux security context of %s (%s): %m", path, inside_path); if (mac_selinux_enforcing()) return r; #endif diff --git a/src/basic/selinux-util.h b/src/basic/selinux-util.h index 159f3f16c24..736082cab04 100644 --- a/src/basic/selinux-util.h +++ b/src/basic/selinux-util.h @@ -22,7 +22,11 @@ void mac_selinux_retest(void); int mac_selinux_init(void); void mac_selinux_finish(void); -int mac_selinux_fix(const char *path, LabelFixFlags flags); +int mac_selinux_fix_container(const char *path, const char *inside_path, LabelFixFlags flags); +static inline int mac_selinux_fix(const char *path, LabelFixFlags flags) { + return mac_selinux_fix_container(path, path, flags); +} + int mac_selinux_apply(const char *path, const char *label); int mac_selinux_get_create_label_from_exe(const char *exe, char **label); diff --git a/src/basic/smack-util.c b/src/basic/smack-util.c index da9a2139d31..8043a97c359 100644 --- a/src/basic/smack-util.c +++ b/src/basic/smack-util.c @@ -206,7 +206,7 @@ int mac_smack_fix_at(int dirfd, const char *path, LabelFixFlags flags) { return smack_fix_fd(fd, path, flags); } -int mac_smack_fix(const char *path, LabelFixFlags flags) { +int mac_smack_fix_container(const char *path, const char *inside_path, LabelFixFlags flags) { _cleanup_free_ char *abspath = NULL; _cleanup_close_ int fd = -1; int r; @@ -228,7 +228,7 @@ int mac_smack_fix(const char *path, LabelFixFlags flags) { return -errno; } - return smack_fix_fd(fd, abspath, flags); + return smack_fix_fd(fd, inside_path, flags); } int mac_smack_copy(const char *dest, const char *src) { @@ -274,7 +274,7 @@ int mac_smack_apply_pid(pid_t pid, const char *label) { return 0; } -int mac_smack_fix(const char *path, LabelFixFlags flags) { +int mac_smack_fix_container(const char *path, const char *inside_path, LabelFixFlags flags) { return 0; } diff --git a/src/basic/smack-util.h b/src/basic/smack-util.h index 395ec07b57c..df2ce370716 100644 --- a/src/basic/smack-util.h +++ b/src/basic/smack-util.h @@ -29,7 +29,11 @@ typedef enum SmackAttr { bool mac_smack_use(void); -int mac_smack_fix(const char *path, LabelFixFlags flags); +int mac_smack_fix_container(const char *path, const char *inside_path, LabelFixFlags flags); +static inline int mac_smack_fix(const char *path, LabelFixFlags flags) { + return mac_smack_fix_container(path, path, flags); +} + int mac_smack_fix_at(int dirfd, const char *path, LabelFixFlags flags); const char* smack_attr_to_string(SmackAttr i) _const_; diff --git a/src/core/namespace.c b/src/core/namespace.c index a461a3cce43..d4d6970af37 100644 --- a/src/core/namespace.c +++ b/src/core/namespace.c @@ -690,6 +690,11 @@ static int mount_private_dev(MountEntry *m) { r = log_debug_errno(errno, "Failed to mount tmpfs on '%s': %m", dev); goto fail; } + r = label_fix_container(dev, "/dev", 0); + if (r < 0) { + log_debug_errno(errno, "Failed to fix label of '%s' as /dev: %m", dev); + goto fail; + } devpts = strjoina(temporary_mount, "/dev/pts"); (void) mkdir(devpts, 0755);