431bdd9f2f
Add a definition for the extended_socket_class policy capability used to enable the use of separate socket security classes for all network address families rather than the generic socket class. The capability also enables the use of separate security classes for ICMP and SCTP sockets, which were previously mapped to rawip_socket class. Add definitions for the new socket classes and access vectors enabled by this capability. Add the new socket classes to the socket_class_set macro, and exclude them from webview_zygote domain as with other socket classes. Allowing access by specific domains to the new socket security classes is left to future commits. Domains previously allowed permissions to the 'socket' class will require permission to the more specific socket class when running on kernels with this support. The kernel support will be included upstream in Linux 4.11. The relevant kernel commits are da69a5306ab92e07224da54aafee8b1dccf024f6 ("selinux: support distinctions among all network address families"), ef37979a2cfa3905adbf0c2a681ce16c0aaea92d ("selinux: handle ICMPv6 consistently with ICMP"), and b4ba35c75a0671a06b978b6386b54148efddf39f ("selinux: drop unused socket security classes"). This change requires selinux userspace commit d479baa82d67c9ac56c1a6fa041abfb9168aa4b3 ("libsepol: Define extended_socket_class policy capability") in order to build the policy with this capability enabled. This commit is already in AOSP master. Test: policy builds Change-Id: I788b4be9f0ec0bf2356c0bbef101cd42a1af49bb Signed-off-by: Stephen Smalley <sds@tycho.nsa.gov>
48 lines
3.3 KiB
Text
48 lines
3.3 KiB
Text
#####################################
|
|
# Common groupings of object classes.
|
|
#
|
|
define(`capability_class_set', `{ capability capability2 }')
|
|
|
|
define(`devfile_class_set', `{ chr_file blk_file }')
|
|
define(`notdevfile_class_set', `{ file lnk_file sock_file fifo_file }')
|
|
define(`file_class_set', `{ devfile_class_set notdevfile_class_set }')
|
|
define(`dir_file_class_set', `{ dir file_class_set }')
|
|
|
|
define(`socket_class_set', `{ socket tcp_socket udp_socket rawip_socket netlink_socket packet_socket key_socket unix_stream_socket unix_dgram_socket appletalk_socket netlink_route_socket netlink_firewall_socket netlink_tcpdiag_socket netlink_nflog_socket netlink_xfrm_socket netlink_selinux_socket netlink_audit_socket netlink_ip6fw_socket netlink_dnrt_socket netlink_kobject_uevent_socket tun_socket netlink_iscsi_socket netlink_fib_lookup_socket netlink_connector_socket netlink_netfilter_socket netlink_generic_socket netlink_scsitransport_socket netlink_rdma_socket netlink_crypto_socket sctp_socket icmp_socket ax25_socket ipx_socket netrom_socket atmpvc_socket x25_socket rose_socket decnet_socket atmsvc_socket rds_socket irda_socket pppox_socket llc_socket can_socket tipc_socket bluetooth_socket iucv_socket rxrpc_socket isdn_socket phonet_socket ieee802154_socket caif_socket alg_socket nfc_socket vsock_socket kcm_socket qipcrtr_socket }')
|
|
define(`dgram_socket_class_set', `{ udp_socket unix_dgram_socket }')
|
|
define(`stream_socket_class_set', `{ tcp_socket unix_stream_socket }')
|
|
define(`unpriv_socket_class_set', `{ tcp_socket udp_socket unix_stream_socket unix_dgram_socket }')
|
|
|
|
define(`ipc_class_set', `{ sem msgq shm ipc }')
|
|
|
|
#####################################
|
|
# Common groupings of permissions.
|
|
#
|
|
define(`x_file_perms', `{ getattr execute execute_no_trans }')
|
|
define(`r_file_perms', `{ getattr open read ioctl lock }')
|
|
define(`w_file_perms', `{ open append write lock }')
|
|
define(`rx_file_perms', `{ r_file_perms x_file_perms }')
|
|
define(`ra_file_perms', `{ r_file_perms append }')
|
|
define(`rw_file_perms', `{ r_file_perms w_file_perms }')
|
|
define(`rwx_file_perms', `{ rw_file_perms x_file_perms }')
|
|
define(`create_file_perms', `{ create rename setattr unlink rw_file_perms }')
|
|
|
|
define(`r_dir_perms', `{ open getattr read search ioctl lock }')
|
|
define(`w_dir_perms', `{ open search write add_name remove_name lock }')
|
|
define(`ra_dir_perms', `{ r_dir_perms add_name write }')
|
|
define(`rw_dir_perms', `{ r_dir_perms w_dir_perms }')
|
|
define(`create_dir_perms', `{ create reparent rename rmdir setattr rw_dir_perms }')
|
|
|
|
define(`r_ipc_perms', `{ getattr read associate unix_read }')
|
|
define(`w_ipc_perms', `{ write unix_write }')
|
|
define(`rw_ipc_perms', `{ r_ipc_perms w_ipc_perms }')
|
|
define(`create_ipc_perms', `{ create setattr destroy rw_ipc_perms }')
|
|
|
|
#####################################
|
|
# Common socket permission sets.
|
|
define(`rw_socket_perms', `{ ioctl read getattr write setattr lock append bind connect getopt setopt shutdown }')
|
|
define(`rw_socket_perms_no_ioctl', `{ read getattr write setattr lock append bind connect getopt setopt shutdown }')
|
|
define(`create_socket_perms', `{ create rw_socket_perms }')
|
|
define(`create_socket_perms_no_ioctl', `{ create rw_socket_perms_no_ioctl }')
|
|
define(`rw_stream_socket_perms', `{ rw_socket_perms listen accept }')
|
|
define(`create_stream_socket_perms', `{ create rw_stream_socket_perms }')
|