01d95c23ab
Define new netlink socket security classes introduced by upstream kernel commit 6c6d2e9bde1c1c87a7ead806f8f5e2181d41a652 ("selinux: update netlink socket classes"). This was merged in Linux 4.2 and is therefore only required for Android kernels based on 4.2 or newer (e.g. the android-4.4 branch of the kernel/common tree). Add the new socket classes to socket_class_set. Add an initial set of allow rules although further refinement will likely be necessary. Any allow rule previously written on :netlink_socket may need to be rewritten or duplicated for one or more of the more specific classes. For now, we retain the existing :netlink_socket rules for compatibility on older kernels. Change-Id: I5040b30edd2d374538490a080feda96dd4bae5bf Signed-off-by: Stephen Smalley <sds@tycho.nsa.gov>
46 lines
2.7 KiB
Text
46 lines
2.7 KiB
Text
#####################################
|
|
# Common groupings of object classes.
|
|
#
|
|
define(`capability_class_set', `{ capability capability2 }')
|
|
|
|
define(`devfile_class_set', `{ chr_file blk_file }')
|
|
define(`notdevfile_class_set', `{ file lnk_file sock_file fifo_file }')
|
|
define(`file_class_set', `{ devfile_class_set notdevfile_class_set }')
|
|
define(`dir_file_class_set', `{ dir file_class_set }')
|
|
|
|
define(`socket_class_set', `{ socket tcp_socket udp_socket rawip_socket netlink_socket packet_socket key_socket unix_stream_socket unix_dgram_socket appletalk_socket netlink_route_socket netlink_firewall_socket netlink_tcpdiag_socket netlink_nflog_socket netlink_xfrm_socket netlink_selinux_socket netlink_audit_socket netlink_ip6fw_socket netlink_dnrt_socket netlink_kobject_uevent_socket tun_socket netlink_iscsi_socket netlink_fib_lookup_socket netlink_connector_socket netlink_netfilter_socket netlink_generic_socket netlink_scsitransport_socket netlink_rdma_socket netlink_crypto_socket }')
|
|
define(`dgram_socket_class_set', `{ udp_socket unix_dgram_socket }')
|
|
define(`stream_socket_class_set', `{ tcp_socket unix_stream_socket }')
|
|
define(`unpriv_socket_class_set', `{ tcp_socket udp_socket unix_stream_socket unix_dgram_socket }')
|
|
|
|
define(`ipc_class_set', `{ sem msgq shm ipc }')
|
|
|
|
#####################################
|
|
# Common groupings of permissions.
|
|
#
|
|
define(`x_file_perms', `{ getattr execute execute_no_trans }')
|
|
define(`r_file_perms', `{ getattr open read ioctl lock }')
|
|
define(`w_file_perms', `{ open append write }')
|
|
define(`rx_file_perms', `{ r_file_perms x_file_perms }')
|
|
define(`ra_file_perms', `{ r_file_perms append }')
|
|
define(`rw_file_perms', `{ r_file_perms w_file_perms }')
|
|
define(`rwx_file_perms', `{ rw_file_perms x_file_perms }')
|
|
define(`create_file_perms', `{ create rename setattr unlink rw_file_perms }')
|
|
|
|
define(`r_dir_perms', `{ open getattr read search ioctl }')
|
|
define(`w_dir_perms', `{ open search write add_name remove_name }')
|
|
define(`ra_dir_perms', `{ r_dir_perms add_name write }')
|
|
define(`rw_dir_perms', `{ r_dir_perms w_dir_perms }')
|
|
define(`create_dir_perms', `{ create reparent rename rmdir setattr rw_dir_perms }')
|
|
|
|
define(`r_ipc_perms', `{ getattr read associate unix_read }')
|
|
define(`w_ipc_perms', `{ write unix_write }')
|
|
define(`rw_ipc_perms', `{ r_ipc_perms w_ipc_perms }')
|
|
define(`create_ipc_perms', `{ create setattr destroy rw_ipc_perms }')
|
|
|
|
#####################################
|
|
# Common socket permission sets.
|
|
define(`rw_socket_perms', `{ ioctl read getattr write setattr lock append bind connect getopt setopt shutdown }')
|
|
define(`create_socket_perms', `{ create rw_socket_perms }')
|
|
define(`rw_stream_socket_perms', `{ rw_socket_perms listen accept }')
|
|
define(`create_stream_socket_perms', `{ create rw_stream_socket_perms }')
|