From 356f4be679544363466dad93e7bee68b2a6f2cf0 Mon Sep 17 00:00:00 2001 From: Stephen Smalley Date: Fri, 23 May 2014 11:26:19 -0400 Subject: [PATCH] Restrict requesting contexts other than policy-defined defaults. Writing to the /proc/self/attr files (encapsulated by the libselinux set*con functions) enables a program to request a specific security context for various operations instead of the policy-defined defaults. The security context specified using these calls is checked by an operation-specific permission, e.g. dyntransition for setcon, transition for setexeccon, create for setfscreatecon or setsockcreatecon, but the ability to request a context at all is controlled by a process permission. Omit these permissions from domain.te and only add them back where required so that only specific domains can even request a context other than the default defined by the policy. Change-Id: I6a2fb1279318625a80f3ea8e3f0932bdbe6df676 Signed-off-by: Stephen Smalley --- adbd.te | 1 + domain.te | 2 +- init.te | 6 ++++++ kernel.te | 2 ++ recovery.te | 3 +++ runas.te | 1 + ueventd.te | 3 +++ zygote.te | 1 + 8 files changed, 18 insertions(+), 1 deletion(-) diff --git a/adbd.te b/adbd.te index 44607c712..4b6764759 100644 --- a/adbd.te +++ b/adbd.te @@ -3,6 +3,7 @@ type adbd, domain; userdebug_or_eng(` + allow adbd self:process setcurrent; allow adbd su:process dyntransition; ') diff --git a/domain.te b/domain.te index 5fef04b29..f7e86923f 100644 --- a/domain.te +++ b/domain.te @@ -11,7 +11,7 @@ allow domain tmpfs:file { read getattr }; allow domain tmpfs:dir r_dir_perms; # Intra-domain accesses. -allow domain self:process ~{ execmem execstack execheap ptrace }; +allow domain self:process ~{ execmem execstack execheap ptrace setexec setfscreate setcurrent setkeycreate setsockcreate }; allow domain self:fd use; allow domain self:dir r_dir_perms; allow domain self:lnk_file r_file_perms; diff --git a/init.te b/init.te index 3441dd0c3..e94ca4784 100644 --- a/init.te +++ b/init.te @@ -27,3 +27,9 @@ allow init watchdogd:process transition; # the directory as part of a recursive restorecon. allow init keystore_data_file:dir { open create read getattr setattr search }; allow init keystore_data_file:file { getattr }; + +# Use setexeccon(), setfscreatecon(), and setsockcreatecon(). +# setexec is for services with seclabel options. +# setfscreate is for labeling directories and socket files. +# setsockcreate is for labeling local/unix domain sockets. +allow init self:process { setexec setfscreate setsockcreate }; diff --git a/kernel.te b/kernel.te index 0048a626e..f2405e4fd 100644 --- a/kernel.te +++ b/kernel.te @@ -1,6 +1,8 @@ # Life begins with the kernel. type kernel, domain; +# setcon to init domain. +allow kernel self:process setcurrent; allow kernel init:process dyntransition; # The kernel is unconfined. diff --git a/recovery.te b/recovery.te index cfec16104..c1329833a 100644 --- a/recovery.te +++ b/recovery.te @@ -15,3 +15,6 @@ allow recovery dev_type:blk_file rw_file_perms; allow recovery self:process execmem; allow recovery ashmem_device:chr_file execute; allow recovery tmpfs:file rx_file_perms; + +# Use setfscreatecon() to label files for OTA updates. +allow recovery self:process setfscreate; diff --git a/runas.te b/runas.te index 8648ee711..8cc0eeac9 100644 --- a/runas.te +++ b/runas.te @@ -21,4 +21,5 @@ allow runas self:capability { setuid setgid }; # read /seapp_contexts and /data/security/seapp_contexts security_access_policy(runas) selinux_check_context(runas) # validate context +allow runas self:process setcurrent; allow runas non_system_app_set:process dyntransition; # setcon diff --git a/ueventd.te b/ueventd.te index babebe04d..25460de2b 100644 --- a/ueventd.te +++ b/ueventd.te @@ -20,3 +20,6 @@ allow ueventd dev_type:blk_file { create setattr unlink }; allow ueventd self:netlink_kobject_uevent_socket create_socket_perms; allow ueventd efs_file:dir search; allow ueventd efs_file:file r_file_perms; + +# Use setfscreatecon() to label /dev directories and files. +allow ueventd self:process setfscreate; diff --git a/zygote.te b/zygote.te index 4d169f358..da3a03723 100644 --- a/zygote.te +++ b/zygote.te @@ -9,6 +9,7 @@ allow zygote self:capability { dac_override setgid setuid fowner chown }; # Drop capabilities from bounding set. allow zygote self:capability setpcap; # Switch SELinux context to app domains. +allow zygote self:process setcurrent; allow zygote system_server:process dyntransition; allow zygote appdomain:process dyntransition; # Allow zygote to read app /proc/pid dirs (b/10455872)