mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: Alan Cox <alan@lxorguk.ukuu.org.uk>
To: Eric Paris <eparis@redhat.com>
Cc: linux-kernel@vger.kernel.org, selinux@tycho.nsa.gov,
	linux-security-module@vger.kernel.org, sds@tycho.nsa.gov,
	jmorris@namei.org, spender@grsecurity.net, dwalsh@redhat.com,
	cl@linux-foundation.org, arjan@infradead.org, kyle@mcmartin.ca,
	cpardy@redhat.com, arnd@arndb.de
Subject: Re: [PATCH 1/2] VM/SELinux: require CAP_SYS_RAWIO for all mmap_zero operations
Date: Tue, 21 Jul 2009 17:09:09 +0100	[thread overview]
Message-ID: <20090721170909.6182230c@lxorguk.ukuu.org.uk> (raw)
In-Reply-To: <1248191833.2654.320.camel@localhost>

> This just seemed reasonable, since the Kconfig default is 4096 that's
> what most people have anyway right?

Yes - its rather inadequate when there are multi-page objects floating
around to exploit (remember you only need writes through data pointers for
exploits not executable code)

> runcon -t wine_t [my exploit]
> win.
> 
> So now I have to stop allowing unconfined_t to specifically run things
> as wine_t.  Easy enough to get around
> 
> chcon -t wine_exec_t [my exploit]
> win.
> 
> Well crap, now I have to stop letting unconfined_t label things
> wine_exec_t.  Easy enough to get around if you can load it as an rpm
> (ok, this step is probably harder)

If I can load it as an rpm then I'm the superuser and I already won so
that case isn't too bad really is it ?

So far you've described in SELinux the equivalent of

"user must not be able to chown and setuid their files to someone else"

which was hardly news in 1970 ;)

> and hell, how do I know I can't just get wine some windows program to
> get win to map the page for me?

Mathematical absolutes don't work here. How do you know 4K is enough, 64K
is enough - you never do that either. You can only make it a lot harder.

> unconfined is such a monstrosity it's too hard to get a handle on.  Make
> everyone log in as user_t (man semanage) and you will be better (but I
> haven't proven it is safe...)

Ok.

> and you still could.  Just set mmap_min_addr = 0 and you get SELinux
> protection for confined domains.  I'll gladly add an selinux tunable if
> people like it so SELinux users who don't want to enforce the uid=0 rule
> can do exactly everything they can do today.
> 
> Someone on this list has to know a wine guru.  Seems to me there has to
> be a way that we can give wine CAP_SYS_RAWIO just long enough to map the
> page so non-SELinux users aren't left in the lurch they are today.

I did look - but wine doesn't simply wrap itself around an application,
run it and die. The wine execution model is rather more complicated and
the need to map page zero can thus pop up later on. Some of the other
users you can do this with, and most of the other ones like LRMI of
course are CAP_SYS_RAWIO *anyway* as the main user of this stuff is vm86
bios execution.

It's a really ugly problem that almost begs for better hardware
facilities (such as the multiple independent address spaces in some
processors)


  reply	other threads:[~2009-07-21 16:09 UTC|newest]

Thread overview: 10+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2009-07-21 14:41 Eric Paris
2009-07-21 14:42 ` [PATCH 2/2] SELinux: selinux_file_mmap always enforce mapping the 0 page Eric Paris
2009-07-21 15:04 ` [PATCH 1/2] VM/SELinux: require CAP_SYS_RAWIO for all mmap_zero operations Alan Cox
2009-07-21 15:18   ` Eric Paris
2009-07-21 15:38     ` Alan Cox
2009-07-21 15:57       ` Eric Paris
2009-07-21 16:09         ` Alan Cox [this message]
2009-07-21 16:23           ` Eric Paris
2009-07-21 16:30             ` Alan Cox
2009-07-29 15:06       ` Pavel Machek

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20090721170909.6182230c@lxorguk.ukuu.org.uk \
    --to=alan@lxorguk.ukuu.org.uk \
    --cc=arjan@infradead.org \
    --cc=arnd@arndb.de \
    --cc=cl@linux-foundation.org \
    --cc=cpardy@redhat.com \
    --cc=dwalsh@redhat.com \
    --cc=eparis@redhat.com \
    --cc=jmorris@namei.org \
    --cc=kyle@mcmartin.ca \
    --cc=linux-kernel@vger.kernel.org \
    --cc=linux-security-module@vger.kernel.org \
    --cc=sds@tycho.nsa.gov \
    --cc=selinux@tycho.nsa.gov \
    --cc=spender@grsecurity.net \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®