mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: wzt wzt <wzt.wzt@gmail.com>
To: Tetsuo Handa <penguin-kernel@i-love.sakura.ne.jp>
Cc: linux-kernel@vger.kernel.org,
	linux-security-module@vger.kernel.org, sds@tycho.nsa.gov,
	jmorris@namei.org
Subject: Re: [PATCH] Security: Add __init to register_security to disable load  a security module on runtime
Date: Sat, 27 Feb 2010 11:02:39 +0800	[thread overview]
Message-ID: <628d1651002261902k6b22277dmfa93c01350c1aed6@mail.gmail.com> (raw)
In-Reply-To: <201002271052.AHB64003.OOQLJtFOHVFMSF@I-love.SAKURA.ne.jp>

>That won't become a problem unless kernel command line is tampered.
>Giving permissions to tamper kernel command line is the problem.

The user also can modify /etc/selinuc/config, set SELINUX=disabled.

>Honestly speaking, I prefer register_security() being exported to kernel modules.

New kernel doesn't export register_security() to kernel modules
anymore.  For some reason the user disabled selinux, so the malicious
security modules have a chance to loaded on runtime.  LSM original
intention is not allowed to load security modules on runtime, right?
But if selinux is disabled, they can.

On Sat, Feb 27, 2010 at 9:52 AM, Tetsuo Handa
<penguin-kernel@i-love.sakura.ne.jp> wrote:
> Zhitong Wang wrote:
>> LSM framework doesn't allow to load a security module on runtime, it must be loaded on boot time.
>> but in security/security.c:
>> int register_security(struct security_operations *ops)
>> {
>>         ...
>>         if (security_ops != &default_security_ops)
>>                 return -EAGAIN;
>>         ...
>> }
>> if security_ops == &default_security_ops, it can access to register a security module. If selinux is enabled,
>> other security modules can't register, but if selinux is disabled on boot time, the security_ops was set to
>> default_security_ops, LSM allows other kernel modules to use register_security() to register a not trust
>> security module. For example:
>>
>> disable selinux on boot time(selinux=0).
>
> That won't become a problem unless kernel command line is tampered.
> Giving permissions to tamper kernel command line is the problem.
>
> There are malicious security modules, but non malicious in-tree security
> modules are bothered by two limitations since register_security() is not
> exported to kernel modules since 2.6.24 .
>
> One is the size of vmlinux. Since all security modules have to be compiled
> into vmlinux, it makes difficult for distributors to include multiple security
> modules into vmlinux when there is vmlinux's size limitation. A well-known
> distributor is now considering including TOMOYO in addition to SELinux, but
> the size limitation of vmlinux seems to be the only problem that prevents
> inclusion.
>
> The other is the support provided by distributors. Another well-known
> distributor's support policy is that "We don't provide any support if vmlinux
> or kernel modules provided by us are recompiled. But we provide support if
> kernel modules provided by third party are used without modifying vmlinux and
> kernel modules provided by us." This means that the only way to allow users to
> use TOMOYO with distributor's support is to convince the distributor to include
> TOMOYO into vmlinux. This is a very difficult problem since the distributor
> recommends SELinux.
>
> Honestly speaking, I prefer register_security() being exported to kernel
> modules.
>

  reply	other threads:[~2010-02-27  3:02 UTC|newest]

Thread overview: 7+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2010-02-26 14:49 wzt.wzt
2010-02-27  1:52 ` Tetsuo Handa
2010-02-27  3:02   ` wzt wzt [this message]
2010-02-27  6:30     ` Tetsuo Handa
2010-02-28  5:56       ` wzt wzt
2010-02-28  6:35         ` Tetsuo Handa
2010-03-02 22:17 ` James Morris

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=628d1651002261902k6b22277dmfa93c01350c1aed6@mail.gmail.com \
    --to=wzt.wzt@gmail.com \
    --cc=jmorris@namei.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=linux-security-module@vger.kernel.org \
    --cc=penguin-kernel@i-love.sakura.ne.jp \
    --cc=sds@tycho.nsa.gov \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®