Bug 1549691 - RFE: enable the process:getrlimit permission in the SELinux policy
Summary: RFE: enable the process:getrlimit permission in the SELinux policy
Keywords:
Status: CLOSED RAWHIDE
Alias: None
Product: Fedora
Classification: Fedora
Component: selinux-policy
Version: rawhide
Hardware: All
OS: Linux
unspecified
unspecified
Target Milestone: ---
Assignee: Lukas Vrabec
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard:
Depends On:
Blocks: 1549772
TreeView+ depends on / blocked
 
Reported: 2018-02-27 16:32 UTC by Paul Moore
Modified: 2018-07-09 19:49 UTC (History)
5 users (show)

Fixed In Version:
Clone Of:
: 1549772 (view as bug list)
Environment:
Last Closed: 2018-03-05 16:15:51 UTC
Type: Bug
Embargoed:


Attachments (Terms of Use)

Description Paul Moore 2018-02-27 16:32:32 UTC
Description of problem:
The current Fedora SELinux policy does not support the process:getrlimit which was added in Linux v4.12.  The kernel commit provides a good description of the new permission:

    commit 791ec491c372f49cea3ea7a7143454a9023ac9d4
    Author: Stephen Smalley <sds.gov>
    Date:   Fri Feb 17 07:57:00 2017 -0500

    prlimit,security,selinux: add a security hook for prlimit
    
    When SELinux was first added to the kernel, a process could only get
    and set its own resource limits via getrlimit(2) and setrlimit(2), so no
    MAC checks were required for those operations, and thus no security hooks
    were defined for them. Later, SELinux introduced a hook for setlimit(2)
    with a check if the hard limit was being changed in order to be able to
    rely on the hard limit value as a safe reset point upon context
    transitions.
    
    Later on, when prlimit(2) was added to the kernel with the ability to get
    or set resource limits (hard or soft) of another process, LSM/SELinux was
    not updated other than to pass the target process to the setrlimit hook.
    This resulted in incomplete control over both getting and setting the
    resource limits of another process.
    
    Add a new security_task_prlimit() hook to the check_prlimit_permission()
    function to provide complete mediation.  The hook is only called when
    acting on another task, and only if the existing DAC/capability checks
    would allow access.  Pass flags down to the hook to indicate whether the
    prlimit(2) call will read, write, or both read and write the resource
    limits of the target process.
    
    The existing security_task_setrlimit() hook is left alone; it continues
    to serve a purpose in supporting the ability to make decisions based on
    the old and/or new resource limit values when setting limits.  This
    is consistent with the DAC/capability logic, where
    check_prlimit_permission() performs generic DAC/capability checks for
    acting on another task, while do_prlimit() performs a capability check
    based on a comparison of the old and new resource limits.  Fix the
    inline documentation for the hook to match the code.
    
    Implement the new hook for SELinux.  For setting resource limits, we
    reuse the existing setrlimit permission.  Note that this does overload      
    the setrlimit permission to mean the ability to set the resource limit      
    (soft or hard) of another process or the ability to change one's own        
    hard limit.  For getting resource limits, a new getrlimit permission        
    is defined.  This was not originally defined since getrlimit(2) could       
    only be used to obtain a process' own limits.                               
                                                                                
    Signed-off-by: Stephen Smalley <sds.gov>                          
    Signed-off-by: James Morris <james.l.morris> 

Version-Release number of selected component (if applicable):

selinux-policy-3.14.2-2.fc28.6.noarch

Actual results:

# dmesg | grep -i "selinux" | grep "getrlimit"
[    1.971064] SELinux:  Permission getrlimit in class process not defined in policy.

Additional info:

Upstream kernel commit which added the process:getrlimit permission:

* https://git.kernel.org/pub/scm/linux/kernel/git/pcmoore/selinux.git/commit/?h=stable-4.12&id=791ec491c372f49cea3ea7a7143454a9023ac9d4

Comment 2 Lukas Vrabec 2018-03-05 16:15:51 UTC
commit 836d6c4f0f86e5fd6008d78a4ddf2332e77af548
Author: Stephen Smalley <sds.gov>
Date:   Wed May 17 11:33:46 2017 -0400

    refpolicy: Define getrlimit permission for class process
    
    This permission was added to the kernel in commit 791ec491c372
    ("prlimit,security,selinux: add a security hook for prlimit")
    circa Linux 4.12 in order to control the ability to get the resource
    limits of another process.  It is only checked when acting on another
    process, so getrlimit permission is not required for use of getrlimit(2).
    
    Signed-off-by: Stephen Smalley <sds.gov>


# sesearch -A -c process -p getrlimit | wc -l 
51


Fedora Rawhide/28 builds with getrlimit permission
https://koji.fedoraproject.org/koji/buildinfo?buildID=1053702
https://koji.fedoraproject.org/koji/buildinfo?buildID=1053698


Note You need to log in before you can comment on or make changes to this bug.