Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org X-Spam-Level: X-Spam-Status: No, score=-1.1 required=3.0 tests=DKIMWL_WL_HIGH,DKIM_SIGNED, DKIM_VALID,DKIM_VALID_AU,HEADER_FROM_DIFFERENT_DOMAINS,MAILING_LIST_MULTI, SPF_PASS,URIBL_BLOCKED autolearn=ham autolearn_force=no version=3.4.0 Received: from mail.kernel.org (mail.kernel.org [198.145.29.99]) by smtp.lore.kernel.org (Postfix) with ESMTP id D36B8C43381 for ; Tue, 12 Mar 2019 00:50:45 +0000 (UTC) Received: from vger.kernel.org (vger.kernel.org [209.132.180.67]) by mail.kernel.org (Postfix) with ESMTP id A01602084F for ; Tue, 12 Mar 2019 00:50:45 +0000 (UTC) Authentication-Results: mail.kernel.org; dkim=pass (1024-bit key) header.d=ieee.org header.i=@ieee.org header.b="G63vdzlq" Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1726709AbfCLAup (ORCPT ); Mon, 11 Mar 2019 20:50:45 -0400 Received: from mail-qt1-f178.google.com ([209.85.160.178]:45848 "EHLO mail-qt1-f178.google.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1725861AbfCLAup (ORCPT ); Mon, 11 Mar 2019 20:50:45 -0400 Received: by mail-qt1-f178.google.com with SMTP id v20so702911qtv.12 for ; Mon, 11 Mar 2019 17:50:44 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ieee.org; s=google; h=subject:to:cc:references:from:message-id:date:user-agent :mime-version:in-reply-to:content-language:content-transfer-encoding; bh=IEqIzulZJqxKEbLxaRsC+KGJd3pDFoI0KV5bkEfH2wc=; b=G63vdzlqiVpCGJ5mJ87//qFxK8fc7hSxOY3MRdOXskQAQPKT0bmYqK2be2gP5qXCuq KcTB/xS4bJJmoowYlLAPRn5EljVdX2tgiwAfCZ1kUxMDBW9CIvWLUggnLgpasNS4chv/ I9OJF+H4vNN3tXMVVg7tC2EzQGKcZG7EtoB/8= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:subject:to:cc:references:from:message-id:date :user-agent:mime-version:in-reply-to:content-language :content-transfer-encoding; bh=IEqIzulZJqxKEbLxaRsC+KGJd3pDFoI0KV5bkEfH2wc=; b=fRG1d2Oau4tDuxb/yTS+Sb7sBl6Ahyyy9FI8lH/HXFifASWg93hh9nB+tB5WYJqASo 49gJdlM60TOcD5bY/YPYhKU2v5/fOGL8h0vD/yATWWpkY5AyPU67Ywl116afGGPt2JF1 ur4snMiGxMrWcdRXbya5llpRm77WLtGTJi8cREibErymoU9sd78F8Qn+qNjfk6YEOTP2 4dOTl5YkPmJoeMuStfShFaIQUmQUczv/+ODeZb2BW44YbOGGmE8L3h+baSDI+XgvUScI SOcsFwBKlE1AGmnYl4eppflrlO7hiX78wp5I9NTRYAS4ui57cddhQSh8unkOK8W1+I4N uKLA== X-Gm-Message-State: APjAAAXRfr3hI/ALLi56pF4X2yPKVCiOiHPbCOs2o/tzvxImjems+Jv8 RIWg8526GzM+nr/zFXvx71QFj1o5NdA= X-Google-Smtp-Source: APXvYqzgnMUrYf4yzA3pmpTy6sP0MZBEzpSJv1YdC89q/9s1ujUuQudXzTVWauvQIKT0kPPMLguQUA== X-Received: by 2002:a0c:ae78:: with SMTP id z53mr27769098qvc.235.1552351843983; Mon, 11 Mar 2019 17:50:43 -0700 (PDT) Received: from [192.168.1.190] (pool-108-15-23-247.bltmmd.fios.verizon.net. [108.15.23.247]) by smtp.gmail.com with ESMTPSA id h10sm8588183qta.3.2019.03.11.17.50.43 (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Mon, 11 Mar 2019 17:50:43 -0700 (PDT) Subject: Re: what's up with mac_admin To: Dominick Grift , Russell Coker Cc: "selinux-refpolicy@vger.kernel.org" References: <2502654.FxcCWanWCu@liv> <87ftrtx5p2.fsf@gmail.com> From: Chris PeBenito Message-ID: <2b937872-7fbd-a3bc-9bcd-b659cf360d04@ieee.org> Date: Mon, 11 Mar 2019 20:50:43 -0400 User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:60.0) Gecko/20100101 Thunderbird/60.3.0 MIME-Version: 1.0 In-Reply-To: <87ftrtx5p2.fsf@gmail.com> Content-Type: text/plain; charset=utf-8; format=flowed Content-Language: en-US Content-Transfer-Encoding: 7bit Sender: selinux-refpolicy-owner@vger.kernel.org Precedence: bulk List-ID: X-Mailing-List: selinux-refpolicy@vger.kernel.org On 3/11/19 2:53 AM, Dominick Grift wrote: > Russell Coker writes: > >> type=AVC msg=audit(1552226284.038:2422): avc: denied { mac_admin } for >> pid=8289 comm="rsync" capability=33 >> scontext=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 >> tcontext=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 tclass=capability2 >> permissive=0 > > Its for setting invalid labels. Something you generally want to avoid. Correct. There used to be a neverallow, but when that was removed, we forgot to remove the comment in access_vectors. It's gone now. >> >> The above is from running rsync with the -X option. >> >> $ grep -R mac_admin . >> ./policy/flask/access_vectors: mac_admin # unused by SELinux >> ./policy/modules/apps/livecd.te:dontaudit livecd_t self:capability2 mac_admin; >> >> Grepping the git policy shows that there's a comment saying it's unused as >> well as a dontaudit rule indicating that it has been used for some time. > -- Chris PeBenito