Received: by 2002:a25:ad19:0:0:0:0:0 with SMTP id y25csp7251294ybi; Mon, 8 Jul 2019 17:56:12 -0700 (PDT) X-Google-Smtp-Source: APXvYqzV93Ji/5Hpz42OsViTD3ed/V9Fceg3UwMvU+fZ5dIWXKMoXm01tQO8C6sXHwi3vyNUMRtj X-Received: by 2002:a63:553:: with SMTP id 80mr27772684pgf.280.1562633772050; Mon, 08 Jul 2019 17:56:12 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1562633772; cv=none; d=google.com; s=arc-20160816; b=j4Qh44YcNmP6SFSYtmY2Ul2glzy+zuWXNTg7akP3yWVGQ1TZJTBokD8BQBZ1YezUPF Z/swLW2XWK6M+ZvjtYyw6LZ45jjdQYfkbzDapnZLQ06VIfighzzJHhp06hE8CwLJ46dc v1wbZqT+8NcNlXAPX8obsvsQYsKE+7GJOn0bbqmjAEfHzqIIHz3QFG4H4x77MjmvAOk5 +tpkd2tUXu0sv/tI8noTmfhvpNPPKsbK7t3D6CChSexiSykBIpczNDQyG894PhKzmDNQ n3x4t94SDscCpVw4Fb6Z3Ymrqpx+BS/p+AIaL9gkKyDzCDzZryWYe+euoFkXcOuSY/KA cL4Q== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:sender:content-transfer-encoding :content-language:in-reply-to:mime-version:user-agent:date :message-id:from:references:to:subject:dkim-signature; bh=gegLPKKqlVPrpBG5LhjTaB6jPPKoyNA3a8yQg1y+u3w=; b=y9nYQoUiLV+1O8bxxRo4M2RoggoMMo/j1DX1DHWGMlIsa86E40Bl27yFgmga7HMNiz TtD2+0I91bfglsLZUxX9+giR3YOSz2mCnc8HU0B0ixWOwTVP3Tmp9OC8DkpOCdXMmIiF sUkqXy+Z6gt9dlI+QfDmx4/IhJHVmYo4XY6aPK4835MHi7s1XELAiSXkXGbQfPfu8eGj AOr9KTdnt0TWIz0ppkP4CPdAmdm6w079hpIMYc4FeovocbGDe5txPGrnZEr2or4bLl85 l55v2TkSEz0NYfyiyRS3dYqJtvNG9k4OUvE3HnKm5mhAFhh5n6oUJdqRY0brdaz22Tlp oH/Q== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@ieee.org header.s=google header.b=SIBVRl4X; spf=pass (google.com: best guess record for domain of selinux-refpolicy-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=selinux-refpolicy-owner@vger.kernel.org; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=ieee.org Return-Path: Received: from vger.kernel.org (vger.kernel.org. [209.132.180.67]) by mx.google.com with ESMTP id g2si18916138plp.1.2019.07.08.17.56.10; Mon, 08 Jul 2019 17:56:12 -0700 (PDT) Received-SPF: pass (google.com: best guess record for domain of selinux-refpolicy-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) client-ip=209.132.180.67; Authentication-Results: mx.google.com; dkim=pass header.i=@ieee.org header.s=google header.b=SIBVRl4X; spf=pass (google.com: best guess record for domain of selinux-refpolicy-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=selinux-refpolicy-owner@vger.kernel.org; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=ieee.org Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1727142AbfGIAt4 (ORCPT + 11 others); Mon, 8 Jul 2019 20:49:56 -0400 Received: from mail-qt1-f196.google.com ([209.85.160.196]:35812 "EHLO mail-qt1-f196.google.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1725857AbfGIAt4 (ORCPT ); Mon, 8 Jul 2019 20:49:56 -0400 Received: by mail-qt1-f196.google.com with SMTP id d23so20016063qto.2 for ; Mon, 08 Jul 2019 17:49:55 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ieee.org; s=google; h=subject:to:references:from:message-id:date:user-agent:mime-version :in-reply-to:content-language:content-transfer-encoding; bh=gegLPKKqlVPrpBG5LhjTaB6jPPKoyNA3a8yQg1y+u3w=; b=SIBVRl4X6m5y6Q6dO9We1dKlB6AQ3ZlZew/GpoD9BJG+sBM+mFzCmgwvMqxUVpZs2o 96E2n/oky7elnV54/3KL7jNj4n9pJDptNsxU4lwdJcubBxWW7/1+iq9qIvrlbsCbo2D+ lBbfKyjbN2Kr7W3Z5vja6ztG2zV1o6evH5dqQ= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:subject:to:references:from:message-id:date :user-agent:mime-version:in-reply-to:content-language :content-transfer-encoding; bh=gegLPKKqlVPrpBG5LhjTaB6jPPKoyNA3a8yQg1y+u3w=; b=qA2tBIvCs3sZABmJHY3vCknaXNx77pEGz834kgky6sR03PiIqhE6XlgjlpfvUbmSxG v0XL9LwUqi5a4gM/IJ64tn7BzX5YTL0LG8xbkg5MI/XfH5Ul8zM8QXASZRMDlcpKTi8M nBIFoXHcZazHbnF8pe7gxpFkfwEG+ujBa6mt1DQMXKCjiP0oH63xT0/TXaxYu9PlrDYE jJOrjERTwyEpnARgJAt11+IIYf0vgHmFxpOh6SULj9ZvEMICJuLSuxRPJubqr9P07ReX tf1d/td614Y88NLDYxbh1DnJymnY1tC/Htm2Y1Mr6Kxikz2ju09kWUF3UaIrgKFbBFl+ NuXw== X-Gm-Message-State: APjAAAWLBpI97IjUxrb4ICS5moC4KRqD8ysOk58GRGjfNj5G5H2V4p5b A38m1bZbVQJvJzcwLuOzBP6+s59734E= X-Received: by 2002:a0c:d238:: with SMTP id m53mr16327570qvh.161.1562633394924; Mon, 08 Jul 2019 17:49:54 -0700 (PDT) Received: from [192.168.1.190] (pool-108-15-23-247.bltmmd.fios.verizon.net. [108.15.23.247]) by smtp.gmail.com with ESMTPSA id n3sm8435728qkk.54.2019.07.08.17.49.54 (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Mon, 08 Jul 2019 17:49:54 -0700 (PDT) Subject: Re: [PATCH 2/5 - v2] grant permission for rpm to write to audit log To: "Sugar, David" , "selinux-refpolicy@vger.kernel.org" References: <20190702175932.24697-1-dsugar@tresys.com> From: Chris PeBenito Message-ID: Date: Mon, 8 Jul 2019 20:39:45 -0400 User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:60.0) Gecko/20100101 Thunderbird/60.6.1 MIME-Version: 1.0 In-Reply-To: <20190702175932.24697-1-dsugar@tresys.com> Content-Type: text/plain; charset=utf-8; format=flowed Content-Language: en-US Content-Transfer-Encoding: 7bit Sender: selinux-refpolicy-owner@vger.kernel.org Precedence: bulk List-ID: X-Mailing-List: selinux-refpolicy@vger.kernel.org On 7/2/19 1:59 PM, Sugar, David wrote: > Messages like this are added to the audit log when an rpm is installed: > type=SOFTWARE_UPDATE msg=audit(1560913896.581:244): pid=1265 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:rpm_t:s0 msg='sw="ntpdate-4.2.6p5-25.el7_3.2.x86_64" sw_type=rpm key_enforce=0 gpg_res=0 root_dir="/" comm="rpm" exe="/usr/bin/rpm" hostname=? addr=? terminal=? res=success' > > These are the denials that I'm seeing: > type=AVC msg=audit(1560913896.581:243): avc: denied { audit_write } for pid=1265 comm="rpm" capability=29 scontext=system_u:system_r:rpm_t:s0 tcontext=system_u:system_r:rpm_t:s0 tclass=capability permissive=1 > > type=AVC msg=audit(1561298132.446:240): avc: denied { create } for pid=1266 comm="rpm" scontext=system_u:system_r:rpm_t:s0 tcontext=system_u:system_r:rpm_t:s0 tclass=netlink_audit_socket permissive=1 > type=AVC msg=audit(1561298132.446:241): avc: denied { write } for pid=1266 comm="rpm" scontext=system_u:system_r:rpm_t:s0 tcontext=system_u:system_r:rpm_t:s0 tclass=netlink_audit_socket permissive=1 > type=AVC msg=audit(1561298132.446:241): avc: denied { nlmsg_relay } for pid=1266 comm="rpm" scontext=system_u:system_r:rpm_t:s0 tcontext=system_u:system_r:rpm_t:s0 tclass=netlink_audit_socket permissive=1 > type=AVC msg=audit(1561298132.447:243): avc: denied { read } for pid=1266 comm="rpm" scontext=system_u:system_r:rpm_t:s0 tcontext=system_u:system_r:rpm_t:s0 tclass=netlink_audit_socket permissive=1 > > v2 - Use interface rather than adding permissions here - this change may > confuse subsequent patches in this set, if so let me know and I will > submit a pull request on github. > > Signed-off-by: Dave Sugar > --- > policy/modules/admin/rpm.te | 1 + > 1 file changed, 1 insertion(+) > > diff --git a/policy/modules/admin/rpm.te b/policy/modules/admin/rpm.te > index 0e6e9c03..ba022247 100644 > --- a/policy/modules/admin/rpm.te > +++ b/policy/modules/admin/rpm.te > @@ -204,6 +204,7 @@ libs_exec_ld_so(rpm_t) > libs_exec_lib_files(rpm_t) > libs_run_ldconfig(rpm_t, rpm_roles) > > +logging_send_audit_msgs(rpm_t) > logging_send_syslog_msg(rpm_t) > > seutil_manage_src_policy(rpm_t) Merged. -- Chris PeBenito