485 |
domain ACL. For example, |
domain ACL. For example, |
486 |
|
|
487 |
"1 /bin/sh if task.euid!=0" |
"1 /bin/sh if task.euid!=0" |
488 |
|
|
489 |
allows the domain to execute /bin/sh only when the process's euid |
allows the domain to execute /bin/sh only when the process's euid |
490 |
is not 0, and |
is not 0, and |
491 |
|
|
871 |
based on realpath while argv[0] check is done based on the symlink's |
based on realpath while argv[0] check is done based on the symlink's |
872 |
pathname and argv[0], this specification will allow attackers behave |
pathname and argv[0], this specification will allow attackers behave |
873 |
as /bin/cat in the domain of /bin/ls if "/bin/ls and /bin/cat are |
as /bin/cat in the domain of /bin/ls if "/bin/ls and /bin/cat are |
874 |
links to /sbin/busybox" and "the attacker is permitted to create |
links to /sbin/busybox" and "the attacker is permitted to create |
875 |
a symlink named ~/cat that points to /bin/ls" and "the attacker is |
a symlink named ~/cat that points to /bin/ls" and "the attacker is |
876 |
permitted to run /bin/ls". |
permitted to run /bin/ls". |
877 |
So, I changed to compare the basename of realpath and argv[0]. |
So, I changed to compare the basename of realpath and argv[0]. |
959 |
|
|
960 |
Until now, users had to add init=/.init parameter to load policy |
Until now, users had to add init=/.init parameter to load policy |
961 |
before /sbin/init starts. |
before /sbin/init starts. |
962 |
I inserted call_usermodehelper() to call external policy loader when |
I inserted call_usermodehelper() to call external policy loader when |
963 |
execve("/sbin/init") is requested and external policy loader exists. |
execve("/sbin/init") is requested and external policy loader exists. |
964 |
|
|
965 |
This change will remove init=/.init parameter from most environment, |
This change will remove init=/.init parameter from most environment, |
1003 |
|
|
1004 |
@ Remove initializer directive. |
@ Remove initializer directive. |
1005 |
|
|
1006 |
Use "initialize_domain" instrad of "initializer". |
Use "initialize_domain" instead of "initializer". |
1007 |
|
|
1008 |
Fix 2007/08/21 |
Fix 2007/08/21 |
1009 |
|
|
2046 |
kernel 2.6.31 introduced memory leak detection mechanism |
kernel 2.6.31 introduced memory leak detection mechanism |
2047 |
( CONFIG_DEBUG_KMEMLEAK ), TOMOYO no longer needs to use own list. |
( CONFIG_DEBUG_KMEMLEAK ), TOMOYO no longer needs to use own list. |
2048 |
|
|
2049 |
I removed the list to ruduce use of spinlocks. |
I removed the list to reduce use of spinlocks. |
2050 |
|
|
2051 |
@ Rewrite ccs-patch-2.\*.diff . |
@ Rewrite ccs-patch-2.\*.diff . |
2052 |
|
|
2053 |
ccs-patch-2.\*.diff was rewriteen like LSM hooks. |
ccs-patch-2.\*.diff was rewritten like LSM hooks. |
2054 |
|
|
2055 |
@ Don't check "allow_read/write" for open-for-ioctl-only. |
@ Don't check "allow_read/write" for open-for-ioctl-only. |
2056 |
|
|
2066 |
|
|
2067 |
@ Move files from fs/ to security/ccsecurity. |
@ Move files from fs/ to security/ccsecurity. |
2068 |
|
|
2069 |
Config menu section changed from "File systems" to "Security options". |
Config menu section changed from "File systems" to "Security options". |
2070 |
|
|
2071 |
Kernel config symbols changed from CONFIG_SAKURA CONFIG_TOMOYO |
Kernel config symbols changed from CONFIG_SAKURA CONFIG_TOMOYO |
2072 |
CONFIG_SYAORAN to CONFIG_CCSECURITY . |
CONFIG_SYAORAN to CONFIG_CCSECURITY . |
2084 |
the domain which the process belongs to. |
the domain which the process belongs to. |
2085 |
|
|
2086 |
Thus, I added global PID in audit logs. |
Thus, I added global PID in audit logs. |
2087 |
|
|
2088 |
@ Transit to new domain before do_execve() succeeds. |
@ Transit to new domain before do_execve() succeeds. |
2089 |
|
|
2090 |
Permission checks for interpreters and environment variables are |
Permission checks for interpreters and environment variables are |
2144 |
Thus, I moved ccs_capable() checks from ccs_setattr_permission() to |
Thus, I moved ccs_capable() checks from ccs_setattr_permission() to |
2145 |
ccs_chmod_permission() and ccs_chown_permission(), and removed |
ccs_chmod_permission() and ccs_chown_permission(), and removed |
2146 |
ccs_setattr_permission(). |
ccs_setattr_permission(). |
2147 |
|
|
2148 |
|
Fix 2009/09/25 |
2149 |
|
|
2150 |
|
@ Embed more information into audit logs. |
2151 |
|
|
2152 |
|
Until now, /proc/ccs/grant_log /proc/ccs/reject_log /proc/ccs/query were |
2153 |
|
not printing file's information (e.g. file's uid/gid/mode). |
2154 |
|
|
2155 |
|
Recently, users who started using "if" clause expect that the learning |
2156 |
|
mode automatically adds various conditions like "if task.uid=path1.uid". |
2157 |
|
|
2158 |
|
But the profile will become too complicated if I support all possible |
2159 |
|
conditions. Thus, I added all information which is enough to generate |
2160 |
|
"if" clause with all possible conditions from audit logs. |
2161 |
|
|
2162 |
|
Now, the learning mode got different usage. Users can specify |
2163 |
|
"CONFIG::learning={ max_entry=0 }" in the profile. All requests which |
2164 |
|
are not permitted by policy will be sent to /proc/ccs/reject_log with |
2165 |
|
"mode=learning" header lines. Users can selectively append conditions |
2166 |
|
and append to the policy using "/usr/sbin/ccs-loadpolicy -d". |
2167 |
|
The learning mode with "CONFIG::learning={ max_entry=0 }" is almost |
2168 |
|
the same with the permissive mode, only difference is "mode=learning" |
2169 |
|
and "mode=permissive". |
2170 |
|
|
2171 |
|
Fix 2009/10/05 |
2172 |
|
|
2173 |
|
@ Fix size truncation bug at ccs_memcmp(). |
2174 |
|
|
2175 |
|
ccs_memcmp() was using "u8" for size parameter by error. Therefore, when |
2176 |
|
size >= 256 was passed to ccs_memcmp(), it was doing partial comparison |
2177 |
|
(incorrect result) or read overrun (CPU stall). |
2178 |
|
|
2179 |
|
ccs_memcmp() should use "size_t" for size parameter because size of |
2180 |
|
"struct ccs_condition" may exceed 256 bytes if complicated condition was |
2181 |
|
given. |
2182 |
|
|
2183 |
|
Fix 2009/10/08 |
2184 |
|
|
2185 |
|
@ Add CONFIG_CCSECURITY_DEFAULT_LOADER option. |
2186 |
|
|
2187 |
|
I made the default policy loader's pathname ( /sbin/ccs-init ) |
2188 |
|
configurable. |
2189 |
|
|
2190 |
|
@ Add CONFIG_CCSECURITY_ALTERNATIVE_TRIGGER option. |
2191 |
|
|
2192 |
|
Some environments do not have /sbin/init . In such environments, we need |
2193 |
|
to use different program's pathname (e.g. /init or /linuxrc ) as |
2194 |
|
activation trigger. |
2195 |
|
|
2196 |
|
Thus, I made the alternative trigger ( /sbin/ccs-start ) configurable. |
2197 |
|
|
2198 |
|
Fix 2009/11/02 |
2199 |
|
|
2200 |
|
@ Fix buffer contention. |
2201 |
|
|
2202 |
|
A permission like |
2203 |
|
|
2204 |
|
allow_env PATH if exec.envp["PATH"]="/" |
2205 |
|
|
2206 |
|
was not working since I was using the same buffer for both environment |
2207 |
|
variable's name and value. |
2208 |
|
|
2209 |
|
Fix 2009/11/03 |
2210 |
|
|
2211 |
|
@ Fix memory leak in ccs_write_address_group_policy(). |
2212 |
|
|
2213 |
|
I forgot to call kfree() if same entry was added. |
2214 |
|
|
2215 |
|
@ Reduce mutexes. |
2216 |
|
|
2217 |
|
I was using mutex_lock()/mutex_unlock() so that I can use |
2218 |
|
atomic_dec_and_test() for removing an element from a list. |
2219 |
|
I moved that operation to garbage collector in order to reduce frequency |
2220 |
|
of mutex_lock()/mutex_unlock() calls. |
2221 |
|
|
2222 |
|
@ Escape from nested loops correctly. |
2223 |
|
|
2224 |
|
In ccs_read_address_group_policy(), I was escaping from nested loops |
2225 |
|
correctly. But in ccs_read_path_group_policy() and |
2226 |
|
ccs_read_number_group_policy(), I wasn't. |
2227 |
|
|
2228 |
|
As a result, reading path_group and number_group caused kernel oops |
2229 |
|
when they were not read atomically. |
2230 |
|
|
2231 |
|
Fix 2009/11/06 |
2232 |
|
|
2233 |
|
@ Fix incorrect allow_mount audit log. |
2234 |
|
|
2235 |
|
Audit log for allow_mount was using decimal format. |
2236 |
|
It needs to use hexadecimal format. |
2237 |
|
|
2238 |
|
Fix 2009/11/09 |
2239 |
|
|
2240 |
|
@ Add profile version check. |
2241 |
|
|
2242 |
|
To avoid upgrading from TOMOYO 1.6.x to TOMOYO 1.7.x without upgrading |
2243 |
|
/proc/ccs/profile (which results in not protecting the system at all), |
2244 |
|
I added a check for PROFILE_VERSION= . |
2245 |
|
|
2246 |
|
Version 1.7.1 2009/11/11 Fourth anniversary release. |
2247 |
|
|
2248 |
|
Fix 2009/11/13 |
2249 |
|
|
2250 |
|
@ Don't use core_initcall() for initializing lock for GC. |
2251 |
|
|
2252 |
|
Some kernels call TOMOYO's hooks before processing core_initcall(). |
2253 |
|
Thus, I can't use core_initcall() for initializing lock for GC. |