485 |
domain ACL. For example, |
domain ACL. For example, |
486 |
|
|
487 |
"1 /bin/sh if task.euid!=0" |
"1 /bin/sh if task.euid!=0" |
488 |
|
|
489 |
allows the domain to execute /bin/sh only when the process's euid |
allows the domain to execute /bin/sh only when the process's euid |
490 |
is not 0, and |
is not 0, and |
491 |
|
|
871 |
based on realpath while argv[0] check is done based on the symlink's |
based on realpath while argv[0] check is done based on the symlink's |
872 |
pathname and argv[0], this specification will allow attackers behave |
pathname and argv[0], this specification will allow attackers behave |
873 |
as /bin/cat in the domain of /bin/ls if "/bin/ls and /bin/cat are |
as /bin/cat in the domain of /bin/ls if "/bin/ls and /bin/cat are |
874 |
links to /sbin/busybox" and "the attacker is permitted to create |
links to /sbin/busybox" and "the attacker is permitted to create |
875 |
a symlink named ~/cat that points to /bin/ls" and "the attacker is |
a symlink named ~/cat that points to /bin/ls" and "the attacker is |
876 |
permitted to run /bin/ls". |
permitted to run /bin/ls". |
877 |
So, I changed to compare the basename of realpath and argv[0]. |
So, I changed to compare the basename of realpath and argv[0]. |
959 |
|
|
960 |
Until now, users had to add init=/.init parameter to load policy |
Until now, users had to add init=/.init parameter to load policy |
961 |
before /sbin/init starts. |
before /sbin/init starts. |
962 |
I inserted call_usermodehelper() to call external policy loader when |
I inserted call_usermodehelper() to call external policy loader when |
963 |
execve("/sbin/init") is requested and external policy loader exists. |
execve("/sbin/init") is requested and external policy loader exists. |
964 |
|
|
965 |
This change will remove init=/.init parameter from most environment, |
This change will remove init=/.init parameter from most environment, |
1003 |
|
|
1004 |
@ Remove initializer directive. |
@ Remove initializer directive. |
1005 |
|
|
1006 |
Use "initialize_domain" instrad of "initializer". |
Use "initialize_domain" instead of "initializer". |
1007 |
|
|
1008 |
Fix 2007/08/21 |
Fix 2007/08/21 |
1009 |
|
|
2046 |
kernel 2.6.31 introduced memory leak detection mechanism |
kernel 2.6.31 introduced memory leak detection mechanism |
2047 |
( CONFIG_DEBUG_KMEMLEAK ), TOMOYO no longer needs to use own list. |
( CONFIG_DEBUG_KMEMLEAK ), TOMOYO no longer needs to use own list. |
2048 |
|
|
2049 |
I removed the list to ruduce use of spinlocks. |
I removed the list to reduce use of spinlocks. |
2050 |
|
|
2051 |
@ Rewrite ccs-patch-2.\*.diff . |
@ Rewrite ccs-patch-2.\*.diff . |
2052 |
|
|
2053 |
ccs-patch-2.\*.diff was rewriteen like LSM hooks. |
ccs-patch-2.\*.diff was rewritten like LSM hooks. |
2054 |
|
|
2055 |
@ Don't check "allow_read/write" for open-for-ioctl-only. |
@ Don't check "allow_read/write" for open-for-ioctl-only. |
2056 |
|
|
2066 |
|
|
2067 |
@ Move files from fs/ to security/ccsecurity. |
@ Move files from fs/ to security/ccsecurity. |
2068 |
|
|
2069 |
Config menu section changed from "File systems" to "Security options". |
Config menu section changed from "File systems" to "Security options". |
2070 |
|
|
2071 |
Kernel config symbols changed from CONFIG_SAKURA CONFIG_TOMOYO |
Kernel config symbols changed from CONFIG_SAKURA CONFIG_TOMOYO |
2072 |
CONFIG_SYAORAN to CONFIG_CCSECURITY . |
CONFIG_SYAORAN to CONFIG_CCSECURITY . |
2084 |
the domain which the process belongs to. |
the domain which the process belongs to. |
2085 |
|
|
2086 |
Thus, I added global PID in audit logs. |
Thus, I added global PID in audit logs. |
2087 |
|
|
2088 |
@ Transit to new domain before do_execve() succeeds. |
@ Transit to new domain before do_execve() succeeds. |
2089 |
|
|
2090 |
Permission checks for interpreters and environment variables are |
Permission checks for interpreters and environment variables are |
2091 |
done using new domain. In order to be allow ccs-queryd to reach the new |
done using new domain. In order to allow ccs-queryd to reach the new |
2092 |
domain via global PID, I reverted "Don't transit to new domain until |
domain via global PID, I reverted "Don't transit to new domain until |
2093 |
do_execve() succeeds." made on 2008/10/07. |
do_execve() succeeds." made on 2008/10/07. |
2094 |
|
|
2167 |
The learning mode with "CONFIG::learning={ max_entry=0 }" is almost |
The learning mode with "CONFIG::learning={ max_entry=0 }" is almost |
2168 |
the same with the permissive mode, only difference is "mode=learning" |
the same with the permissive mode, only difference is "mode=learning" |
2169 |
and "mode=permissive". |
and "mode=permissive". |
2170 |
|
|
2171 |
|
Fix 2009/10/05 |
2172 |
|
|
2173 |
|
@ Fix size truncation bug at ccs_memcmp(). |
2174 |
|
|
2175 |
|
ccs_memcmp() was using "u8" for size parameter by error. Therefore, when |
2176 |
|
size >= 256 was passed to ccs_memcmp(), it was doing partial comparison |
2177 |
|
(incorrect result) or read overrun (CPU stall). |
2178 |
|
|
2179 |
|
ccs_memcmp() should use "size_t" for size parameter because size of |
2180 |
|
"struct ccs_condition" may exceed 256 bytes if complicated condition was |
2181 |
|
given. |
2182 |
|
|
2183 |
|
Fix 2009/10/08 |
2184 |
|
|
2185 |
|
@ Add CONFIG_CCSECURITY_DEFAULT_LOADER option. |
2186 |
|
|
2187 |
|
I made the default policy loader's pathname ( /sbin/ccs-init ) |
2188 |
|
configurable. |
2189 |
|
|
2190 |
|
@ Add CONFIG_CCSECURITY_ALTERNATIVE_TRIGGER option. |
2191 |
|
|
2192 |
|
Some environments do not have /sbin/init . In such environments, we need |
2193 |
|
to use different program's pathname (e.g. /init or /linuxrc ) as |
2194 |
|
activation trigger. |
2195 |
|
|
2196 |
|
Thus, I made the alternative trigger ( /sbin/ccs-start ) configurable. |
2197 |
|
|
2198 |
|
Fix 2009/11/02 |
2199 |
|
|
2200 |
|
@ Fix buffer contention. |
2201 |
|
|
2202 |
|
A permission like |
2203 |
|
|
2204 |
|
allow_env PATH if exec.envp["PATH"]="/" |
2205 |
|
|
2206 |
|
was not working since I was using the same buffer for both environment |
2207 |
|
variable's name and value. |
2208 |
|
|
2209 |
|
Fix 2009/11/03 |
2210 |
|
|
2211 |
|
@ Fix memory leak in ccs_write_address_group_policy(). |
2212 |
|
|
2213 |
|
I forgot to call kfree() if same entry was added. |
2214 |
|
|
2215 |
|
@ Reduce mutexes. |
2216 |
|
|
2217 |
|
I was using mutex_lock()/mutex_unlock() so that I can use |
2218 |
|
atomic_dec_and_test() for removing an element from a list. |
2219 |
|
I moved that operation to garbage collector in order to reduce frequency |
2220 |
|
of mutex_lock()/mutex_unlock() calls. |
2221 |
|
|
2222 |
|
@ Escape from nested loops correctly. |
2223 |
|
|
2224 |
|
In ccs_read_address_group_policy(), I was escaping from nested loops |
2225 |
|
correctly. But in ccs_read_path_group_policy() and |
2226 |
|
ccs_read_number_group_policy(), I wasn't. |
2227 |
|
|
2228 |
|
As a result, reading path_group and number_group caused kernel oops |
2229 |
|
when they were not read atomically. |
2230 |
|
|
2231 |
|
Fix 2009/11/06 |
2232 |
|
|
2233 |
|
@ Fix incorrect allow_mount audit log. |
2234 |
|
|
2235 |
|
Audit log for allow_mount was using decimal format. |
2236 |
|
It needs to use hexadecimal format. |
2237 |
|
|
2238 |
|
Fix 2009/11/09 |
2239 |
|
|
2240 |
|
@ Add profile version check. |
2241 |
|
|
2242 |
|
To avoid upgrading from TOMOYO 1.6.x to TOMOYO 1.7.x without upgrading |
2243 |
|
/proc/ccs/profile (which results in not protecting the system at all), |
2244 |
|
I added a check for PROFILE_VERSION= . |
2245 |
|
|
2246 |
|
Version 1.7.1 2009/11/11 Fourth anniversary release. |
2247 |
|
|
2248 |
|
Fix 2009/11/13 |
2249 |
|
|
2250 |
|
@ Don't use core_initcall() for initializing lock for GC. |
2251 |
|
|
2252 |
|
Some kernels call TOMOYO's hooks before processing core_initcall(). |
2253 |
|
Thus, I can't use core_initcall() for initializing lock for GC. |
2254 |
|
|
2255 |
|
Fix 2009/11/18 |
2256 |
|
|
2257 |
|
@ Don't check "allow_write" permission for open(O_RDONLY | O_TRUNC). |
2258 |
|
|
2259 |
|
Since TOMOYO checks "allow_truncate" permission rather than "allow_write" |
2260 |
|
permission for O_TRUNC, I need to distinguish open(O_RDONLY | O_TRUNC) |
2261 |
|
and open(O_RDWR | O_TRUNC). But I made a mistake between TOMOYO 1.7.0 and |
2262 |
|
1.7.1 which made it impossible for TOMOYO for kernels 2.6.14 and earlier |
2263 |
|
to distinguish them. |
2264 |
|
|
2265 |
|
Fix 2009/11/27 |
2266 |
|
|
2267 |
|
@ Use newly created domain's name for domain creation audit log. |
2268 |
|
|
2269 |
|
Since 1.7.0 , /proc/ccs/reject_log was by error using existing domain's |
2270 |
|
name when auditing newly created domain's "use_profile" line. |
2271 |
|
|
2272 |
|
Fix 2009/12/12 |
2273 |
|
|
2274 |
|
@ Use rcu_read_lock() for find_task_by_pid(). |
2275 |
|
|
2276 |
|
Since kernel 2.6.18 , caller of find_task_by_pid() needs to call |
2277 |
|
rcu_read_lock() rather than read_lock(&tasklist_lock) because find_pid() |
2278 |
|
uses RCU primitives but spinlock does not prevent RCU callback if |
2279 |
|
preemptive RCU ( CONFIG_PREEMPT_RCU or CONFIG_TREE_PREEMPT_RCU ) is |
2280 |
|
enabled. |
2281 |
|
|
2282 |
|
Fix 2009/12/15 |
2283 |
|
|
2284 |
|
@ Allow deleting "quota_exceeded" and "transition_failed" entries. |
2285 |
|
|
2286 |
|
To notify users of "this domain has too many entries to hold" and "some |
2287 |
|
process in this domain was not able to perform domain transition", |
2288 |
|
"quota_exceeded" and "transition_failed" messages are used respectively. |
2289 |
|
These messages were not deletable. But it is more convenient for users |
2290 |
|
to be notified again if such events occurred again after tuning policy. |
2291 |
|
Thus, I made these messages deletable. |
2292 |
|
|
2293 |
|
Fix 2009/12/17 |
2294 |
|
|
2295 |
|
@ Don't check read permission in ccs_try_alt_exec(). |
2296 |
|
|
2297 |
|
While I was trying to remove ccs_execve_list list for GC optimization |
2298 |
|
between TOMOYO 1.7.0 and 1.7.1 , I made a mistake which made TOMOYO to |
2299 |
|
check allow_read permission of the programs specified by execute_handler |
2300 |
|
and denied_execute_handler keywords. |
2301 |
|
|
2302 |
|
@ Don't check DAC permission if disabled mode. |
2303 |
|
|
2304 |
|
I was checking DAC permissions regarding directory entry modification |
2305 |
|
operations (e.g. mkdir()) even if mode=disabled . It is a waste of CPU |
2306 |
|
resource to check DAC permissions when MAC permissions are not checked. |
2307 |
|
Thus, I modified to skip DAC permission checks if mode=disabled . |
2308 |
|
|
2309 |
|
Fix 2009/12/19 |
2310 |
|
|
2311 |
|
@ Fix memory leak in ccs_environ(). |
2312 |
|
|
2313 |
|
When I fixed a bug that a permission like |
2314 |
|
|
2315 |
|
allow_env PATH if exec.envp["PATH"]="/" |
2316 |
|
|
2317 |
|
was not working (2009/11/02), I allocated two buffers but only one buffer |
2318 |
|
was released. |
2319 |
|
|
2320 |
|
This bug will trigger OOM killer if environment variable checking is |
2321 |
|
enabled. |
2322 |
|
|
2323 |
|
Fix 2010/01/17 |
2324 |
|
|
2325 |
|
@ Use current domain's name for execute_handler audit log. |
2326 |
|
|
2327 |
|
Since 1.6.7 , /proc/ccs/grant_log was by error using next domain's name |
2328 |
|
when auditing current domain's "execute_handler" line. |
2329 |
|
|
2330 |
|
Fix 2010/03/02 |
2331 |
|
|
2332 |
|
@ Allow domain transition without execve(). |
2333 |
|
|
2334 |
|
To be able to split permissions for Apache's CGI programs which are |
2335 |
|
executed without execve(), I added special domain transition which is |
2336 |
|
performed by atomically writing '\0'-terminated binary string to |
2337 |
|
/proc/ccs/.transition interface. For example, a process which belongs to |
2338 |
|
"<kernel> /usr/sbin/httpd" domain will transit to |
2339 |
|
"<kernel> /usr/sbin/httpd //app=cgi1\040id=10000" domain by atomically |
2340 |
|
writing "app=cgi1 id=10000" + '\0' to /proc/ccs/.transition using |
2341 |
|
Apache's ap_hook_handler() functionality. |
2342 |
|
|
2343 |
|
Note that '\0'-terminated binary string is converted to TOMOYO's string |
2344 |
|
inside kernel and prefix "//" is automatically added to the string so |
2345 |
|
that domainname does not conflict with domainnames created by execve(). |
2346 |
|
Without this prefix, if "<kernel> /usr/sbin/sshd /bin/bash" domain is |
2347 |
|
allowed to open /proc/ccs/.transition for writing and |
2348 |
|
"<kernel> /usr/sbin/sshd /bin/bash /usr/bin/passwd" domain is allowed to |
2349 |
|
access /etc/shadow , /bin/bash will be able to access /etc/shadow by |
2350 |
|
atomically writing "/usr/bin/passwd" + '\0' to /proc/ccs/.transition . |
2351 |
|
Allowing /bin/bash to access /etc/shadow is not what people want. |
2352 |
|
|
2353 |
|
Permission for this operation is checked by "allow_transit" keyword. |
2354 |
|
Unlike "allow_execute" keyword, the string parameter for "allow_transit" |
2355 |
|
keyword does not refer a real file on filesystem's namespace. Therefore, |
2356 |
|
you can store any combination of parameters like LDAP's DN entry in the |
2357 |
|
string parameter for "allow_transit" keyword. |
2358 |
|
|
2359 |
|
Fix 2010/03/08 |
2360 |
|
|
2361 |
|
@ Allow building as loadable kernel module. |
2362 |
|
|
2363 |
|
To be able to minimize filesize increment of vmlinux, I made it |
2364 |
|
possible to compile TOMOYO Linux as loadable kernel module. |
2365 |
|
Although patching the kernel source and recompiling the kernel are |
2366 |
|
inevitable, this change will make it easier to enable TOMOYO Linux |
2367 |
|
when there is a filesize limitation on vmlinux (e.g. embedded systems). |
2368 |
|
|
2369 |
|
Fix 2010/03/25 |
2370 |
|
|
2371 |
|
@ Fix ccs_get_ipv6_address() bug. |
2372 |
|
|
2373 |
|
Since 1.7.0 , ccs_get_ipv6_address() was by error returning address of |
2374 |
|
"struct list_head ccs_address_list" if memory allocation failed. |
2375 |
|
As a result, ccs_put_ipv6_address() will modify memory near |
2376 |
|
"struct list_head ccs_address_list" if memory allocation failed. |
2377 |
|
|
2378 |
|
Fix 2010/03/26 |
2379 |
|
|
2380 |
|
@ Fix ccs_lport_reserved() bug. |
2381 |
|
|
2382 |
|
Since 1.7.0 , ccs_lport_reserved() was by error checking wrong port |
2383 |
|
number. As a result, "deny_autobind" keyword was not working as expected. |
2384 |
|
|
2385 |
|
Version 1.7.2 2010/04/01 Feature enhancement release. |
2386 |
|
|
2387 |
|
Fix 2010/04/10 |
2388 |
|
|
2389 |
|
@ Fix invalid "struct nameidata" to "struct path" conversion macro. |
2390 |
|
|
2391 |
|
Regarding kernels 2.6.24 and earlier, I was converting "struct nameidata" |
2392 |
|
to "struct path" in caller side so that I can unify the callee function's |
2393 |
|
parameter type. But it turned out that the macro I used did not follow C |
2394 |
|
standards and did not work with gcc 4.x . As a result, "allow_pivot_root" |
2395 |
|
keyword was not working as expected. |
2396 |
|
|
2397 |
|
Fix 2010/05/05 |
2398 |
|
|
2399 |
|
@ Fix incorrect audit on/off control. |
2400 |
|
|
2401 |
|
The grant_log= and reject_log= parameters of CONFIG::misc::env were not |
2402 |
|
used because I forgot to update request type. As a result, those of |
2403 |
|
CONFIG::file::execute were used for CONFIG::misc::env . |
2404 |
|
|
2405 |
|
Those of CONFIG::file::rewrite were not used because I forgot to update |
2406 |
|
request type. As a result, those of CONFIG::file::truncate were used for |
2407 |
|
CONFIG::file::rewrite . |
2408 |
|
|
2409 |
|
Fix 2010/05/10 |
2410 |
|
|
2411 |
|
@ Fix incorrect out of memory warning. |
2412 |
|
|
2413 |
|
Out of memory warnings were not printed in some cases by error. |
2414 |
|
|
2415 |
|
Fix 2010/05/27 |
2416 |
|
|
2417 |
|
@ Add missing rcu_dereference() for ccs_find_execute_handler(). |
2418 |
|
|
2419 |
|
Since 1.7.0 , ccs_find_execute_handler() was by error using |
2420 |
|
list_for_each_entry() rather than list_for_each_entry_rcu(). |
2421 |
|
This bug affects only Alpha architecture. |
2422 |
|
|
2423 |
|
Fix 2010/06/03 |
2424 |
|
|
2425 |
|
@ Fix missing sanity check for "file_pattern". |
2426 |
|
|
2427 |
|
Since 1.7.0 , ccs_write_pattern_policy() was by error accepting |
2428 |
|
invalid pathname. |
2429 |
|
|
2430 |
|
Fix 2010/06/09 |
2431 |
|
|
2432 |
|
@ Add missing ccs_put_name() in ccs_parse_envp(). |
2433 |
|
|
2434 |
|
Since 1.7.0 , ccs_parse_envp() was not calling ccs_put_name() if |
2435 |
|
environment variable's value ('if exec.envp["name"]="value"' condition) |
2436 |
|
was invalid. |
2437 |
|
|
2438 |
|
@ Add missing NULL check in ccs_condition(). |
2439 |
|
|
2440 |
|
Since 1.7.0 , if 'if symlink.target=' part was given against non-file |
2441 |
|
permissions (e.g. allow_env PATH if symlink.target="/"), it triggered |
2442 |
|
NULL pointer dereference. |
2443 |
|
|
2444 |
|
Fix 2010/07/29 |
2445 |
|
|
2446 |
|
@ Change keyword syntax. |
2447 |
|
|
2448 |
|
I removed "allow_" prefix from directives. New directives for files are |
2449 |
|
prefixed with "file ". For example, "allow_read" changed to "file read", |
2450 |
|
"allow_ioctl" changed to "file ioctl". New directive for "allow_network" |
2451 |
|
is "network". New directive for "allow_env" is "misc env". New directive |
2452 |
|
for "allow_signal" is "ipc signal". New directive for "allow_capability" |
2453 |
|
is "capability". These directives correspond with keywords used by |
2454 |
|
profile's CONFIG lines. |
2455 |
|
|
2456 |
|
I removed "deny_rewrite" and "allow_rewrite" directives and introduced |
2457 |
|
"file append" directive. Thus, permission for open(O_WRONLY | O_APPEND) |
2458 |
|
changed from "allow_write" + "allow_rewrite" to "file append". |
2459 |
|
|
2460 |
|
I removed "SYS_MOUNT", "SYS_UMOUNT", "SYS_CHROOT", "SYS_KILL", |
2461 |
|
"SYS_LINK", "SYS_SYMLINK", "SYS_RENAME", "SYS_UNLINK", "SYS_CHMOD", |
2462 |
|
"SYS_CHOWN", "SYS_IOCTL", "SYS_PIVOT_ROOT" keywords from capabilities |
2463 |
|
because these permissions can be checked by other directives (e.g. |
2464 |
|
"file mount", "ipc signal"). |
2465 |
|
|
2466 |
|
I also removed "conceal_mount" keyword from capabilities because this |
2467 |
|
check requires hooks in filesystem part while almost all hooks for |
2468 |
|
filesystem part have moved to LSM by Linux 2.6.34. |
2469 |
|
|
2470 |
|
@ Distinguish send() and recv() operations for UDP and IP protocols. |
2471 |
|
|
2472 |
|
Until now, it was impossible for UDP and IP protocols to allow either |
2473 |
|
only sending or only receiving because permissions were aggregated with |
2474 |
|
"connect" keyword. I broke "connect" keyword into "send" and "recv" |
2475 |
|
keywords so that you can keep access control for send() operation enabled |
2476 |
|
when you have to turn access control for recv() operation off due to |
2477 |
|
application breakage by filtering incoming datagram. |
2478 |
|
|
2479 |
|
@ Wait for next connection/datagram if current connection/datagram was |
2480 |
|
discarded. |
2481 |
|
|
2482 |
|
Regarding "network TCP accept", "network UDP recv", "network RAW recv" |
2483 |
|
keywords, I modified to wait for next connection/datagram if current |
2484 |
|
connection/datagram was discarded. LSM hooks for these keywords are |
2485 |
|
currently missing because this behavior may break applications. |
2486 |
|
If you found applications broken by this behavior, you can set |
2487 |
|
CONFIG::network::inet_tcp_accept and/or CONFIG::network::inet_udp_recv |
2488 |
|
and/or CONFIG::network::inet_raw_recv to mode=disabled in order to |
2489 |
|
disable filtering for incoming connection/datagram. |
2490 |
|
|
2491 |
|
@ Allow specifying multiple permissions in a line. |
2492 |
|
|
2493 |
|
Until now, only "allow_read/write" can be specified for combination of |
2494 |
|
"allow_read" + "allow_write". Now, you can combine other permissions as |
2495 |
|
long as type of parameters for these permissions is same. For example, |
2496 |
|
"file read/write/append/execute/unlink/truncate /tmp/file" is correct |
2497 |
|
but "file read/write/create /tmp/file" is wrong because "file create" |
2498 |
|
requires create mode whereas "file read" and "file write" do not. |
2499 |
|
|
2500 |
|
@ Allow wildcard for execute permission and domainname. |
2501 |
|
|
2502 |
|
Until now, to execute programs with temporary names, "aggregator" is |
2503 |
|
needed. To simplify code, I modified to accept wildcards for execute |
2504 |
|
permission and domainname. Now, you can directly specify |
2505 |
|
"file execute /tmp/logrotate.\?\?\?\?\?\?" and use |
2506 |
|
"/tmp/logrotate.\?\?\?\?\?\?" within domainnames. |
2507 |
|
|
2508 |
|
@ Change pathname for non-rename()able filesystems. |
2509 |
|
|
2510 |
|
LSM version of TOMOYO wants to use /proc/self/ rather than /proc/$PID/ if |
2511 |
|
$PID matches current thread's process ID in order to prevent current |
2512 |
|
thread from accessing other process's information unless needed. |
2513 |
|
But since procfs can be mounted on various locations (e.g. /proc/ /proc2/ |
2514 |
|
/p/ /tmp/foo/100/p/ ), LSM version of TOMOYO cannot tell that whether the |
2515 |
|
numeric part in the string returned by __d_path() represents process ID |
2516 |
|
or not. |
2517 |
|
|
2518 |
|
Therefore, to be able to convert from $PID to self no matter where procfs |
2519 |
|
is mounted, I changed pathname representations for filesystems which do |
2520 |
|
not support rename() operation (e.g. proc, sysfs, securityfs). |
2521 |
|
|
2522 |
|
Now, "/proc/self/mounts" changed to "proc:/self/mounts" and |
2523 |
|
"/sys/kernel/security/" changed to "sys:/kernel/security/" and |
2524 |
|
"/dev/pts/0" changed to "devpts:/0". |
2525 |
|
|
2526 |
|
@ Add a new keyword "any" for domain transition control. |
2527 |
|
|
2528 |
|
To be able to make it easier to apply execute_handler on each domain, |
2529 |
|
I added "any" keyword to domain transition control keywords. Now, |
2530 |
|
"initialize_domain /usr/sbin/sshd" changed to |
2531 |
|
"initialize_domain /usr/sbin/sshd from any" and |
2532 |
|
"keep_domain <kernel> /usr/sbin/sshd /bin/bash" changed to |
2533 |
|
"keep_domain any from <kernel> /usr/sbin/sshd /bin/bash". |
2534 |
|
|
2535 |
|
"keep_domain /path/to/execute_handler from any" will allow you to apply |
2536 |
|
execute_handler for any domains without creating domains for |
2537 |
|
execute_handler. |
2538 |
|
|
2539 |
|
@ Change buffering mode for reading policy. |
2540 |
|
|
2541 |
|
To be able to read() very very long lines correctly, I changed the way |
2542 |
|
TOMOYO buffers policy for reading. |
2543 |
|
|
2544 |
|
@ Introduce "acl_group" keyword. |
2545 |
|
|
2546 |
|
Until now, it was possible to specify only "allow_read" and "allow_env" |
2547 |
|
keywords in the exception policy. |
2548 |
|
|
2549 |
|
Since some operations like "file read/write/append /dev/null" and |
2550 |
|
"network UDP send/recv @DNS_SERVER 53" are very common and should be |
2551 |
|
permitted to all domains, I introduced "acl_group" keyword for giving |
2552 |
|
such permissions. |
2553 |
|
|
2554 |
|
For example, specify "acl_group 0 file read/write/append /dev/null" in |
2555 |
|
the exception policy and specify "use_group 0" from the domains in the |
2556 |
|
domain policy. |
2557 |
|
|
2558 |
|
"ignore_global_allow_read" and "ignore_global_allow_env" keywords were |
2559 |
|
removed from domain policy and "use_group" keyword was added. |
2560 |
|
|
2561 |
|
@ Allow controlling generation of access granted logs for per an entry |
2562 |
|
basis. |
2563 |
|
|
2564 |
|
I added per-entry flag which controls generation of grant logs because |
2565 |
|
Xen and KVM issues ioctl requests so frequently. For example, |
2566 |
|
|
2567 |
|
file ioctl /dev/null 0x5401 ; set audit=no |
2568 |
|
|
2569 |
|
will suppress /proc/ccs/grant_log even if profile says grant_log=yes . |
2570 |
|
|
2571 |
|
file ioctl /dev/null 0x5401 ; set audit=yes |
2572 |
|
|
2573 |
|
will generate /proc/ccs/grant_log even if profile says grant_log=no . |
2574 |
|
|
2575 |
|
file ioctl /dev/null 0x5401 |
2576 |
|
|
2577 |
|
will generate /proc/ccs/grant_log only if profile says grant_log=yes . |
2578 |
|
|
2579 |
|
This flag is intended for frequently accessed resources like |
2580 |
|
|
2581 |
|
file read /var/www/html/\{\*\}/\*.html ; set audit=no |
2582 |
|
|
2583 |
|
. |
2584 |
|
|
2585 |
|
@ Optimize for object's size. |
2586 |
|
|
2587 |
|
I merged similar code in order to reduce object's filesize. |