selinux: Ship policy module for install_t domain transitions - #2366
gursewak1997 wants to merge 1 commit into
Conversation
Add transition rules from initrc_t and unconfined_service_t to install_t via install_exec_t, so wrapper systemd services can gain mac_admin capability. Assisted-by: AI Signed-off-by: gursewak1997 <gursmangat@gmail.com>
159537d to
a87253a
Compare
|
Thanks for working on this! I think we need an integration test for this. Also it'd be good to "crosscheck" that the test fails without this patch. I'm OK shipping this here but IMO it actually has nothing to do with bootc at all - this is purely a (Fedora?) SELinux policy issue and as I said in the Jira I think it could affect e.g. dnf too. I'd like to at least spend some time/tokens on what a patch for the base selinux-policy would look like. |
I opened fedora-selinux/selinux-policy#3327 |
|
Neither this module nor fedora-selinux/selinux-policy#3327 grants |
|
Hi @andrewdunndev thanks for looking at this! Since you've been regularly participating one general thing I wanted to more formally invite you to participate in our development if you're interested, we have live chats on Zoom and there's also a Slack. (But what you're doing here is great too of course, async communciation is the right default)
I'm not saying it's wrong to do that, but...the security benefits are relatively low for services which start from a high privilege anyways. NNP is mostly about further securing things which should run as non-root anyways. Anyways though, I think the right place to take this is a new issue on https://github.com/fedora-selinux/selinux-policy ? |
Problem
When systemd directly runs a binary labeled
install_exec_t, the SELinux policy transitions the process toinstall_t(which grantsmac_admin). But when users wrap bootc in their own systemd services, the wrapper runs asinitrc_torunconfined_service_t, and there are no transition rules from those domains — so bootc never getsinstall_t. This silently breaks cross-major-version updates that need to write arbitrary SELinux labels.This has been a pain point since the ostree days. Unlike rpm-ostree (a daemon where systemd handled the transition), bootc encourages users to wrap it in custom services where the entrypoint binary won't be
install_exec_t.Repro (from the issue):
Solution
Ship a small SELinux policy module that adds the missing
type_transitionrules frominitrc_tandunconfined_service_ttoinstall_tviainstall_exec_t. The module is built during the RPM build and loaded viasemodulein%post.Ref: RHEL-117256
Assisted-by: AI