Thread (5 messages) read the whole thread 5 messages, 4 authors, 2025-02-27

Re: [PATCH] selinux: add FILE__WATCH_MOUNTNS

From: Paul Moore <paul@paul-moore.com>
Date: 2025-02-27 16:48:21
Also in: linux-fsdevel, selinux

On Thu, Feb 27, 2025 at 10:22 AM Stephen Smalley
[off-list ref] wrote:
On Wed, Feb 26, 2025 at 3:19 PM Paul Moore [off-list ref] wrote:
quoted
On Feb 24, 2025 Miklos Szeredi [off-list ref] wrote:
quoted
Watching mount namespaces for changes (mount, umount, move mount) was added
by previous patches.

This patch adds the file/watch_mountns permission that can be applied to
nsfs files (/proc/$$/ns/mnt), making it possible to allow or deny watching
a particular namespace for changes.

Suggested-by: Paul Moore <paul@paul-moore.com>
Link: https://lore.kernel.org/all/CAHC9VhTOmCjCSE2H0zwPOmpFopheexVb6jyovz92ZtpKtoVv6A@mail.gmail.com/ (local)
Signed-off-by: Miklos Szeredi <redacted>
---
 security/selinux/hooks.c            | 3 +++
 security/selinux/include/classmap.h | 2 +-
 2 files changed, 4 insertions(+), 1 deletion(-)
Thanks Miklos, this looks good to me.  VFS folks / Christian, can you
merge this into the associated FSNOTIFY_OBJ_TYPE_MNTNS branch you are
targeting for linux-next?

Acked-by: Paul Moore <paul@paul-moore.com>
I'm not objecting to this patch, but just for awareness, this adds the
permission for all file-related classes, including dir(ectory), and we
are almost out of space in the access vector at which point we'll need
to introduce a file2 class or similar (as with process2).
Yes, I've been paying closer attention to this over the past several
years as we start to nudge the permission count limits.  However, as
you mentioned, this isn't a new concern and we've successfully dealt
with it in the past.

-- 
paul-moore.com
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help