Go to file
Jan Zarsky 42b4a44b74 python: add xperms support to audit2allow
Add support for extended permissions to audit2allow. Extend AuditParser
to parse the 'ioctlcmd' field in AVC message. Extend PolicyGenerator to
generate allowxperm rules. Add the '-x'/'--xperms' option to audit2allow
to turn on generating of extended permission AV rules.

AVCMessage parses the ioctlcmd field in AVC messages. AuditParser
converts the ioctlcmd values into generic representation of extended
permissions that is stored in access vectors.

Extended permissions are represented by operations (currently only
'ioctl') and values associated to the operations. Values (for example
'~{ 0x42 1234 23-34 }') are stored in the XpermSet class.

PolicyGenerator contains new method to turn on generating of xperms.
When turned on, for each access vector, standard AV rule and possibly
several xperm AV rules are generated. Xperm AV rules are represented by
the AVExtRule class.

With xperm generating turned off, PolicyGenerator provides comments
about extended permissions in certain situations. When the AVC message
contains the ioctlcmd field and the access would be allowed according to
the policy, PolicyGenerator warns about xperm rules being the possible
cause of the denial.

Signed-off-by: Jan Zarsky <jzarsky@redhat.com>
2018-06-16 10:36:14 +02:00
checkpolicy checkpolicy: destroy the class datum if it fails to initialize 2018-05-30 22:00:13 +02:00
dbus Update VERSIONs to 2.8 for release. 2018-05-24 14:21:09 -04:00
gui Update VERSIONs to 2.8 for release. 2018-05-24 14:21:09 -04:00
libselinux libselinux: fix the whatis line for the selinux_boolean_sub.3 manpage 2018-05-30 22:07:49 +02:00
libsemanage Update VERSIONs to 2.8 for release. 2018-05-24 14:21:09 -04:00
libsepol libsepol/cil: use a colon instead of a semicolon to report rc 2018-06-15 09:03:04 -04:00
mcstrans Update VERSIONs to 2.8 for release. 2018-05-24 14:21:09 -04:00
policycoreutils policycoreutils/hll/pp: remove unused variable 2018-06-06 15:56:45 -04:00
python python: add xperms support to audit2allow 2018-06-16 10:36:14 +02:00
restorecond restorecond: Fix consistancy of DESTDIR usage 2018-06-02 20:21:25 +02:00
sandbox Update VERSIONs to 2.8 for release. 2018-05-24 14:21:09 -04:00
scripts scripts: add a helper script to run clang's static analyzer 2018-06-15 09:03:17 -04:00
secilc secilc: Make the clean target call the clean target of docs/ 2018-05-30 22:06:43 +02:00
semodule-utils Update VERSIONs to 2.8 for release. 2018-05-24 14:21:09 -04:00
.gitignore restorecond: Add gitignore 2016-11-16 11:20:05 -05:00
.travis.yml travis.yml: add ruby 2.5 to the test matrix 2018-05-22 23:47:20 +08:00
CleanSpec.mk Add empty top level Android.mk / CleanSpec.mk files 2015-04-16 07:54:09 -04:00
Makefile build: setup buildpaths if DESTDIR is specified 2018-02-14 20:02:03 +01:00
README libsepol: build: follow standard semantics for DESTDIR and PREFIX 2018-02-14 15:59:36 +01:00

Please submit all bug reports and patches to selinux@tycho.nsa.gov.
Subscribe via selinux-join@tycho.nsa.gov.

Build dependencies on Fedora:
yum install audit-libs-devel bison bzip2-devel dbus-devel dbus-glib-devel flex flex-devel flex-static glib2-devel libcap-devel libcap-ng-devel pam-devel pcre-devel python-devel setools-devel swig xmlto redhat-rpm-config

To build and install everything under a private directory, run:
make DESTDIR=~/obj install install-pywrap

To install as the default system libraries and binaries
(overwriting any previously installed ones - dangerous!),
on x86_64, run:
make LIBDIR=/usr/lib64 SHLIBDIR=/lib64 install install-pywrap relabel
or on x86 (32-bit), run:
make install install-pywrap relabel

This may render your system unusable if the upstream SELinux userspace
lacks library functions or other dependencies relied upon by your
distribution.  If it breaks, you get to keep both pieces.

To install libsepol on macOS (mainly for policy analysis):
cd libsepol; make PREFIX=/usr/local install

This requires GNU coreutils (brew install coreutils).