Skip to content
Snippets Groups Projects
Commit 1b1d133b authored by Nick Kralevich's avatar Nick Kralevich
Browse files

Add nnp_nosuid_transition policycap and related class/perm definitions.

https://github.com/torvalds/linux/commit/af63f4193f9fbbbac50fc766417d74735afd87ef
allows a security policy writer to determine whether transitions under
nosuid / NO_NEW_PRIVS should be allowed or not.

Define these permissions, so that they're usable to policy writers.

This change is modeled after refpolicy
https://github.com/TresysTechnology/refpolicy/commit/1637a8b407c85f67f0b2ca5c6d852cef3c999087

Test: policy compiles and device boots
Test Note: Because this requires a newer kernel, full testing on such
   kernels could not be done.
Change-Id: I9866724b3b97adfc0cdef5aaba6de0ebbfbda72f
parent 8d7d5b42
No related branches found
No related tags found
No related merge requests found
...@@ -330,6 +330,11 @@ class process ...@@ -330,6 +330,11 @@ class process
getrlimit getrlimit
} }
class process2
{
nnp_transition
nosuid_transition
}
# #
# Define the access vector interpretation for ipc-related objects # Define the access vector interpretation for ipc-related objects
......
...@@ -11,3 +11,10 @@ policycap open_perms; ...@@ -11,3 +11,10 @@ policycap open_perms;
# to the rawip_socket class. # to the rawip_socket class.
policycap extended_socket_class; policycap extended_socket_class;
# Enable NoNewPrivileges support. Requires libsepol 2.7+
# and kernel 4.14 (estimated).
#
# Checks enabled;
# process2: nnp_transition, nosuid_transition
#
policycap nnp_nosuid_transition;
...@@ -130,6 +130,8 @@ class kcm_socket ...@@ -130,6 +130,8 @@ class kcm_socket
class qipcrtr_socket class qipcrtr_socket
class smc_socket class smc_socket
class process2
# Property service # Property service
class property_service # userspace class property_service # userspace
......
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment