Skip to content

Commit dd34b5d

Browse files
eparisJames Morris
authored andcommitted
SELinux: new permission between tty audit and audit socket
New selinux permission to separate the ability to turn on tty auditing from the ability to set audit rules. Signed-off-by: Eric Paris <eparis@redhat.com> Acked-by: Stephen Smalley <sds@tycho.nsa.gov> Signed-off-by: James Morris <jmorris@namei.org>
1 parent 6a25b27 commit dd34b5d

File tree

3 files changed

+3
-1
lines changed

3 files changed

+3
-1
lines changed

security/selinux/include/av_perm_to_string.h

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -153,6 +153,7 @@
153153
S_(SECCLASS_NETLINK_AUDIT_SOCKET, NETLINK_AUDIT_SOCKET__NLMSG_WRITE, "nlmsg_write")
154154
S_(SECCLASS_NETLINK_AUDIT_SOCKET, NETLINK_AUDIT_SOCKET__NLMSG_RELAY, "nlmsg_relay")
155155
S_(SECCLASS_NETLINK_AUDIT_SOCKET, NETLINK_AUDIT_SOCKET__NLMSG_READPRIV, "nlmsg_readpriv")
156+
S_(SECCLASS_NETLINK_AUDIT_SOCKET, NETLINK_AUDIT_SOCKET__NLMSG_TTY_AUDIT, "nlmsg_tty_audit")
156157
S_(SECCLASS_NETLINK_IP6FW_SOCKET, NETLINK_IP6FW_SOCKET__NLMSG_READ, "nlmsg_read")
157158
S_(SECCLASS_NETLINK_IP6FW_SOCKET, NETLINK_IP6FW_SOCKET__NLMSG_WRITE, "nlmsg_write")
158159
S_(SECCLASS_ASSOCIATION, ASSOCIATION__SENDTO, "sendto")

security/selinux/include/av_permissions.h

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -708,6 +708,7 @@
708708
#define NETLINK_AUDIT_SOCKET__NLMSG_WRITE 0x00800000UL
709709
#define NETLINK_AUDIT_SOCKET__NLMSG_RELAY 0x01000000UL
710710
#define NETLINK_AUDIT_SOCKET__NLMSG_READPRIV 0x02000000UL
711+
#define NETLINK_AUDIT_SOCKET__NLMSG_TTY_AUDIT 0x04000000UL
711712
#define NETLINK_IP6FW_SOCKET__IOCTL 0x00000001UL
712713
#define NETLINK_IP6FW_SOCKET__READ 0x00000002UL
713714
#define NETLINK_IP6FW_SOCKET__WRITE 0x00000004UL

security/selinux/nlmsgtab.c

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -113,7 +113,7 @@ static struct nlmsg_perm nlmsg_audit_perms[] =
113113
{ AUDIT_USER, NETLINK_AUDIT_SOCKET__NLMSG_RELAY },
114114
{ AUDIT_SIGNAL_INFO, NETLINK_AUDIT_SOCKET__NLMSG_READ },
115115
{ AUDIT_TTY_GET, NETLINK_AUDIT_SOCKET__NLMSG_READ },
116-
{ AUDIT_TTY_SET, NETLINK_AUDIT_SOCKET__NLMSG_WRITE },
116+
{ AUDIT_TTY_SET, NETLINK_AUDIT_SOCKET__NLMSG_TTY_AUDIT },
117117
};
118118

119119

0 commit comments

Comments
 (0)