详解SELinux SID
Intro
SID = Security Identifier (即Security ID)。其作用就是取代安全上下文,在权限匹配时,提升规则搜索速度,以及降低整个策略数据的空间复杂度,提升了整个SELinux特性的性能损耗。
例如一次权限匹配的函数调用原型如下:
int avc_has_perm(struct selinux_state *state, u32 ssid, u32 tsid, u16 tclass,
u32 requested, struct common_audit_data *auditdata)
其中ssid, tsid就代表了源(source)SID和目的(target)SID。在最终的av(access vector)计算中,SID被转化为context。
什么是context?
context,即安全上下文,是SELinux的核心概念。形如user_u:role_r:type_t:s0-s1:c0,c1-c255
的就是context。其中user字段和role字段用于RBAC,type字段用于TEAC,后面的s0-s1,c1-c255用于mls/mcs。而所有的这些字段,都由策略编译工具生成了整数数据,在SELinux加载策略时一并加载到内存policydb中。
// context定义
struct context {
u32 user;
u32 role;
u32 type;
u32 len; /* length of string in bytes */
struct mls_range range;
char *str; /* string representation if context cannot be mapped. */
};
// context加载
static int context_read_and_validate(struct context *c,
struct policydb *p,
void *fp)
{
...
c->user = le32_to_cpu(buf[0]);
c->role = le32_to_cpu(buf[1]);
c->type = le32_to_cpu(buf[2]);
...
}
在真正的权限匹配时,SELinux通过SID获取到对应的context,再通过context中的type属性,所搜policydb中相应的hash表找到对应的map array,并获取对应某个权限的一个bit位,来得到权限判定结果。
// 搜索sidtab获取SID对应的context,并用context数据结构来计算权限
void security_compute_av(struct selinux_state *state,
u32 ssid,
u32 tsid,
u16 orig_tclass,
struct av_decision *avd,
struct extended_perms *xperms)
{
scontext = sidtab_search(sidtab, ssid);
...
tcontext = sidtab_search(sidtab, tsid);
...
context_struct_compute_av(policydb, scontext, tcontext, tclass, avd,
xperms);
...
}
// 通过context的type字段从policydb中获取权限数据
static void context_struct_compute_av(struct policydb *policydb,
struct context *scontext,
struct context *tcontext,
u16 tclass,
struct av_decision *avd,
struct extended_perms *xperms)
{
...
sattr = flex_array_get(policydb->type_attr_map_array,
scontext->type - 1);
tattr = flex_array_get(policydb->type_attr_map_array,
tcontext->type - 1);
ebitmap_for_each_positive_bit(sattr, snode, i) {
ebitmap_for_each_positive_bit(tattr, tnode, j) {
...
for (node = avtab_search_node(&policydb->te_avtab,
&avkey);
node;
node = avtab_search_node_next(node, avkey.specified)) {
// Get and assign perm data
}
...
}
}
...
}
initial SID
initial SID是一种比较特殊的SID。他在策略编译和SELinux启动中都扮演了非常重要的角色。通常在编译policy的时候,需要一些flask文件,例如Fedora refpolicy:
> ls refpolicy-master/policy/flask/
access_vectors initial_sids security_classes
其中initial_sids就指定了policy二进制中所有的initial SID。内容如下:
# FLASK
#
# Define initial security identifiers
#
sid kernel
sid security
sid unlabeled
sid fs
sid file
sid file_labels
sid init
sid any_socket
sid port
sid netif
sid netmsg
sid node
sid igmp_packet
sid icmp_socket
sid tcp_socket
sid sysctl_modprobe
sid sysctl
sid sysctl_fs
sid sysctl_kernel
sid sysctl_net
sid sysctl_net_unix
sid sysctl_vm
sid sysctl_dev
sid kmod
sid policy
sid scmp_packet
sid devnull
# FLASK
参考《Building The Sample Policy》中的介绍,这些flask文件的内容将被写到最终的policy二进制文件中(即policy.conf),如下:
notebook-tools/build-sepolicy -o policy.conf -d ../../flask-files
build-sepolicy是一个python的示例程序,他是这样处理flask文件的:
try:
f = Flask()
f.parseSids(flask_dir + "/initial_sids")
f.parseClasses(flask_dir + "/security_classes")
f.parseVectors(flask_dir + "/access_vectors")
# Open the file and then create the requested policy source file
of = open(outf, 'w')
if include == 1:
of.writelines(f.createPolicyHdr(mode))
print("Output header file")
elif cil == 1:
of.writelines(f.createCilPolicy(mode))
print("Output CIL policy")
elif class_perm == 1:
of.writelines(f.createCilClassPerms(mode))
print("Output CIL class permission sets")
elif sids == 1:
of.writelines(f.createCilInitialSIDS(mode))
print("Output CIL initial SIDs")
else:
of.writelines(f.createPolicy(mode))
print("Output Kernel Language policy")
of.close()
可见这些文件的内容,被写入到一个Flask对象中,而该对象的内容最终会被写入策略二进制数据。在后续的策略编译中,这些文件会被checkpolicy来处理。
initial SID的作用
from "SELinux by Example: Using Security Enhanced Linux"
Some objects are labeled via an initial SID early in system initialization, even before the policy is loaded. This labeling behavior is needed, for example, to label objects such as the kernel security server and the root filesystem, which are present in the system before the first policy load. When the policy is eventually loaded, the initial SIDs are then associated with the appropriate security context.
Initial SIDs are also used to prevent objects from having a missing or invalid security context, which would make it impossible for SELinux to correctly enforce access. Instead, SELinux associates these objects with the special unlabeled initial SID. The unlabeled initial SID should have a security context that allows only limited access, thereby preventing inappropriate access until the objects can be relabeled by the administrator or destroyed.
Invalid security contexts most commonly result from loading a new policy that removes users, roles, or types, or changes role or type authorizations. In this situation, the SIDs representing security contexts that use these invalid names or associations will become invalid and are mapped to the unlabeled SID at policy load. Invalid security contexts can also arise when transferring object instances between systems (for example, using removable media). Further, if the objects are created on a non-SELinux system, they will have no associated security context. Regardless of whether the security context is invalid or missing, SELinux will use the unlabeled initial SID on first access to the object as the security context.
总结一下,一共有这几点:
- 系统启动时,policy尚未加载,也就是所有的context还没被抽象成SID,存储在内存中的policydb里。allow规则也还没加载,这时候,为了保证代码归一,所以需要这些unlabeled SID,在SELinux启动流程中,再具体介绍。
- 当系统策略变化时,有些role,user或type被删除,导致一些安全上下文失效了,此时这些安全上下文,在策略加载时,会被映射到这些initial SID上。(这里还没找到具体的代码位置)
启动时的使用
init进程在加载策略之前,首先将SELinux的enforcing模式打开。其打开的方式就是往selinuxfs的enforce文件写1。注意此时策略未加载,初始化也未完成。所以策略判断直接取allow。
void security_compute_av(struct selinux_state *state,
u32 ssid,
u32 tsid,
u16 orig_tclass,
struct av_decision *avd,
struct extended_perms *xperms)
{
...
if (!state->initialized)
goto allow;
...
allow:
avd->allowed = 0xffffffff;
}
但由于用户态的入口是一致的,即启动完成后,用户态可以写同样的enforce文件完成SELinux状态的切换,所以为了判断此时用户态进程是否具有设置的权限,在enforce文件的入口处,对用户态进程权限进行了判定:
length = avc_has_perm(&selinux_state,
current_sid(), SECINITSID_SECURITY,
SECCLASS_SECURITY, SECURITY__SETENFORCE,
NULL);
这里就用到了initial SID - SECINITSID_SECURITY
。这里其实已经可以使用selinuxfs的inode.i_security.sid,但由于selinuxfs未通过系统的file open调用,所以无法使用到inode下的SID标签。
系统标签无效时
以socket bind时,对IP地址进行权限判断为例。该权限判断流程大致如下:
<svg id="dwfitkdvt4k" width="100%" xmlns="http://www.w3.org/2000/svg" style="max-width: 249.0625px;" viewBox="0 0 249.0625 311.125"><style>


#dwfitkdvt4k .label {
  font-family: 'trebuchet ms', verdana, arial;
  color: #333; }

#dwfitkdvt4k .node rect,
#dwfitkdvt4k .node circle,
#dwfitkdvt4k .node ellipse,
#dwfitkdvt4k .node polygon {
  fill: #ECECFF;
  stroke: #9370DB;
  stroke-width: 1px; }

#dwfitkdvt4k .node.clickable {
  cursor: pointer; }

#dwfitkdvt4k .arrowheadPath {
  fill: #333333; }

#dwfitkdvt4k .edgePath .path {
  stroke: #333333;
  stroke-width: 1.5px; }

#dwfitkdvt4k .edgeLabel {
  background-color: #e8e8e8; }

#dwfitkdvt4k .cluster rect {
  fill: #ffffde !important;
  stroke: #aaaa33 !important;
  stroke-width: 1px !important; }

#dwfitkdvt4k .cluster text {
  fill: #333; }

#dwfitkdvt4k div.mermaidTooltip {
  position: absolute;
  text-align: center;
  max-width: 200px;
  padding: 2px;
  font-family: 'trebuchet ms', verdana, arial;
  font-size: 12px;
  background: #ffffde;
  border: 1px solid #aaaa33;
  border-radius: 2px;
  pointer-events: none;
  z-index: 100; }

#dwfitkdvt4k .actor {
  stroke: #CCCCFF;
  fill: #ECECFF; }

#dwfitkdvt4k text.actor {
  fill: black;
  stroke: none; }

#dwfitkdvt4k .actor-line {
  stroke: grey; }

#dwfitkdvt4k .messageLine0 {
  stroke-width: 1.5;
  stroke-dasharray: '2 2';
  stroke: #333; }

#dwfitkdvt4k .messageLine1 {
  stroke-width: 1.5;
  stroke-dasharray: '2 2';
  stroke: #333; }

#dwfitkdvt4k #arrowhead {
  fill: #333; }

#dwfitkdvt4k #crosshead path {
  fill: #333 !important;
  stroke: #333 !important; }

#dwfitkdvt4k .messageText {
  fill: #333;
  stroke: none; }

#dwfitkdvt4k .labelBox {
  stroke: #CCCCFF;
  fill: #ECECFF; }

#dwfitkdvt4k .labelText {
  fill: black;
  stroke: none; }

#dwfitkdvt4k .loopText {
  fill: black;
  stroke: none; }

#dwfitkdvt4k .loopLine {
  stroke-width: 2;
  stroke-dasharray: '2 2';
  stroke: #CCCCFF; }

#dwfitkdvt4k .note {
  stroke: #aaaa33;
  fill: #fff5ad; }

#dwfitkdvt4k .noteText {
  fill: black;
  stroke: none;
  font-family: 'trebuchet ms', verdana, arial;
  font-size: 14px; }

#dwfitkdvt4k .activation0 {
  fill: #f4f4f4;
  stroke: #666; }

#dwfitkdvt4k .activation1 {
  fill: #f4f4f4;
  stroke: #666; }

#dwfitkdvt4k .activation2 {
  fill: #f4f4f4;
  stroke: #666; }


#dwfitkdvt4k .section {
  stroke: none;
  opacity: 0.2; }

#dwfitkdvt4k .section0 {
  fill: rgba(102, 102, 255, 0.49); }

#dwfitkdvt4k .section2 {
  fill: #fff400; }

#dwfitkdvt4k .section1,
#dwfitkdvt4k .section3 {
  fill: white;
  opacity: 0.2; }

#dwfitkdvt4k .sectionTitle0 {
  fill: #333; }

#dwfitkdvt4k .sectionTitle1 {
  fill: #333; }

#dwfitkdvt4k .sectionTitle2 {
  fill: #333; }

#dwfitkdvt4k .sectionTitle3 {
  fill: #333; }

#dwfitkdvt4k .sectionTitle {
  text-anchor: start;
  font-size: 11px;
  text-height: 14px; }


#dwfitkdvt4k .grid .tick {
  stroke: lightgrey;
  opacity: 0.3;
  shape-rendering: crispEdges; }

#dwfitkdvt4k .grid path {
  stroke-width: 0; }


#dwfitkdvt4k .today {
  fill: none;
  stroke: red;
  stroke-width: 2px; }



#dwfitkdvt4k .task {
  stroke-width: 2; }

#dwfitkdvt4k .taskText {
  text-anchor: middle;
  font-size: 11px; }

#dwfitkdvt4k .taskTextOutsideRight {
  fill: black;
  text-anchor: start;
  font-size: 11px; }

#dwfitkdvt4k .taskTextOutsideLeft {
  fill: black;
  text-anchor: end;
  font-size: 11px; }


#dwfitkdvt4k .taskText0,
#dwfitkdvt4k .taskText1,
#dwfitkdvt4k .taskText2,
#dwfitkdvt4k .taskText3 {
  fill: white; }

#dwfitkdvt4k .task0,
#dwfitkdvt4k .task1,
#dwfitkdvt4k .task2,
#dwfitkdvt4k .task3 {
  fill: #8a90dd;
  stroke: #534fbc; }

#dwfitkdvt4k .taskTextOutside0,
#dwfitkdvt4k .taskTextOutside2 {
  fill: black; }

#dwfitkdvt4k .taskTextOutside1,
#dwfitkdvt4k .taskTextOutside3 {
  fill: black; }


#dwfitkdvt4k .active0,
#dwfitkdvt4k .active1,
#dwfitkdvt4k .active2,
#dwfitkdvt4k .active3 {
  fill: #bfc7ff;
  stroke: #534fbc; }

#dwfitkdvt4k .activeText0,
#dwfitkdvt4k .activeText1,
#dwfitkdvt4k .activeText2,
#dwfitkdvt4k .activeText3 {
  fill: black !important; }


#dwfitkdvt4k .done0,
#dwfitkdvt4k .done1,
#dwfitkdvt4k .done2,
#dwfitkdvt4k .done3 {
  stroke: grey;
  fill: lightgrey;
  stroke-width: 2; }

#dwfitkdvt4k .doneText0,
#dwfitkdvt4k .doneText1,
#dwfitkdvt4k .doneText2,
#dwfitkdvt4k .doneText3 {
  fill: black !important; }


#dwfitkdvt4k .crit0,
#dwfitkdvt4k .crit1,
#dwfitkdvt4k .crit2,
#dwfitkdvt4k .crit3 {
  stroke: #ff8888;
  fill: red;
  stroke-width: 2; }

#dwfitkdvt4k .activeCrit0,
#dwfitkdvt4k .activeCrit1,
#dwfitkdvt4k .activeCrit2,
#dwfitkdvt4k .activeCrit3 {
  stroke: #ff8888;
  fill: #bfc7ff;
  stroke-width: 2; }

#dwfitkdvt4k .doneCrit0,
#dwfitkdvt4k .doneCrit1,
#dwfitkdvt4k .doneCrit2,
#dwfitkdvt4k .doneCrit3 {
  stroke: #ff8888;
  fill: lightgrey;
  stroke-width: 2;
  cursor: pointer;
  shape-rendering: crispEdges; }

#dwfitkdvt4k .doneCritText0,
#dwfitkdvt4k .doneCritText1,
#dwfitkdvt4k .doneCritText2,
#dwfitkdvt4k .doneCritText3 {
  fill: black !important; }

#dwfitkdvt4k .activeCritText0,
#dwfitkdvt4k .activeCritText1,
#dwfitkdvt4k .activeCritText2,
#dwfitkdvt4k .activeCritText3 {
  fill: black !important; }

#dwfitkdvt4k .titleText {
  text-anchor: middle;
  font-size: 18px;
  fill: black; }

#dwfitkdvt4k g.classGroup text {
  fill: #9370DB;
  stroke: none;
  font-family: 'trebuchet ms', verdana, arial;
  font-size: 10px; }

#dwfitkdvt4k g.classGroup rect {
  fill: #ECECFF;
  stroke: #9370DB; }

#dwfitkdvt4k g.classGroup line {
  stroke: #9370DB;
  stroke-width: 1; }

#dwfitkdvt4k .classLabel .box {
  stroke: none;
  stroke-width: 0;
  fill: #ECECFF;
  opacity: 0.5; }

#dwfitkdvt4k .classLabel .label {
  fill: #9370DB;
  font-size: 10px; }

#dwfitkdvt4k .relation {
  stroke: #9370DB;
  stroke-width: 1;
  fill: none; }

#dwfitkdvt4k #compositionStart {
  fill: #9370DB;
  stroke: #9370DB;
  stroke-width: 1; }

#dwfitkdvt4k #compositionEnd {
  fill: #9370DB;
  stroke: #9370DB;
  stroke-width: 1; }

#dwfitkdvt4k #aggregationStart {
  fill: #ECECFF;
  stroke: #9370DB;
  stroke-width: 1; }

#dwfitkdvt4k #aggregationEnd {
  fill: #ECECFF;
  stroke: #9370DB;
  stroke-width: 1; }

#dwfitkdvt4k #dependencyStart {
  fill: #9370DB;
  stroke: #9370DB;
  stroke-width: 1; }

#dwfitkdvt4k #dependencyEnd {
  fill: #9370DB;
  stroke: #9370DB;
  stroke-width: 1; }

#dwfitkdvt4k #extensionStart {
  fill: #9370DB;
  stroke: #9370DB;
  stroke-width: 1; }

#dwfitkdvt4k #extensionEnd {
  fill: #9370DB;
  stroke: #9370DB;
  stroke-width: 1; }

#dwfitkdvt4k .commit-id,
#dwfitkdvt4k .commit-msg,
#dwfitkdvt4k .branch-label {
  fill: lightgrey;
  color: lightgrey; }



#dwfitkdvt4k .label{
  color:#18B14E;
}
#dwfitkdvt4k .te-md-container--dark .node rect {
  fill: red;
}

#dwfitkdvt4k .node rect,
#dwfitkdvt4k .node circle,
#dwfitkdvt4k .node ellipse,
#dwfitkdvt4k .node polygon {
  fill: #F9FFFB;;
  stroke: #2DBD60;
  stroke-width: 1.5px;
}
#dwfitkdvt4k .arrowheadPath{
  fill: #2DBD60;
}
#dwfitkdvt4k .edgePath .path {
  stroke: #2DBD60;
  stroke-width: 1px;
}
#dwfitkdvt4k .edgeLabel {
  background-color: #fff;
}
#dwfitkdvt4k .cluster rect {
  fill: #F9FFFB !important;
  stroke: #2DBD60 !important;
  stroke-width: 1px !important;
}

#dwfitkdvt4k .cluster text {
  fill: #F9FFFB;
}

#dwfitkdvt4k div.mermaidTooltip {
  background: #F9FFFB;
  border: 1px solid #2DBD60;
}


#dwfitkdvt4k .actor {
  stroke: #2DBD60;
  fill: #F9FFFB;
}

#dwfitkdvt4k text.actor {
  fill: #2DBD60;
  stroke: none;
}

#dwfitkdvt4k .actor-line {
  stroke: #2DBD60;
}

#dwfitkdvt4k .messageLine0 {
  stroke-width: 1.5;
  stroke-dasharray: '2 2';
  marker-end: 'url(#arrowhead)';
  stroke: #2DBD60;
}

#dwfitkdvt4k .messageLine1 {
  stroke-width: 1.5;
  stroke-dasharray: '2 2';
  stroke: #2DBD60;
}

#dwfitkdvt4k #arrowhead {
  fill: #2DBD60;
}

#dwfitkdvt4k #crosshead path {
  fill: #2DBD60 !important;
  stroke: #2DBD60 !important;
}

#dwfitkdvt4k .messageText {
  fill: #2DBD60;
  stroke: none;
}

#dwfitkdvt4k .labelBox {
  stroke: #2DBD60;
  fill: #F9FFFB;
}

#dwfitkdvt4k .labelText {
  fill: #2DBD60;
  stroke: #2DBD60;
}

#dwfitkdvt4k .loopText {
  fill: #2DBD60;
  stroke: #2DBD60;
}

#dwfitkdvt4k .loopLine {
  stroke-width: 2;
  stroke-dasharray: '2 2';
  marker-end: 'url(#arrowhead)';
  stroke: #2DBD60;
}

#dwfitkdvt4k .note {
  stroke: #2DBD60;
  fill: #F9FFFB;
}

#dwfitkdvt4k .noteText {
  fill: #2DBD60;
  stroke: #2DBD60;
}


#dwfitkdvt4k .section{
  opacity:1;
}
#dwfitkdvt4k .section0,#dwfitkdvt4k  .section2 {
  fill: #ECF7F0;
}

#dwfitkdvt4k .section1,
#dwfitkdvt4k .section3 {
  fill: #FFF;
}
#dwfitkdvt4k .taskText0,
#dwfitkdvt4k .taskText1,
#dwfitkdvt4k .taskText2,
#dwfitkdvt4k .taskText3 {
  fill: #fff;
}

#dwfitkdvt4k .task0,
#dwfitkdvt4k .task1,
#dwfitkdvt4k .task2,
#dwfitkdvt4k .task3 {
  fill: #2DBD60;
  stroke: #359F5A;
}
</style><style>#dwfitkdvt4k {
    color: rgb(244, 244, 244);
    font: normal normal normal normal 14px/22.399999618530273px monospace;
  }</style><g transform="translate(-12, -12)"><g class="output"><g class="clusters"></g><g class="edgePaths"><g class="edgePath" style="opacity: 1;"><path class="path" d="M136.53125,56.28125L136.53125,81.28125L136.53125,106.28125" marker-end="url(#arrowhead5957)" style="stroke: #333; stroke-width: 1.5px;fill:none"></path><defs><marker id="arrowhead5957" viewBox="0 0 10 10" refX="9" refY="5" markerUnits="strokeWidth" markerWidth="8" markerHeight="6" orient="auto"><path d="M 0 0 L 10 5 L 0 10 z" class="arrowheadPath" style="stroke-width: 1px; stroke-dasharray: 1px, 0px;"></path></marker></defs></g><g class="edgePath" style="opacity: 1;"><path class="path" d="M136.53125,142.5625L136.53125,167.5625L136.53125,192.5625" marker-end="url(#arrowhead5958)" style="stroke: #333; stroke-width: 1.5px;fill:none"></path><defs><marker id="arrowhead5958" viewBox="0 0 10 10" refX="9" refY="5" markerUnits="strokeWidth" markerWidth="8" markerHeight="6" orient="auto"><path d="M 0 0 L 10 5 L 0 10 z" class="arrowheadPath" style="stroke-width: 1px; stroke-dasharray: 1px, 0px;"></path></marker></defs></g><g class="edgePath" style="opacity: 1;"><path class="path" d="M136.53125,228.84375L136.53125,253.84375L136.53125,278.84375" marker-end="url(#arrowhead5959)" style="stroke: #333; stroke-width: 1.5px;fill:none"></path><defs><marker id="arrowhead5959" viewBox="0 0 10 10" refX="9" refY="5" markerUnits="strokeWidth" markerWidth="8" markerHeight="6" orient="auto"><path d="M 0 0 L 10 5 L 0 10 z" class="arrowheadPath" style="stroke-width: 1px; stroke-dasharray: 1px, 0px;"></path></marker></defs></g></g><g class="edgeLabels"><g class="edgeLabel" style="opacity: 1;" transform=""><g transform="translate(0,0)" class="label"><rect rx="0" ry="0" width="0" height="0" style="fill:#e8e8e8;"></rect><text><tspan xml:space="preserve" dy="1em" x="1"></tspan></text></g></g><g class="edgeLabel" style="opacity: 1;" transform=""><g transform="translate(0,0)" class="label"><rect rx="0" ry="0" width="0" height="0" style="fill:#e8e8e8;"></rect><text><tspan xml:space="preserve" dy="1em" x="1"></tspan></text></g></g><g class="edgeLabel" style="opacity: 1;" transform=""><g transform="translate(0,0)" class="label"><rect rx="0" ry="0" width="0" height="0" style="fill:#e8e8e8;"></rect><text><tspan xml:space="preserve" dy="1em" x="1"></tspan></text></g></g></g><g class="nodes"><g class="node" style="opacity: 1;" id="A" transform="translate(136.53125,38.140625)"><rect rx="0" ry="0" x="-70.3125" y="-18.140625" width="140.625" height="36.28125"></rect><g class="label" transform="translate(0,0)"><g transform="translate(-60.3125,-8.140625)"><text><tspan xml:space="preserve" dy="1em" x="1">selinux_socket_bind</tspan></text></g></g></g><g class="node" style="opacity: 1;" id="B" transform="translate(136.53125,124.421875)"><rect rx="0" ry="0" x="-104.8828125" y="-18.140625" width="209.765625" height="36.28125"></rect><g class="label" transform="translate(0,0)"><g transform="translate(-94.8828125,-8.140625)"><text><tspan xml:space="preserve" dy="1em" x="1">sock_has_perm(SOCKET__BIND)</tspan></text></g></g></g><g class="node" style="opacity: 1;" id="C" transform="translate(136.53125,210.703125)"><rect rx="0" ry="0" x="-116.53125" y="-18.140625" width="233.0625" height="36.28125"></rect><g class="label" transform="translate(0,0)"><g transform="translate(-106.53125,-8.140625)"><text><tspan xml:space="preserve" dy="1em" x="1">get nodecon sid by sel_netnode_sid</tspan></text></g></g></g><g class="node" style="opacity: 1;" id="D" transform="translate(136.53125,296.984375)"><rect rx="0" ry="0" x="-49.5390625" y="-18.140625" width="99.078125" height="36.28125"></rect><g class="label" transform="translate(0,0)"><g transform="translate(-39.5390625,-8.140625)"><text><tspan xml:space="preserve" dy="1em" x="1">av_has_perm</tspan></text></g></g></g></g></g></g></svg>
security_node_sid
会从policydb->ocontexts[OCON_NODE]
中搜索policydb中关于该IP地址的nodecon定义,如果找不着,说明此IP相关的nodecon无效(未定义),则会走默认的initial SID。
if (c) {
if (!c->sid[0]) {
rc = sidtab_context_to_sid(sidtab,
&c->context[0],
&c->sid[0]);
if (rc)
goto out;
}
*out_sid = c->sid[0];
} else {
*out_sid = SECINITSID_NODE; // <===== intial SID
}
其他SID
除了initial SID由内核直接加载生成,其他的SID则由对应的打标签流程生成。例如:文件的SID则由setfiles/restorecon工具打入文件系统的扩展属性上,socket则由socket系统调用创建时生成。
以socket bind为例,因为比较简单。当socket bind系统调用被执行时,一个socket object被绑定到一个node上。而此时该node的SID才被写入policydb中。
int sel_netnode_sid(void *addr, u16 family, u32 *sid)
{
struct sel_netnode *node;
rcu_read_lock();
node = sel_netnode_find(addr, family);
if (node != NULL) {
*sid = node->nsec.sid;
rcu_read_unlock();
return 0;
}
rcu_read_unlock();
return sel_netnode_sid_slow(addr, family, sid);
}
sel_netnode_sid_slow
调用security_node_sid
,并最终调用sidtab_context_to_sid
将相关的SID以及对应的context数据结构插入到表中。
<svg id="dkdtggueo7c" width="100%" xmlns="http://www.w3.org/2000/svg" style="max-width: 431.125px;" viewBox="0 0 431.125 470.046875"><style>


#dkdtggueo7c .label {
  font-family: 'trebuchet ms', verdana, arial;
  color: #333; }

#dkdtggueo7c .node rect,
#dkdtggueo7c .node circle,
#dkdtggueo7c .node ellipse,
#dkdtggueo7c .node polygon {
  fill: #ECECFF;
  stroke: #9370DB;
  stroke-width: 1px; }

#dkdtggueo7c .node.clickable {
  cursor: pointer; }

#dkdtggueo7c .arrowheadPath {
  fill: #333333; }

#dkdtggueo7c .edgePath .path {
  stroke: #333333;
  stroke-width: 1.5px; }

#dkdtggueo7c .edgeLabel {
  background-color: #e8e8e8; }

#dkdtggueo7c .cluster rect {
  fill: #ffffde !important;
  stroke: #aaaa33 !important;
  stroke-width: 1px !important; }

#dkdtggueo7c .cluster text {
  fill: #333; }

#dkdtggueo7c div.mermaidTooltip {
  position: absolute;
  text-align: center;
  max-width: 200px;
  padding: 2px;
  font-family: 'trebuchet ms', verdana, arial;
  font-size: 12px;
  background: #ffffde;
  border: 1px solid #aaaa33;
  border-radius: 2px;
  pointer-events: none;
  z-index: 100; }

#dkdtggueo7c .actor {
  stroke: #CCCCFF;
  fill: #ECECFF; }

#dkdtggueo7c text.actor {
  fill: black;
  stroke: none; }

#dkdtggueo7c .actor-line {
  stroke: grey; }

#dkdtggueo7c .messageLine0 {
  stroke-width: 1.5;
  stroke-dasharray: '2 2';
  stroke: #333; }

#dkdtggueo7c .messageLine1 {
  stroke-width: 1.5;
  stroke-dasharray: '2 2';
  stroke: #333; }

#dkdtggueo7c #arrowhead {
  fill: #333; }

#dkdtggueo7c #crosshead path {
  fill: #333 !important;
  stroke: #333 !important; }

#dkdtggueo7c .messageText {
  fill: #333;
  stroke: none; }

#dkdtggueo7c .labelBox {
  stroke: #CCCCFF;
  fill: #ECECFF; }

#dkdtggueo7c .labelText {
  fill: black;
  stroke: none; }

#dkdtggueo7c .loopText {
  fill: black;
  stroke: none; }

#dkdtggueo7c .loopLine {
  stroke-width: 2;
  stroke-dasharray: '2 2';
  stroke: #CCCCFF; }

#dkdtggueo7c .note {
  stroke: #aaaa33;
  fill: #fff5ad; }

#dkdtggueo7c .noteText {
  fill: black;
  stroke: none;
  font-family: 'trebuchet ms', verdana, arial;
  font-size: 14px; }

#dkdtggueo7c .activation0 {
  fill: #f4f4f4;
  stroke: #666; }

#dkdtggueo7c .activation1 {
  fill: #f4f4f4;
  stroke: #666; }

#dkdtggueo7c .activation2 {
  fill: #f4f4f4;
  stroke: #666; }


#dkdtggueo7c .section {
  stroke: none;
  opacity: 0.2; }

#dkdtggueo7c .section0 {
  fill: rgba(102, 102, 255, 0.49); }

#dkdtggueo7c .section2 {
  fill: #fff400; }

#dkdtggueo7c .section1,
#dkdtggueo7c .section3 {
  fill: white;
  opacity: 0.2; }

#dkdtggueo7c .sectionTitle0 {
  fill: #333; }

#dkdtggueo7c .sectionTitle1 {
  fill: #333; }

#dkdtggueo7c .sectionTitle2 {
  fill: #333; }

#dkdtggueo7c .sectionTitle3 {
  fill: #333; }

#dkdtggueo7c .sectionTitle {
  text-anchor: start;
  font-size: 11px;
  text-height: 14px; }


#dkdtggueo7c .grid .tick {
  stroke: lightgrey;
  opacity: 0.3;
  shape-rendering: crispEdges; }

#dkdtggueo7c .grid path {
  stroke-width: 0; }


#dkdtggueo7c .today {
  fill: none;
  stroke: red;
  stroke-width: 2px; }



#dkdtggueo7c .task {
  stroke-width: 2; }

#dkdtggueo7c .taskText {
  text-anchor: middle;
  font-size: 11px; }

#dkdtggueo7c .taskTextOutsideRight {
  fill: black;
  text-anchor: start;
  font-size: 11px; }

#dkdtggueo7c .taskTextOutsideLeft {
  fill: black;
  text-anchor: end;
  font-size: 11px; }


#dkdtggueo7c .taskText0,
#dkdtggueo7c .taskText1,
#dkdtggueo7c .taskText2,
#dkdtggueo7c .taskText3 {
  fill: white; }

#dkdtggueo7c .task0,
#dkdtggueo7c .task1,
#dkdtggueo7c .task2,
#dkdtggueo7c .task3 {
  fill: #8a90dd;
  stroke: #534fbc; }

#dkdtggueo7c .taskTextOutside0,
#dkdtggueo7c .taskTextOutside2 {
  fill: black; }

#dkdtggueo7c .taskTextOutside1,
#dkdtggueo7c .taskTextOutside3 {
  fill: black; }


#dkdtggueo7c .active0,
#dkdtggueo7c .active1,
#dkdtggueo7c .active2,
#dkdtggueo7c .active3 {
  fill: #bfc7ff;
  stroke: #534fbc; }

#dkdtggueo7c .activeText0,
#dkdtggueo7c .activeText1,
#dkdtggueo7c .activeText2,
#dkdtggueo7c .activeText3 {
  fill: black !important; }


#dkdtggueo7c .done0,
#dkdtggueo7c .done1,
#dkdtggueo7c .done2,
#dkdtggueo7c .done3 {
  stroke: grey;
  fill: lightgrey;
  stroke-width: 2; }

#dkdtggueo7c .doneText0,
#dkdtggueo7c .doneText1,
#dkdtggueo7c .doneText2,
#dkdtggueo7c .doneText3 {
  fill: black !important; }


#dkdtggueo7c .crit0,
#dkdtggueo7c .crit1,
#dkdtggueo7c .crit2,
#dkdtggueo7c .crit3 {
  stroke: #ff8888;
  fill: red;
  stroke-width: 2; }

#dkdtggueo7c .activeCrit0,
#dkdtggueo7c .activeCrit1,
#dkdtggueo7c .activeCrit2,
#dkdtggueo7c .activeCrit3 {
  stroke: #ff8888;
  fill: #bfc7ff;
  stroke-width: 2; }

#dkdtggueo7c .doneCrit0,
#dkdtggueo7c .doneCrit1,
#dkdtggueo7c .doneCrit2,
#dkdtggueo7c .doneCrit3 {
  stroke: #ff8888;
  fill: lightgrey;
  stroke-width: 2;
  cursor: pointer;
  shape-rendering: crispEdges; }

#dkdtggueo7c .doneCritText0,
#dkdtggueo7c .doneCritText1,
#dkdtggueo7c .doneCritText2,
#dkdtggueo7c .doneCritText3 {
  fill: black !important; }

#dkdtggueo7c .activeCritText0,
#dkdtggueo7c .activeCritText1,
#dkdtggueo7c .activeCritText2,
#dkdtggueo7c .activeCritText3 {
  fill: black !important; }

#dkdtggueo7c .titleText {
  text-anchor: middle;
  font-size: 18px;
  fill: black; }

#dkdtggueo7c g.classGroup text {
  fill: #9370DB;
  stroke: none;
  font-family: 'trebuchet ms', verdana, arial;
  font-size: 10px; }

#dkdtggueo7c g.classGroup rect {
  fill: #ECECFF;
  stroke: #9370DB; }

#dkdtggueo7c g.classGroup line {
  stroke: #9370DB;
  stroke-width: 1; }

#dkdtggueo7c .classLabel .box {
  stroke: none;
  stroke-width: 0;
  fill: #ECECFF;
  opacity: 0.5; }

#dkdtggueo7c .classLabel .label {
  fill: #9370DB;
  font-size: 10px; }

#dkdtggueo7c .relation {
  stroke: #9370DB;
  stroke-width: 1;
  fill: none; }

#dkdtggueo7c #compositionStart {
  fill: #9370DB;
  stroke: #9370DB;
  stroke-width: 1; }

#dkdtggueo7c #compositionEnd {
  fill: #9370DB;
  stroke: #9370DB;
  stroke-width: 1; }

#dkdtggueo7c #aggregationStart {
  fill: #ECECFF;
  stroke: #9370DB;
  stroke-width: 1; }

#dkdtggueo7c #aggregationEnd {
  fill: #ECECFF;
  stroke: #9370DB;
  stroke-width: 1; }

#dkdtggueo7c #dependencyStart {
  fill: #9370DB;
  stroke: #9370DB;
  stroke-width: 1; }

#dkdtggueo7c #dependencyEnd {
  fill: #9370DB;
  stroke: #9370DB;
  stroke-width: 1; }

#dkdtggueo7c #extensionStart {
  fill: #9370DB;
  stroke: #9370DB;
  stroke-width: 1; }

#dkdtggueo7c #extensionEnd {
  fill: #9370DB;
  stroke: #9370DB;
  stroke-width: 1; }

#dkdtggueo7c .commit-id,
#dkdtggueo7c .commit-msg,
#dkdtggueo7c .branch-label {
  fill: lightgrey;
  color: lightgrey; }



#dkdtggueo7c .label{
  color:#18B14E;
}
#dkdtggueo7c .te-md-container--dark .node rect {
  fill: red;
}

#dkdtggueo7c .node rect,
#dkdtggueo7c .node circle,
#dkdtggueo7c .node ellipse,
#dkdtggueo7c .node polygon {
  fill: #F9FFFB;;
  stroke: #2DBD60;
  stroke-width: 1.5px;
}
#dkdtggueo7c .arrowheadPath{
  fill: #2DBD60;
}
#dkdtggueo7c .edgePath .path {
  stroke: #2DBD60;
  stroke-width: 1px;
}
#dkdtggueo7c .edgeLabel {
  background-color: #fff;
}
#dkdtggueo7c .cluster rect {
  fill: #F9FFFB !important;
  stroke: #2DBD60 !important;
  stroke-width: 1px !important;
}

#dkdtggueo7c .cluster text {
  fill: #F9FFFB;
}

#dkdtggueo7c div.mermaidTooltip {
  background: #F9FFFB;
  border: 1px solid #2DBD60;
}


#dkdtggueo7c .actor {
  stroke: #2DBD60;
  fill: #F9FFFB;
}

#dkdtggueo7c text.actor {
  fill: #2DBD60;
  stroke: none;
}

#dkdtggueo7c .actor-line {
  stroke: #2DBD60;
}

#dkdtggueo7c .messageLine0 {
  stroke-width: 1.5;
  stroke-dasharray: '2 2';
  marker-end: 'url(#arrowhead)';
  stroke: #2DBD60;
}

#dkdtggueo7c .messageLine1 {
  stroke-width: 1.5;
  stroke-dasharray: '2 2';
  stroke: #2DBD60;
}

#dkdtggueo7c #arrowhead {
  fill: #2DBD60;
}

#dkdtggueo7c #crosshead path {
  fill: #2DBD60 !important;
  stroke: #2DBD60 !important;
}

#dkdtggueo7c .messageText {
  fill: #2DBD60;
  stroke: none;
}

#dkdtggueo7c .labelBox {
  stroke: #2DBD60;
  fill: #F9FFFB;
}

#dkdtggueo7c .labelText {
  fill: #2DBD60;
  stroke: #2DBD60;
}

#dkdtggueo7c .loopText {
  fill: #2DBD60;
  stroke: #2DBD60;
}

#dkdtggueo7c .loopLine {
  stroke-width: 2;
  stroke-dasharray: '2 2';
  marker-end: 'url(#arrowhead)';
  stroke: #2DBD60;
}

#dkdtggueo7c .note {
  stroke: #2DBD60;
  fill: #F9FFFB;
}

#dkdtggueo7c .noteText {
  fill: #2DBD60;
  stroke: #2DBD60;
}


#dkdtggueo7c .section{
  opacity:1;
}
#dkdtggueo7c .section0,#dkdtggueo7c  .section2 {
  fill: #ECF7F0;
}

#dkdtggueo7c .section1,
#dkdtggueo7c .section3 {
  fill: #FFF;
}
#dkdtggueo7c .taskText0,
#dkdtggueo7c .taskText1,
#dkdtggueo7c .taskText2,
#dkdtggueo7c .taskText3 {
  fill: #fff;
}

#dkdtggueo7c .task0,
#dkdtggueo7c .task1,
#dkdtggueo7c .task2,
#dkdtggueo7c .task3 {
  fill: #2DBD60;
  stroke: #359F5A;
}
</style><style>#dkdtggueo7c {
    color: rgb(244, 244, 244);
    font: normal normal normal normal 14px/22.399999618530273px monospace;
  }</style><g transform="translate(-12, -12)"><g class="output"><g class="clusters"></g><g class="edgePaths"><g class="edgePath" style="opacity: 1;"><path class="path" d="M260.1953125,56.28125L260.1953125,81.28125L260.1953125,106.28125" marker-end="url(#arrowhead5988)" style="stroke: #333; stroke-width: 1.5px;fill:none"></path><defs><marker id="arrowhead5988" viewBox="0 0 10 10" refX="9" refY="5" markerUnits="strokeWidth" markerWidth="8" markerHeight="6" orient="auto"><path d="M 0 0 L 10 5 L 0 10 z" class="arrowheadPath" style="stroke-width: 1px; stroke-dasharray: 1px, 0px;"></path></marker></defs></g><g class="edgePath" style="opacity: 1;"><path class="path" d="M255.86743030164533,142.5625L247.9609375,175.703125L255.10490664446002,214.93415585553998" marker-end="url(#arrowhead5989)" style="stroke: #333; stroke-width: 1.5px;fill:none"></path><defs><marker id="arrowhead5989" viewBox="0 0 10 10" refX="9" refY="5" markerUnits="strokeWidth" markerWidth="8" markerHeight="6" orient="auto"><path d="M 0 0 L 10 5 L 0 10 z" class="arrowheadPath" style="stroke-width: 1px; stroke-dasharray: 1px, 0px;"></path></marker></defs></g><g class="edgePath" style="opacity: 1;"><path class="path" d="M266.28571835554,214.93415585553998L272.4296875,175.703125L264.52319469835464,142.5625" marker-end="url(#arrowhead5990)" style="stroke: #333; stroke-width: 1.5px;fill:none"></path><defs><marker id="arrowhead5990" viewBox="0 0 10 10" refX="9" refY="5" markerUnits="strokeWidth" markerWidth="8" markerHeight="6" orient="auto"><path d="M 0 0 L 10 5 L 0 10 z" class="arrowheadPath" style="stroke-width: 1px; stroke-dasharray: 1px, 0px;"></path></marker></defs></g><g class="edgePath" style="opacity: 1;"><path class="path" d="M237.03036148388372,262.0381739838837L143.9140625,318.34375L143.9140625,351.484375" marker-end="url(#arrowhead5991)" style="stroke: #333; stroke-width: 1.5px;fill:none"></path><defs><marker id="arrowhead5991" viewBox="0 0 10 10" refX="9" refY="5" markerUnits="strokeWidth" markerWidth="8" markerHeight="6" orient="auto"><path d="M 0 0 L 10 5 L 0 10 z" class="arrowheadPath" style="stroke-width: 1px; stroke-dasharray: 1px, 0px;"></path></marker></defs></g><g class="edgePath" style="opacity: 1;"><path class="path" d="M143.9140625,387.765625L143.9140625,412.765625L238.9453125,448.0224486025262" marker-end="url(#arrowhead5992)" style="stroke: #333; stroke-width: 1.5px;fill:none"></path><defs><marker id="arrowhead5992" viewBox="0 0 10 10" refX="9" refY="5" markerUnits="strokeWidth" markerWidth="8" markerHeight="6" orient="auto"><path d="M 0 0 L 10 5 L 0 10 z" class="arrowheadPath" style="stroke-width: 1px; stroke-dasharray: 1px, 0px;"></path></marker></defs></g><g class="edgePath" style="opacity: 1;"><path class="path" d="M284.3602635161163,262.0381739838837L376.4765625,318.34375L376.4765625,351.484375" marker-end="url(#arrowhead5993)" style="stroke: #333; stroke-width: 1.5px;fill:none"></path><defs><marker id="arrowhead5993" viewBox="0 0 10 10" refX="9" refY="5" markerUnits="strokeWidth" markerWidth="8" markerHeight="6" orient="auto"><path d="M 0 0 L 10 5 L 0 10 z" class="arrowheadPath" style="stroke-width: 1px; stroke-dasharray: 1px, 0px;"></path></marker></defs></g><g class="edgePath" style="opacity: 1;"><path class="path" d="M376.4765625,387.765625L376.4765625,412.765625L281.4453125,448.0224486025262" marker-end="url(#arrowhead5994)" style="stroke: #333; stroke-width: 1.5px;fill:none"></path><defs><marker id="arrowhead5994" viewBox="0 0 10 10" refX="9" refY="5" markerUnits="strokeWidth" markerWidth="8" markerHeight="6" orient="auto"><path d="M 0 0 L 10 5 L 0 10 z" class="arrowheadPath" style="stroke-width: 1px; stroke-dasharray: 1px, 0px;"></path></marker></defs></g></g><g class="edgeLabels"><g class="edgeLabel" style="opacity: 1;" transform=""><g transform="translate(0,0)" class="label"><rect rx="0" ry="0" width="0" height="0" style="fill:#e8e8e8;"></rect><text><tspan xml:space="preserve" dy="1em" x="1"></tspan></text></g></g><g class="edgeLabel" style="opacity: 1;" transform=""><g transform="translate(0,0)" class="label"><rect rx="0" ry="0" width="0" height="0" style="fill:#e8e8e8;"></rect><text><tspan xml:space="preserve" dy="1em" x="1"></tspan></text></g></g><g class="edgeLabel" style="opacity: 1;" transform="translate(272.4296875,175.703125)"><g transform="translate(-4.203125,-8.0078125)" class="label"><rect rx="0" ry="0" width="8.9375" height="16.28125" style="fill:#e8e8e8;"></rect><text><tspan xml:space="preserve" dy="1em" x="1">N</tspan></text></g></g><g class="edgeLabel" style="opacity: 1;" transform="translate(143.9140625,318.34375)"><g transform="translate(-4.203125,-8.0078125)" class="label"><rect rx="0" ry="0" width="8" height="16.28125" style="fill:#e8e8e8;"></rect><text><tspan xml:space="preserve" dy="1em" x="1">Y</tspan></text></g></g><g class="edgeLabel" style="opacity: 1;" transform=""><g transform="translate(0,0)" class="label"><rect rx="0" ry="0" width="0" height="0" style="fill:#e8e8e8;"></rect><text><tspan xml:space="preserve" dy="1em" x="1"></tspan></text></g></g><g class="edgeLabel" style="opacity: 1;" transform="translate(376.4765625,318.34375)"><g transform="translate(-40.6640625,-8.0078125)" class="label"><rect rx="0" ry="0" width="62.65625" height="16.28125" style="fill:#e8e8e8;"></rect><text><tspan xml:space="preserve" dy="1em" x="1">Never find</tspan></text></g></g><g class="edgeLabel" style="opacity: 1;" transform=""><g transform="translate(0,0)" class="label"><rect rx="0" ry="0" width="0" height="0" style="fill:#e8e8e8;"></rect><text><tspan xml:space="preserve" dy="1em" x="1"></tspan></text></g></g></g><g class="nodes"><g class="node" style="opacity: 1;" id="A" transform="translate(260.1953125,38.140625)"><rect rx="0" ry="0" x="-63.859375" y="-18.140625" width="127.71875" height="36.28125"></rect><g class="label" transform="translate(0,0)"><g transform="translate(-53.859375,-8.140625)"><text><tspan xml:space="preserve" dy="1em" x="1">security_node_sid</tspan></text></g></g></g><g class="node" style="opacity: 1;" id="B" transform="translate(260.1953125,124.421875)"><rect rx="0" ry="0" x="-134.3671875" y="-18.140625" width="268.734375" height="36.28125"></rect><g class="label" transform="translate(0,0)"><g transform="translate(-124.3671875,-8.140625)"><text><tspan xml:space="preserve" dy="1em" x="1">search policydb-&gt;ocontexts[OCON_NODE]</tspan></text></g></g></g><g class="node" style="opacity: 1;" id="C" transform="translate(260.1953125,247.0234375)"><polygon points="38.1796875,0 76.359375,-38.1796875 38.1796875,-76.359375 0,-38.1796875" rx="5" ry="5" transform="translate(-38.1796875,38.1796875)"></polygon><g class="label" transform="translate(0,0)"><g transform="translate(-14.28125,-8.140625)"><text><tspan xml:space="preserve" dy="1em" x="1">find?</tspan></text></g></g></g><g class="node" style="opacity: 1;" id="D" transform="translate(143.9140625,369.625)"><rect rx="0" ry="0" x="-123.9140625" y="-18.140625" width="247.828125" height="36.28125"></rect><g class="label" transform="translate(0,0)"><g transform="translate(-113.9140625,-8.140625)"><text><tspan xml:space="preserve" dy="1em" x="1">sidtab_context_to_sid(context，&amp;sid)</tspan></text></g></g></g><g class="node" style="opacity: 1;" id="E" transform="translate(260.1953125,455.90625)"><rect rx="5" ry="5" x="-21.25" y="-18.140625" width="42.5" height="36.28125"></rect><g class="label" transform="translate(0,0)"><g transform="translate(-11.25,-8.140625)"><text><tspan xml:space="preserve" dy="1em" x="1">end</tspan></text></g></g></g><g class="node" style="opacity: 1;" id="F" transform="translate(376.4765625,369.625)"><rect rx="0" ry="0" x="-58.6484375" y="-18.140625" width="117.296875" height="36.28125"></rect><g class="label" transform="translate(0,0)"><g transform="translate(-48.6484375,-8.140625)"><text><tspan xml:space="preserve" dy="1em" x="1">set an initial SID</tspan></text></g></g></g></g></g></g></svg>
security_node_sid
使用传入的IP地址在policydb中匹配查找context,如果找到则进行下一步,匹配或生成SID,找不到,则直接使用initial SID。sidtab_context_to_sid
将context写入sidtab,并获取返回的SID记入policydb中,后续通过context找SID,直接匹配policydb->ocontexts[OCON_NODE];
即可。对于SID本身的生成也很简单,就是一个单向增长的整形数字,在sidtab_context_to_sid
中。
sid = sidtab_search_context(s, context);
if (sid)
goto unlock_out;
...
sid = s->next_sid++;
..
ret = sidtab_insert(s, sid, context);
先尝试在sidtab中查找,如果找不到就加一条记录,并为sid赋值。
总结
SID在整个SELinux子系统中的作用就是提升匹配性能(从安全上下文的字符串匹配,降低到整数匹配),所以在整个SELinux子系统生命周期内,SID总是与安全上下文(context)一一对应的。在一次权限匹配过程中,SID的使用如下:
u32 sid;
struct context {
u32 user;
u32 role;
u32 type;
u32 len; /* length of string in bytes */
struct mls_range range;
char *str; /* string representation if context cannot be mapped. */
};
相关工具
没有一个专门的工具用来转换SID与context。但libselinux提供了相应的接口,参考sidget(3) - Linux man page。
int avc_context_to_sid(security_context_t ctx, security_id_t *sid);
int avc_sid_to_context(security_id_t sid, security_context_t *ctx);
seinfo
- 打印所有initial SID
[ben@localhost ~]$ seinfo --initialsid
Initial SIDs: 27
any_socket
devnull
file
file_labels
fs
icmp_socket
igmp_packet
init
kernel
...
- 打印selinuxfs context
[ben@localhost ~]$ seinfo --genfscon|grep selinux
genfscon selinuxfs / system_u:object_r:security_t:s0
initial_contexts
策略加载后,每个initial SID都有一个对应的context。这些context在各策略模块中定义。这些context在selinuxfs可以查看:
[ben@localhost ~]$ sudo cat /sys/fs/selinux/initial_contexts/kernel
system_u:system_r:kernel_t:s0
参考文献
- Fedora refpolicy
- Frank Mayer, Karl MacMillan, David Caplan, July 27, 2006- “SELinux by Example: Using Security Enhanced Linux”
- SELinux官方教材,"The SELinux Notebook" Volume II, Building The Sample Policy
- SELinux官方教材,"The SELinux Notebook 4th Edition"