요약·해설과 원문, 전문 번역을 서로 분리했습니다. API 이름, symbol, source path는 원문 표기를 사용합니다.
1. 요약·해설
원문의 핵심 논리와 kernel programming 관점의 보충 설명입니다. 아래의 전문 번역과는 별도로 작성했습니다.
smackfs interface
Smack.rst:131-337Access rule, CIPSO, network host, ptrace와 relabel interface를 정리합니다.
보안 모델과 rule
Smack.rst:338-628Smack 백서의 MAC 배경, label 규칙, access mode와 object별 적용을 설명합니다.
Networking과 API
Smack.rst:629-809CIPSO mapping, netlabel exception, application 유형과 xattr API를 설명합니다.
관리와 auditing
Smack.rst:810-871Filesystem mount option, logging level과 bringup mode를 설명합니다.
2. 영어 원문 전체
번역 기준이 된 Linux v6.18.37 원문입니다. 줄 번호는 이 버전의 파일 좌표입니다.
원문 전체 펼치기
=====
Smack
=====
"Good for you, you've decided to clean the elevator!"
- The Elevator, from Dark Star
Smack is the Simplified Mandatory Access Control Kernel.
Smack is a kernel based implementation of mandatory access
control that includes simplicity in its primary design goals.
Smack is not the only Mandatory Access Control scheme
available for Linux. Those new to Mandatory Access Control
are encouraged to compare Smack with the other mechanisms
available to determine which is best suited to the problem
at hand.
Smack consists of three major components:
- The kernel
- Basic utilities, which are helpful but not required
- Configuration data
The kernel component of Smack is implemented as a Linux
Security Modules (LSM) module. It requires netlabel and
works best with file systems that support extended attributes,
although xattr support is not strictly required.
It is safe to run a Smack kernel under a "vanilla" distribution.
Smack kernels use the CIPSO IP option. Some network
configurations are intolerant of IP options and can impede
access to systems that use them as Smack does.
Smack is used in the Tizen operating system. Please
go to http://wiki.tizen.org for information about how
Smack is used in Tizen.
The current git repository for Smack user space is:
git://github.com/smack-team/smack.git
This should make and install on most modern distributions.
There are five commands included in smackutil:
chsmack:
display or set Smack extended attribute values
smackctl:
load the Smack access rules
smackaccess:
report if a process with one label has access
to an object with another
These two commands are obsolete with the introduction of
the smackfs/load2 and smackfs/cipso2 interfaces.
smackload:
properly formats data for writing to smackfs/load
smackcipso:
properly formats data for writing to smackfs/cipso
In keeping with the intent of Smack, configuration data is
minimal and not strictly required. The most important
configuration step is mounting the smackfs pseudo filesystem.
If smackutil is installed the startup script will take care
of this, but it can be manually as well.
Add this line to ``/etc/fstab``::
smackfs /sys/fs/smackfs smackfs defaults 0 0
The ``/sys/fs/smackfs`` directory is created by the kernel.
Smack uses extended attributes (xattrs) to store labels on filesystem
objects. The attributes are stored in the extended attribute security
name space. A process must have ``CAP_MAC_ADMIN`` to change any of these
attributes.
The extended attributes that Smack uses are:
SMACK64
Used to make access control decisions. In almost all cases
the label given to a new filesystem object will be the label
of the process that created it.
SMACK64EXEC
The Smack label of a process that execs a program file with
this attribute set will run with this attribute's value.
SMACK64MMAP
Don't allow the file to be mmapped by a process whose Smack
label does not allow all of the access permitted to a process
with the label contained in this attribute. This is a very
specific use case for shared libraries.
SMACK64TRANSMUTE
Can only have the value "TRUE". If this attribute is present
on a directory when an object is created in the directory and
the Smack rule (more below) that permitted the write access
to the directory includes the transmute ("t") mode the object
gets the label of the directory instead of the label of the
creating process. If the object being created is a directory
the SMACK64TRANSMUTE attribute is set as well.
SMACK64IPIN
This attribute is only available on file descriptors for sockets.
Use the Smack label in this attribute for access control
decisions on packets being delivered to this socket.
SMACK64IPOUT
This attribute is only available on file descriptors for sockets.
Use the Smack label in this attribute for access control
decisions on packets coming from this socket.
There are multiple ways to set a Smack label on a file::
# attr -S -s SMACK64 -V "value" path
# chsmack -a value path
A process can see the Smack label it is running with by
reading ``/proc/self/attr/current``. A process with ``CAP_MAC_ADMIN``
can set the process Smack by writing there.
Most Smack configuration is accomplished by writing to files
in the smackfs filesystem. This pseudo-filesystem is mounted
on ``/sys/fs/smackfs``.
access
Provided for backward compatibility. The access2 interface
is preferred and should be used instead.
This interface reports whether a subject with the specified
Smack label has a particular access to an object with a
specified Smack label. Write a fixed format access rule to
this file. The next read will indicate whether the access
would be permitted. The text will be either "1" indicating
access, or "0" indicating denial.
access2
This interface reports whether a subject with the specified
Smack label has a particular access to an object with a
specified Smack label. Write a long format access rule to
this file. The next read will indicate whether the access
would be permitted. The text will be either "1" indicating
access, or "0" indicating denial.
ambient
This contains the Smack label applied to unlabeled network
packets.
change-rule
This interface allows modification of existing access control rules.
The format accepted on write is::
"%s %s %s %s"
where the first string is the subject label, the second the
object label, the third the access to allow and the fourth the
access to deny. The access strings may contain only the characters
"rwxat-". If a rule for a given subject and object exists it will be
modified by enabling the permissions in the third string and disabling
those in the fourth string. If there is no such rule it will be
created using the access specified in the third and the fourth strings.
cipso
Provided for backward compatibility. The cipso2 interface
is preferred and should be used instead.
This interface allows a specific CIPSO header to be assigned
to a Smack label. The format accepted on write is::
"%24s%4d%4d"["%4d"]...
The first string is a fixed Smack label. The first number is
the level to use. The second number is the number of categories.
The following numbers are the categories::
"level-3-cats-5-19 3 2 5 19"
cipso2
This interface allows a specific CIPSO header to be assigned
to a Smack label. The format accepted on write is::
"%s%4d%4d"["%4d"]...
The first string is a long Smack label. The first number is
the level to use. The second number is the number of categories.
The following numbers are the categories::
"level-3-cats-5-19 3 2 5 19"
direct
This contains the CIPSO level used for Smack direct label
representation in network packets.
doi
This contains the CIPSO domain of interpretation used in
network packets.
ipv6host
This interface allows specific IPv6 internet addresses to be
treated as single label hosts. Packets are sent to single
label hosts only from processes that have Smack write access
to the host label. All packets received from single label hosts
are given the specified label. The format accepted on write is::
"%h:%h:%h:%h:%h:%h:%h:%h label" or
"%h:%h:%h:%h:%h:%h:%h:%h/%d label".
The "::" address shortcut is not supported.
If label is "-DELETE" a matched entry will be deleted.
load
Provided for backward compatibility. The load2 interface
is preferred and should be used instead.
This interface allows access control rules in addition to
the system defined rules to be specified. The format accepted
on write is::
"%24s%24s%5s"
where the first string is the subject label, the second the
object label, and the third the requested access. The access
string may contain only the characters "rwxat-", and specifies
which sort of access is allowed. The "-" is a placeholder for
permissions that are not allowed. The string "r-x--" would
specify read and execute access. Labels are limited to 23
characters in length.
load2
This interface allows access control rules in addition to
the system defined rules to be specified. The format accepted
on write is::
"%s %s %s"
where the first string is the subject label, the second the
object label, and the third the requested access. The access
string may contain only the characters "rwxat-", and specifies
which sort of access is allowed. The "-" is a placeholder for
permissions that are not allowed. The string "r-x--" would
specify read and execute access.
load-self
Provided for backward compatibility. The load-self2 interface
is preferred and should be used instead.
This interface allows process specific access rules to be
defined. These rules are only consulted if access would
otherwise be permitted, and are intended to provide additional
restrictions on the process. The format is the same as for
the load interface.
load-self2
This interface allows process specific access rules to be
defined. These rules are only consulted if access would
otherwise be permitted, and are intended to provide additional
restrictions on the process. The format is the same as for
the load2 interface.
logging
This contains the Smack logging state.
mapped
This contains the CIPSO level used for Smack mapped label
representation in network packets.
netlabel
This interface allows specific internet addresses to be
treated as single label hosts. Packets are sent to single
label hosts without CIPSO headers, but only from processes
that have Smack write access to the host label. All packets
received from single label hosts are given the specified
label. The format accepted on write is::
"%d.%d.%d.%d label" or "%d.%d.%d.%d/%d label".
If the label specified is "-CIPSO" the address is treated
as a host that supports CIPSO headers.
onlycap
This contains labels processes must have for CAP_MAC_ADMIN
and ``CAP_MAC_OVERRIDE`` to be effective. If this file is empty
these capabilities are effective at for processes with any
label. The values are set by writing the desired labels, separated
by spaces, to the file or cleared by writing "-" to the file.
ptrace
This is used to define the current ptrace policy
0 - default:
this is the policy that relies on Smack access rules.
For the ``PTRACE_READ`` a subject needs to have a read access on
object. For the ``PTRACE_ATTACH`` a read-write access is required.
1 - exact:
this is the policy that limits ``PTRACE_ATTACH``. Attach is
only allowed when subject's and object's labels are equal.
``PTRACE_READ`` is not affected. Can be overridden with ``CAP_SYS_PTRACE``.
2 - draconian:
this policy behaves like the 'exact' above with an
exception that it can't be overridden with ``CAP_SYS_PTRACE``.
revoke-subject
Writing a Smack label here sets the access to '-' for all access
rules with that subject label.
unconfined
If the kernel is configured with ``CONFIG_SECURITY_SMACK_BRINGUP``
a process with ``CAP_MAC_ADMIN`` can write a label into this interface.
Thereafter, accesses that involve that label will be logged and
the access permitted if it wouldn't be otherwise. Note that this
is dangerous and can ruin the proper labeling of your system.
It should never be used in production.
relabel-self
This interface contains a list of labels to which the process can
transition to, by writing to ``/proc/self/attr/current``.
Normally a process can change its own label to any legal value, but only
if it has ``CAP_MAC_ADMIN``. This interface allows a process without
``CAP_MAC_ADMIN`` to relabel itself to one of labels from predefined list.
A process without ``CAP_MAC_ADMIN`` can change its label only once. When it
does, this list will be cleared.
The values are set by writing the desired labels, separated
by spaces, to the file or cleared by writing "-" to the file.
If you are using the smackload utility
you can add access rules in ``/etc/smack/accesses``. They take the form::
subjectlabel objectlabel access
access is a combination of the letters rwxatb which specify the
kind of access permitted a subject with subjectlabel on an
object with objectlabel. If there is no rule no access is allowed.
Look for additional programs on http://schaufler-ca.com
The Simplified Mandatory Access Control Kernel (Whitepaper)
===========================================================
Casey Schaufler
Mandatory Access Control
------------------------
Computer systems employ a variety of schemes to constrain how information is
shared among the people and services using the machine. Some of these schemes
allow the program or user to decide what other programs or users are allowed
access to pieces of data. These schemes are called discretionary access
control mechanisms because the access control is specified at the discretion
of the user. Other schemes do not leave the decision regarding what a user or
program can access up to users or programs. These schemes are called mandatory
access control mechanisms because you don't have a choice regarding the users
or programs that have access to pieces of data.
Bell & LaPadula
---------------
From the middle of the 1980's until the turn of the century Mandatory Access
Control (MAC) was very closely associated with the Bell & LaPadula security
model, a mathematical description of the United States Department of Defense
policy for marking paper documents. MAC in this form enjoyed a following
within the Capital Beltway and Scandinavian supercomputer centers but was
often sited as failing to address general needs.
Domain Type Enforcement
-----------------------
Around the turn of the century Domain Type Enforcement (DTE) became popular.
This scheme organizes users, programs, and data into domains that are
protected from each other. This scheme has been widely deployed as a component
of popular Linux distributions. The administrative overhead required to
maintain this scheme and the detailed understanding of the whole system
necessary to provide a secure domain mapping leads to the scheme being
disabled or used in limited ways in the majority of cases.
Smack
-----
Smack is a Mandatory Access Control mechanism designed to provide useful MAC
while avoiding the pitfalls of its predecessors. The limitations of Bell &
LaPadula are addressed by providing a scheme whereby access can be controlled
according to the requirements of the system and its purpose rather than those
imposed by an arcane government policy. The complexity of Domain Type
Enforcement and avoided by defining access controls in terms of the access
modes already in use.
Smack Terminology
-----------------
The jargon used to talk about Smack will be familiar to those who have dealt
with other MAC systems and shouldn't be too difficult for the uninitiated to
pick up. There are four terms that are used in a specific way and that are
especially important:
Subject:
A subject is an active entity on the computer system.
On Smack a subject is a task, which is in turn the basic unit
of execution.
Object:
An object is a passive entity on the computer system.
On Smack files of all types, IPC, and tasks can be objects.
Access:
Any attempt by a subject to put information into or get
information from an object is an access.
Label:
Data that identifies the Mandatory Access Control
characteristics of a subject or an object.
These definitions are consistent with the traditional use in the security
community. There are also some terms from Linux that are likely to crop up:
Capability:
A task that possesses a capability has permission to
violate an aspect of the system security policy, as identified by
the specific capability. A task that possesses one or more
capabilities is a privileged task, whereas a task with no
capabilities is an unprivileged task.
Privilege:
A task that is allowed to violate the system security
policy is said to have privilege. As of this writing a task can
have privilege either by possessing capabilities or by having an
effective user of root.
Smack Basics
------------
Smack is an extension to a Linux system. It enforces additional restrictions
on what subjects can access which objects, based on the labels attached to
each of the subject and the object.
Labels
~~~~~~
Smack labels are ASCII character strings. They can be up to 255 characters
long, but keeping them to twenty-three characters is recommended.
Single character labels using special characters, that being anything
other than a letter or digit, are reserved for use by the Smack development
team. Smack labels are unstructured, case sensitive, and the only operation
ever performed on them is comparison for equality. Smack labels cannot
contain unprintable characters, the "/" (slash), the "\" (backslash), the "'"
(quote) and '"' (double-quote) characters.
Smack labels cannot begin with a '-'. This is reserved for special options.
There are some predefined labels::
_ Pronounced "floor", a single underscore character.
^ Pronounced "hat", a single circumflex character.
* Pronounced "star", a single asterisk character.
? Pronounced "huh", a single question mark character.
@ Pronounced "web", a single at sign character.
Every task on a Smack system is assigned a label. The Smack label
of a process will usually be assigned by the system initialization
mechanism.
Access Rules
~~~~~~~~~~~~
Smack uses the traditional access modes of Linux. These modes are read,
execute, write, and occasionally append. There are a few cases where the
access mode may not be obvious. These include:
Signals:
A signal is a write operation from the subject task to
the object task.
Internet Domain IPC:
Transmission of a packet is considered a
write operation from the source task to the destination task.
Smack restricts access based on the label attached to a subject and the label
attached to the object it is trying to access. The rules enforced are, in
order:
1. Any access requested by a task labeled "*" is denied.
2. A read or execute access requested by a task labeled "^"
is permitted.
3. A read or execute access requested on an object labeled "_"
is permitted.
4. Any access requested on an object labeled "*" is permitted.
5. Any access requested by a task on an object with the same
label is permitted.
6. Any access requested that is explicitly defined in the loaded
rule set is permitted.
7. Any other access is denied.
Smack Access Rules
~~~~~~~~~~~~~~~~~~
With the isolation provided by Smack access separation is simple. There are
many interesting cases where limited access by subjects to objects with
different labels is desired. One example is the familiar spy model of
sensitivity, where a scientist working on a highly classified project would be
able to read documents of lower classifications and anything she writes will
be "born" highly classified. To accommodate such schemes Smack includes a
mechanism for specifying rules allowing access between labels.
Access Rule Format
~~~~~~~~~~~~~~~~~~
The format of an access rule is::
subject-label object-label access
Where subject-label is the Smack label of the task, object-label is the Smack
label of the thing being accessed, and access is a string specifying the sort
of access allowed. The access specification is searched for letters that
describe access modes:
a: indicates that append access should be granted.
r: indicates that read access should be granted.
w: indicates that write access should be granted.
x: indicates that execute access should be granted.
t: indicates that the rule requests transmutation.
b: indicates that the rule should be reported for bring-up.
Uppercase values for the specification letters are allowed as well.
Access mode specifications can be in any order. Examples of acceptable rules
are::
TopSecret Secret rx
Secret Unclass R
Manager Game x
User HR w
Snap Crackle rwxatb
New Old rRrRr
Closed Off -
Examples of unacceptable rules are::
Top Secret Secret rx
Ace Ace r
Odd spells waxbeans
Spaces are not allowed in labels. Since a subject always has access to files
with the same label specifying a rule for that case is pointless. Only
valid letters (rwxatbRWXATB) and the dash ('-') character are allowed in
access specifications. The dash is a placeholder, so "a-r" is the same
as "ar". A lone dash is used to specify that no access should be allowed.
Applying Access Rules
~~~~~~~~~~~~~~~~~~~~~
The developers of Linux rarely define new sorts of things, usually importing
schemes and concepts from other systems. Most often, the other systems are
variants of Unix. Unix has many endearing properties, but consistency of
access control models is not one of them. Smack strives to treat accesses as
uniformly as is sensible while keeping with the spirit of the underlying
mechanism.
File system objects including files, directories, named pipes, symbolic links,
and devices require access permissions that closely match those used by mode
bit access. To open a file for reading read access is required on the file. To
search a directory requires execute access. Creating a file with write access
requires both read and write access on the containing directory. Deleting a
file requires read and write access to the file and to the containing
directory. It is possible that a user may be able to see that a file exists
but not any of its attributes by the circumstance of having read access to the
containing directory but not to the differently labeled file. This is an
artifact of the file name being data in the directory, not a part of the file.
If a directory is marked as transmuting (SMACK64TRANSMUTE=TRUE) and the
access rule that allows a process to create an object in that directory
includes 't' access the label assigned to the new object will be that
of the directory, not the creating process. This makes it much easier
for two processes with different labels to share data without granting
access to all of their files.
IPC objects, message queues, semaphore sets, and memory segments exist in flat
namespaces and access requests are only required to match the object in
question.
Process objects reflect tasks on the system and the Smack label used to access
them is the same Smack label that the task would use for its own access
attempts. Sending a signal via the kill() system call is a write operation
from the signaler to the recipient. Debugging a process requires both reading
and writing. Creating a new task is an internal operation that results in two
tasks with identical Smack labels and requires no access checks.
Sockets are data structures attached to processes and sending a packet from
one process to another requires that the sender have write access to the
receiver. The receiver is not required to have read access to the sender.
Setting Access Rules
~~~~~~~~~~~~~~~~~~~~
The configuration file /etc/smack/accesses contains the rules to be set at
system startup. The contents are written to the special file
/sys/fs/smackfs/load2. Rules can be added at any time and take effect
immediately. For any pair of subject and object labels there can be only
one rule, with the most recently specified overriding any earlier
specification.
Task Attribute
~~~~~~~~~~~~~~
The Smack label of a process can be read from ``/proc/<pid>/attr/current``. A
process can read its own Smack label from ``/proc/self/attr/current``. A
privileged process can change its own Smack label by writing to
``/proc/self/attr/current`` but not the label of another process.
Format of writing is : only the label or the label followed by one of the
3 trailers: ``\n`` (by common agreement for ``/proc/...`` interfaces),
``\0`` (because some applications incorrectly include it),
``\n\0`` (because we think some applications may incorrectly include it).
File Attribute
~~~~~~~~~~~~~~
The Smack label of a filesystem object is stored as an extended attribute
named SMACK64 on the file. This attribute is in the security namespace. It can
only be changed by a process with privilege.
Privilege
~~~~~~~~~
A process with CAP_MAC_OVERRIDE or CAP_MAC_ADMIN is privileged.
CAP_MAC_OVERRIDE allows the process access to objects it would
be denied otherwise. CAP_MAC_ADMIN allows a process to change
Smack data, including rules and attributes.
Smack Networking
~~~~~~~~~~~~~~~~
As mentioned before, Smack enforces access control on network protocol
transmissions. Every packet sent by a Smack process is tagged with its Smack
label. This is done by adding a CIPSO tag to the header of the IP packet. Each
packet received is expected to have a CIPSO tag that identifies the label and
if it lacks such a tag the network ambient label is assumed. Before the packet
is delivered a check is made to determine that a subject with the label on the
packet has write access to the receiving process and if that is not the case
the packet is dropped.
CIPSO Configuration
~~~~~~~~~~~~~~~~~~~
It is normally unnecessary to specify the CIPSO configuration. The default
values used by the system handle all internal cases. Smack will compose CIPSO
label values to match the Smack labels being used without administrative
intervention. Unlabeled packets that come into the system will be given the
ambient label.
Smack requires configuration in the case where packets from a system that is
not Smack that speaks CIPSO may be encountered. Usually this will be a Trusted
Solaris system, but there are other, less widely deployed systems out there.
CIPSO provides 3 important values, a Domain Of Interpretation (DOI), a level,
and a category set with each packet. The DOI is intended to identify a group
of systems that use compatible labeling schemes, and the DOI specified on the
Smack system must match that of the remote system or packets will be
discarded. The DOI is 3 by default. The value can be read from
/sys/fs/smackfs/doi and can be changed by writing to /sys/fs/smackfs/doi.
The label and category set are mapped to a Smack label as defined in
/etc/smack/cipso.
A Smack/CIPSO mapping has the form::
smack level [category [category]*]
Smack does not expect the level or category sets to be related in any
particular way and does not assume or assign accesses based on them. Some
examples of mappings::
TopSecret 7
TS:A,B 7 1 2
SecBDE 5 2 4 6
RAFTERS 7 12 26
The ":" and "," characters are permitted in a Smack label but have no special
meaning.
The mapping of Smack labels to CIPSO values is defined by writing to
/sys/fs/smackfs/cipso2.
In addition to explicit mappings Smack supports direct CIPSO mappings. One
CIPSO level is used to indicate that the category set passed in the packet is
in fact an encoding of the Smack label. The level used is 250 by default. The
value can be read from /sys/fs/smackfs/direct and changed by writing to
/sys/fs/smackfs/direct.
Socket Attributes
~~~~~~~~~~~~~~~~~
There are two attributes that are associated with sockets. These attributes
can only be set by privileged tasks, but any task can read them for their own
sockets.
SMACK64IPIN:
The Smack label of the task object. A privileged
program that will enforce policy may set this to the star label.
SMACK64IPOUT:
The Smack label transmitted with outgoing packets.
A privileged program may set this to match the label of another
task with which it hopes to communicate.
UNIX domain socket (UDS) with a BSD address functions both as a file in a
filesystem and as a socket. As a file, it carries the SMACK64 attribute. This
attribute is not involved in Smack security enforcement and is immutably
assigned the label "*".
Smack Netlabel Exceptions
~~~~~~~~~~~~~~~~~~~~~~~~~
You will often find that your labeled application has to talk to the outside,
unlabeled world. To do this there's a special file /sys/fs/smackfs/netlabel
where you can add some exceptions in the form of::
@IP1 LABEL1 or
@IP2/MASK LABEL2
It means that your application will have unlabeled access to @IP1 if it has
write access on LABEL1, and access to the subnet @IP2/MASK if it has write
access on LABEL2.
Entries in the /sys/fs/smackfs/netlabel file are matched by longest mask
first, like in classless IPv4 routing.
A special label '@' and an option '-CIPSO' can be used there::
@ means Internet, any application with any label has access to it
-CIPSO means standard CIPSO networking
If you don't know what CIPSO is and don't plan to use it, you can just do::
echo 127.0.0.1 -CIPSO > /sys/fs/smackfs/netlabel
echo 0.0.0.0/0 @ > /sys/fs/smackfs/netlabel
If you use CIPSO on your 192.168.0.0/16 local network and need also unlabeled
Internet access, you can have::
echo 127.0.0.1 -CIPSO > /sys/fs/smackfs/netlabel
echo 192.168.0.0/16 -CIPSO > /sys/fs/smackfs/netlabel
echo 0.0.0.0/0 @ > /sys/fs/smackfs/netlabel
Writing Applications for Smack
------------------------------
There are three sorts of applications that will run on a Smack system. How an
application interacts with Smack will determine what it will have to do to
work properly under Smack.
Smack Ignorant Applications
---------------------------
By far the majority of applications have no reason whatever to care about the
unique properties of Smack. Since invoking a program has no impact on the
Smack label associated with the process the only concern likely to arise is
whether the process has execute access to the program.
Smack Relevant Applications
---------------------------
Some programs can be improved by teaching them about Smack, but do not make
any security decisions themselves. The utility ls(1) is one example of such a
program.
Smack Enforcing Applications
----------------------------
These are special programs that not only know about Smack, but participate in
the enforcement of system policy. In most cases these are the programs that
set up user sessions. There are also network services that provide information
to processes running with various labels.
File System Interfaces
----------------------
Smack maintains labels on file system objects using extended attributes. The
Smack label of a file, directory, or other file system object can be obtained
using getxattr(2)::
len = getxattr("/", "security.SMACK64", value, sizeof (value));
will put the Smack label of the root directory into value. A privileged
process can set the Smack label of a file system object with setxattr(2)::
len = strlen("Rubble");
rc = setxattr("/foo", "security.SMACK64", "Rubble", len, 0);
will set the Smack label of /foo to "Rubble" if the program has appropriate
privilege.
Socket Interfaces
-----------------
The socket attributes can be read using fgetxattr(2).
A privileged process can set the Smack label of outgoing packets with
fsetxattr(2)::
len = strlen("Rubble");
rc = fsetxattr(fd, "security.SMACK64IPOUT", "Rubble", len, 0);
will set the Smack label "Rubble" on packets going out from the socket if the
program has appropriate privilege::
rc = fsetxattr(fd, "security.SMACK64IPIN, "*", strlen("*"), 0);
will set the Smack label "*" as the object label against which incoming
packets will be checked if the program has appropriate privilege.
Administration
--------------
Smack supports some mount options:
smackfsdef=label:
specifies the label to give files that lack
the Smack label extended attribute.
smackfsroot=label:
specifies the label to assign the root of the
file system if it lacks the Smack extended attribute.
smackfshat=label:
specifies a label that must have read access to
all labels set on the filesystem. Not yet enforced.
smackfsfloor=label:
specifies a label to which all labels set on the
filesystem must have read access. Not yet enforced.
smackfstransmute=label:
behaves exactly like smackfsroot except that it also
sets the transmute flag on the root of the mount
These mount options apply to all file system types.
Smack auditing
--------------
If you want Smack auditing of security events, you need to set CONFIG_AUDIT
in your kernel configuration.
By default, all denied events will be audited. You can change this behavior by
writing a single character to the /sys/fs/smackfs/logging file::
0 : no logging
1 : log denied (default)
2 : log accepted
3 : log denied & accepted
Events are logged as 'key=value' pairs, for each event you at least will get
the subject, the object, the rights requested, the action, the kernel function
that triggered the event, plus other pairs depending on the type of event
audited.
Bringup Mode
------------
Bringup mode provides logging features that can make application
configuration and system bringup easier. Configure the kernel with
CONFIG_SECURITY_SMACK_BRINGUP to enable these features. When bringup
mode is enabled accesses that succeed due to rules marked with the "b"
access mode will logged. When a new label is introduced for processes
rules can be added aggressively, marked with the "b". The logging allows
tracking of which rules actual get used for that label.
Another feature of bringup mode is the "unconfined" option. Writing
a label to /sys/fs/smackfs/unconfined makes subjects with that label
able to access any object, and objects with that label accessible to
all subjects. Any access that is granted because a label is unconfined
is logged. This feature is dangerous, as files and directories may
be created in places they couldn't if the policy were being enforced.
3. 한국어 전문 번역
영어 원문의 문단 순서와 의미를 유지한 전체 번역입니다. 코드, 함수명, symbol과 URL은 원문 표기를 유지합니다.
Smack 소개
1-18"좋아, 엘리베이터를 청소하기로 했군!" - 영화 Dark Star의 The Elevator
Smack은 Simplified Mandatory Access Control Kernel입니다. 단순성을 주요 설계 목표로 삼은 kernel 기반 mandatory access control 구현입니다.
Linux에서 사용할 수 있는 Mandatory Access Control 방식은 Smack만이 아닙니다. MAC을 처음 접한다면 당면한 문제에 가장 알맞은 방식을 고르기 위해 Smack과 다른 메커니즘을 비교하는 것이 좋습니다.
구성 요소와 배포
19-43| 구성 요소 | 역할 |
|---|---|
| Kernel | Linux Security Modules(LSM) module로 구현됩니다. |
| 기본 utility | 유용하지만 필수는 아닙니다. |
| Configuration data | 의도적으로 최소화되어 있으며 엄격한 필수 사항은 아닙니다. |
Kernel component는 netlabel이 필요하고 extended attribute를 지원하는 filesystem에서 가장 잘 동작하지만 xattr 지원이 반드시 필요한 것은 아닙니다. Smack kernel을 일반적인 distribution에서 실행해도 안전합니다.
Smack kernel은 CIPSO IP option을 사용합니다. 일부 network configuration은 IP option을 허용하지 않아 Smack처럼 이를 사용하는 시스템 접근을 방해할 수 있습니다.
Smack은 Tizen operating system에서 사용됩니다.
Userspace repository는 대부분의 현대 distribution에서 build하고 install할 수 있습니다.
smackutil command
44-64`smackutil`에는 다음 다섯 command가 포함됩니다.
| Command | 동작 | 상태 |
|---|---|---|
| chsmack | Smack extended attribute value를 표시하거나 설정합니다. | 현재 사용 |
| smackctl | Smack access rule을 load합니다. | 현재 사용 |
| smackaccess | 한 label의 process가 다른 label의 object에 접근할 수 있는지 보고합니다. | 현재 사용 |
| smackload | `smackfs/load`에 쓸 data를 올바른 형식으로 만듭니다. | `load2` 도입 후 obsolete |
| smackcipso | `smackfs/cipso`에 쓸 data를 올바른 형식으로 만듭니다. | `cipso2` 도입 후 obsolete |
smackfs mount와 xattr 권한
65-80Smack의 의도에 맞게 configuration data는 최소이며 반드시 필요하지는 않습니다. 가장 중요한 설정은 `smackfs` pseudo filesystem을 mount하는 것입니다. `smackutil`이 설치되어 있으면 startup script가 처리하지만 수동으로도 할 수 있습니다.
`/etc/fstab`에 다음 줄을 추가합니다.
smackfs /sys/fs/smackfs smackfs defaults 0 0
Kernel이 `/sys/fs/smackfs` directory를 만듭니다.
Smack은 filesystem object의 label을 extended attribute(xattr)에 저장합니다. Attribute는 extended attribute의 `security` namespace에 저장되며, 이를 변경하려면 process에 `CAP_MAC_ADMIN`이 있어야 합니다.
Smack extended attribute
81-117| Attribute | 적용 대상과 의미 |
|---|---|
| SMACK64 | Access control 결정에 사용합니다. 거의 모든 경우 새 filesystem object는 생성한 process의 label을 받습니다. |
| SMACK64EXEC | 이 attribute가 설정된 program file을 exec한 process는 attribute value를 Smack label로 사용해 실행됩니다. |
| SMACK64MMAP | 이 attribute의 label을 가진 process에 허용된 모든 접근을 허용하지 않는 Smack label의 process가 file을 mmap하지 못하게 합니다. Shared library를 위한 매우 구체적인 사용 사례입니다. |
| SMACK64TRANSMUTE | 값은 `"TRUE"`만 가능합니다. Directory에 이 attribute가 있고 write를 허용한 rule에 transmute mode `t`가 있으면 새 object는 생성 process가 아니라 directory label을 받습니다. 새 object가 directory이면 이 attribute도 설정됩니다. |
| SMACK64IPIN | Socket file descriptor에서만 사용할 수 있으며 이 socket으로 전달되는 packet의 access control에 해당 Smack label을 사용합니다. |
| SMACK64IPOUT | Socket file descriptor에서만 사용할 수 있으며 이 socket에서 나가는 packet의 access control에 해당 Smack label을 사용합니다. |
File과 process label 설정
118-130File에 Smack label을 설정하는 방법은 여러 가지입니다.
# attr -S -s SMACK64 -V "value" path
# chsmack -a value path
Process는 `/proc/self/attr/current`를 읽어 현재 실행 label을 확인할 수 있습니다. `CAP_MAC_ADMIN`이 있는 process는 여기에 써서 process Smack label을 설정할 수 있습니다.
대부분의 Smack configuration은 `/sys/fs/smackfs`에 mount한 smackfs filesystem의 file에 써서 수행합니다.
access, access2, ambient, change-rule
131-166| Interface | 동작 |
|---|---|
| access | Backward compatibility용입니다. Fixed format access rule을 쓰고 다음 read에서 허용이면 `1`, 거부이면 `0`을 반환합니다. `access2` 사용을 권장합니다. |
| access2 | Subject label이 object label에 특정 접근을 할 수 있는지 검사합니다. Long format rule을 쓰고 다음 read에서 허용이면 `1`, 거부이면 `0`을 반환합니다. |
| ambient | Label이 없는 network packet에 적용할 Smack label을 담습니다. |
| change-rule | 기존 access control rule을 수정합니다. Subject, object, 허용할 access, 거부할 access 순서로 씁니다. |
"%s %s %s %s"
`change-rule`의 첫 string은 subject label, 둘째는 object label, 셋째는 허용할 access, 넷째는 거부할 access입니다. Access string에는 `rwxat-`만 쓸 수 있습니다.
Subject/object rule이 이미 있으면 세 번째 string의 permission을 켜고 네 번째 string의 permission을 끕니다. Rule이 없으면 두 string이 지정한 access로 새 rule을 만듭니다.
cipso, cipso2, direct, doi
167-200`cipso`는 backward compatibility용이며 `cipso2`를 권장합니다. 특정 CIPSO header를 Smack label에 할당합니다. `cipso`의 write 형식은 다음과 같습니다.
"%24s%4d%4d"["%4d"]...
첫 string은 fixed Smack label, 첫 number는 level, 둘째 number는 category 수이며 이어지는 number가 category입니다.
"level-3-cats-5-19 3 2 5 19"
`cipso2`는 long Smack label을 받아 같은 정보를 지정합니다.
"%s%4d%4d"["%4d"]...
"level-3-cats-5-19 3 2 5 19"
`direct`는 network packet에서 Smack direct label 표현에 쓰는 CIPSO level을 담고, `doi`는 network packet에 쓰는 CIPSO domain of interpretation을 담습니다.
ipv6host
201-213`ipv6host`는 특정 IPv6 internet address를 single-label host로 취급합니다. Host label에 Smack write access가 있는 process만 packet을 보낼 수 있고, single-label host에서 받은 모든 packet에는 지정 label이 붙습니다.
"%h:%h:%h:%h:%h:%h:%h:%h label" or
"%h:%h:%h:%h:%h:%h:%h:%h/%d label".
`::` address 단축 표기는 지원하지 않습니다. Label이 `-DELETE`이면 일치하는 entry를 삭제합니다.
load와 load2
214-244`load`는 backward compatibility용이며 `load2`를 권장합니다. System-defined rule 외의 access control rule을 지정할 수 있습니다.
"%24s%24s%5s"
첫 string은 subject label, 둘째는 object label, 셋째는 요청 access입니다. Access string은 `rwxat-`만 포함하며 허용할 access를 지정합니다. `-`는 허용하지 않는 permission의 자리 표시자이므로 `r-x--`는 read와 execute를 뜻합니다. `load` label 길이는 23자로 제한됩니다.
`load2`는 long label을 지원하며 write 형식은 다음과 같습니다.
"%s %s %s"
`load2`도 subject label, object label, 요청 access 순서이며 `rwxat-`와 같은 permission 의미를 사용하지만 23자 label 제한 설명은 적용되지 않습니다.
load-self, load-self2, logging, mapped
245-267| Interface | 동작 |
|---|---|
| load-self | Process-specific access rule을 정의합니다. 다른 검사에서 허용될 때만 추가 제한으로 적용되며 `load` 형식을 사용합니다. Backward compatibility용입니다. |
| load-self2 | Process-specific access rule을 정의하며 `load2` 형식을 사용합니다. |
| logging | 현재 Smack logging state를 담습니다. |
| mapped | Network packet의 Smack mapped label 표현에 쓰는 CIPSO level을 담습니다. |
netlabel과 onlycap
268-287`netlabel`은 특정 internet address를 single-label host로 취급합니다. Packet은 CIPSO header 없이 전송되지만 host label에 Smack write access가 있는 process만 보낼 수 있습니다. 받은 모든 packet에는 지정 label이 붙습니다.
"%d.%d.%d.%d label" or "%d.%d.%d.%d/%d label".
Label이 `-CIPSO`이면 해당 address를 CIPSO header를 지원하는 host로 취급합니다.
`onlycap`은 `CAP_MAC_ADMIN`과 `CAP_MAC_OVERRIDE`가 유효하려면 process가 가져야 하는 label 목록을 담습니다. File이 비어 있으면 모든 label의 process에 capability가 유효합니다. Space로 구분한 label을 쓰고 `-`를 쓰면 비웁니다.
ptrace, revoke와 relabel
288-327| ptrace 값 | Policy |
|---|---|
| 0 - default | Smack access rule에 의존합니다. `PTRACE_READ`는 object에 read, `PTRACE_ATTACH`는 read-write access가 필요합니다. |
| 1 - exact | `PTRACE_ATTACH`는 subject와 object label이 같을 때만 허용됩니다. `PTRACE_READ`는 영향이 없고 `CAP_SYS_PTRACE`로 우회할 수 있습니다. |
| 2 - draconian | `exact`와 같지만 `CAP_SYS_PTRACE`로도 우회할 수 없습니다. |
`revoke-subject`에 Smack label을 쓰면 해당 subject label을 가진 모든 access rule의 access를 `-`로 설정합니다.
`CONFIG_SECURITY_SMACK_BRINGUP` kernel에서 `CAP_MAC_ADMIN` process가 `unconfined`에 label을 쓰면 그 label 관련 접근을 기록하고 원래 거부될 접근도 허용합니다. Labeling을 망가뜨릴 수 있어 위험하므로 production에서는 절대 사용하지 마십시오.
`relabel-self`는 process가 `/proc/self/attr/current`에 써서 전환할 수 있는 label 목록을 담습니다. 일반적으로 자체 label 변경에는 `CAP_MAC_ADMIN`이 필요하지만, 이 interface는 capability 없는 process도 사전 정의 목록 중 하나로 한 번만 바꾸게 합니다. 변경하면 목록이 비워집니다. Space로 구분한 label을 쓰고 `-`를 쓰면 비웁니다.
smackload 설정과 백서
328-344`smackload` utility를 사용하면 `/etc/smack/accesses`에 다음 형식으로 rule을 추가할 수 있습니다.
subjectlabel objectlabel access
`access`는 subject label이 object label에 할 수 있는 접근을 나타내는 `rwxatb` 조합입니다. Rule이 없으면 접근은 허용되지 않습니다.
이후 내용은 Casey Schaufler의 백서 'The Simplified Mandatory Access Control Kernel'입니다.
Mandatory Access Control
345-357Computer system은 machine을 사용하는 사람과 service 사이에서 정보를 공유하는 방식을 제한하기 위해 다양한 체계를 사용합니다. Program이나 user가 다른 program 또는 user의 data 접근 여부를 결정하는 체계를 discretionary access control이라 합니다. 접근 제어가 user의 재량에 따라 지정되기 때문입니다.
반대로 user나 program이 무엇에 접근할지를 스스로 결정하지 못하게 하는 체계를 mandatory access control이라 합니다. Data에 접근하는 user나 program을 선택할 수 없기 때문입니다.
Bell & LaPadula
358-3671980년대 중반부터 세기가 바뀔 때까지 Mandatory Access Control(MAC)은 종이 문서 표시를 위한 미국 국방부 policy의 수학적 설명인 Bell & LaPadula security model과 밀접하게 연관되었습니다.
이 형태의 MAC은 Washington Capital Beltway와 Scandinavia supercomputer center에서 지지를 받았지만 일반적 요구를 다루지 못한다는 지적을 자주 받았습니다.
Domain Type Enforcement
368-378세기가 바뀔 무렵 Domain Type Enforcement(DTE)가 널리 쓰이기 시작했습니다. User, program, data를 서로 보호되는 domain으로 구성하며 인기 Linux distribution의 component로 폭넓게 배포되었습니다.
하지만 scheme 유지에 필요한 관리 부담과 안전한 domain mapping에 필요한 전체 시스템의 세밀한 이해 때문에 대부분의 경우 비활성화되거나 제한적으로만 사용됩니다.
Smack의 목적
379-389Smack은 이전 방식의 함정을 피하면서 유용한 MAC을 제공하도록 설계되었습니다. Bell & LaPadula의 난해한 정부 policy가 아니라 시스템과 목적의 요구에 따라 접근을 제어하여 그 한계를 해결합니다.
또한 이미 사용 중인 access mode로 access control을 정의하여 Domain Type Enforcement의 복잡성을 피합니다.
Smack 용어
390-430Smack에서 특히 중요한 네 용어는 다음과 같습니다.
| 용어 | 정의 |
|---|---|
| Subject | Computer system의 active entity입니다. Smack에서는 execution의 기본 단위인 task입니다. |
| Object | Computer system의 passive entity입니다. 모든 종류의 file, IPC와 task가 object가 될 수 있습니다. |
| Access | Subject가 object에 정보를 넣거나 object에서 정보를 얻으려는 모든 시도입니다. |
| Label | Subject 또는 object의 Mandatory Access Control 특성을 식별하는 data입니다. |
Linux에서 함께 쓰이는 용어는 다음과 같습니다.
| 용어 | 정의 |
|---|---|
| Capability | 특정 capability가 식별하는 system security policy의 한 측면을 위반할 권한입니다. 하나 이상 가진 task는 privileged, 하나도 없으면 unprivileged task입니다. |
| Privilege | System security policy를 위반하도록 허용된 상태입니다. 이 문서 작성 시점에는 capability를 가지거나 effective user가 root이면 privilege가 있습니다. |
Label 형식
431-450Smack은 subject와 object에 붙은 label을 기준으로 어떤 subject가 어떤 object에 접근할 수 있는지 추가 제한을 강제하는 Linux extension입니다.
Smack label은 최대 255자의 ASCII string이지만 23자 이하를 권장합니다. Letter나 digit이 아닌 특수 문자 하나로 된 label은 Smack 개발팀 용도로 예약되어 있습니다.
Label은 구조가 없고 case-sensitive이며 equality 비교만 수행합니다. Unprintable character, `/`, `\`, single quote와 double quote를 포함할 수 없고 `-`로 시작할 수 없습니다. `-`는 special option용입니다.
사전 정의 label
451-462사전 정의된 label은 다음과 같습니다.
| Label | 호칭 |
|---|---|
| _ | floor |
| ^ | hat |
| * | star |
| ? | huh |
| @ | web |
Smack system의 모든 task에는 label이 할당됩니다. Process의 Smack label은 보통 system initialization mechanism이 할당합니다.
기본 access rule
463-493Smack은 Linux의 전통적인 read, execute, write 및 때때로 append access mode를 사용합니다. Signal은 subject task에서 object task로 가는 write operation이며, Internet domain IPC의 packet transmission은 source task에서 destination task로 가는 write operation입니다.
Subject와 object label에 따라 다음 rule을 순서대로 강제합니다.
| 순서 | Rule |
|---|---|
| 1 | Label `*`인 task가 요청한 모든 access를 거부합니다. |
| 2 | Label `^`인 task의 read 또는 execute access를 허용합니다. |
| 3 | Label `_`인 object의 read 또는 execute access를 허용합니다. |
| 4 | Label `*`인 object에 대한 모든 access를 허용합니다. |
| 5 | Task와 object의 label이 같으면 모든 access를 허용합니다. |
| 6 | Load된 rule set에 명시적으로 정의된 access를 허용합니다. |
| 7 | 그 밖의 모든 access를 거부합니다. |
Label 사이의 access
494-504Smack의 isolation으로 access 분리는 단순하지만 서로 다른 label의 subject와 object 사이에 제한된 access가 필요한 경우도 많습니다.
예를 들어 민감도에 따른 spy model에서 극비 project의 scientist는 더 낮은 classification 문서를 읽을 수 있지만 작성한 모든 문서는 극비로 태어납니다. Smack은 이런 체계를 위해 label 사이의 access 허용 rule을 지정할 수 있습니다.
Access rule 형식
505-547Access rule 형식은 다음과 같습니다.
subject-label object-label access
`subject-label`은 task의 Smack label, `object-label`은 접근 대상의 Smack label, `access`는 허용할 access 종류를 지정하는 string입니다.
| 문자 | 의미 |
|---|---|
| a | append access를 허용합니다. |
| r | read access를 허용합니다. |
| w | write access를 허용합니다. |
| x | execute access를 허용합니다. |
| t | Rule이 transmutation을 요청합니다. |
| b | Rule을 bring-up 대상으로 보고합니다. |
대문자도 허용되며 access mode의 순서는 자유롭습니다. 허용되는 rule 예입니다.
TopSecret Secret rx
Secret Unclass R
Manager Game x
User HR w
Snap Crackle rwxatb
New Old rRrRr
Closed Off -
허용되지 않는 rule 예입니다.
Top Secret Secret rx
Ace Ace r
Odd spells waxbeans
Label에는 space를 쓸 수 없습니다. Subject는 같은 label의 file에 항상 접근할 수 있으므로 그 경우의 rule은 의미가 없습니다. Access에는 `rwxatbRWXATB`와 dash만 허용됩니다. Dash는 자리 표시자이므로 `a-r`은 `ar`과 같고, dash 하나는 어떤 access도 허용하지 않음을 뜻합니다.
Filesystem object access
548-568Smack은 기반 메커니즘의 취지를 지키면서 합리적인 범위에서 access를 일관되게 다루려 합니다.
File, directory, named pipe, symbolic link와 device 같은 filesystem object에는 mode bit access와 밀접한 permission이 필요합니다. File read open에는 file read access, directory search에는 execute access가 필요합니다.
Write access로 file을 만들려면 containing directory에 read와 write가 모두 필요합니다. File 삭제에는 file과 containing directory 모두에 read와 write가 필요합니다.
Containing directory에는 read access가 있지만 다른 label의 file에는 access가 없으면 file의 존재는 보되 attribute는 보지 못할 수 있습니다. File name이 file 일부가 아니라 directory의 data이기 때문입니다.
Transmute, IPC, process와 socket
569-590Directory가 `SMACK64TRANSMUTE=TRUE`이고 process가 object를 만들도록 허용한 rule에 `t` access가 있으면 새 object는 생성 process가 아니라 directory label을 받습니다. 서로 다른 label의 두 process가 모든 file access를 공유하지 않고 data를 공유하기 쉬워집니다.
IPC object, message queue, semaphore set와 memory segment는 flat namespace에 있으므로 access 요청은 해당 object와만 일치하면 됩니다.
Process object의 접근 label은 task가 자체 접근 시도에 쓰는 Smack label과 같습니다. `kill()` signal은 signaler에서 recipient로 가는 write operation이며 debugging에는 read와 write가 모두 필요합니다. 새 task 생성은 같은 label의 두 task를 만드는 내부 operation이라 access check가 필요 없습니다.
Socket은 process에 붙은 data structure입니다. 한 process에서 다른 process로 packet을 보내려면 sender가 receiver에 write access를 가져야 하지만 receiver가 sender에 read access를 가질 필요는 없습니다.
Access rule 설정
591-600System startup 시 설정할 rule은 `/etc/smack/accesses`에 둡니다. 내용은 special file `/sys/fs/smackfs/load2`에 씁니다.
Rule은 언제든 추가할 수 있고 즉시 적용됩니다. Subject/object label pair마다 rule은 하나뿐이며 가장 최근 specification이 앞선 것을 덮어씁니다.
Task attribute
601-613Process의 Smack label은 `/proc/<pid>/attr/current`에서 읽고 자체 label은 `/proc/self/attr/current`에서 읽습니다. Privileged process는 자체 label을 쓸 수 있지만 다른 process label은 바꿀 수 없습니다.
Write 형식은 label만 쓰거나 label 뒤에 `\n`, `\0`, `\n\0` 중 하나를 붙이는 것입니다. 첫 형식은 `/proc/...` interface의 일반 관례이고, 나머지는 이를 잘못 포함하는 application과 호환하기 위한 것입니다.
File attribute와 privilege
614-628Filesystem object의 Smack label은 file의 `security` namespace에 있는 `SMACK64` extended attribute로 저장되며 privileged process만 바꿀 수 있습니다.
`CAP_MAC_OVERRIDE` 또는 `CAP_MAC_ADMIN`이 있는 process는 privileged입니다. `CAP_MAC_OVERRIDE`는 원래 거부될 object 접근을 허용하고, `CAP_MAC_ADMIN`은 rule과 attribute를 포함한 Smack data 변경을 허용합니다.
Smack networking
629-640Smack은 network protocol transmission에도 access control을 강제합니다. Smack process가 보내는 모든 packet은 IP header에 CIPSO tag를 추가하여 Smack label을 표시합니다.
수신 packet에는 label을 식별하는 CIPSO tag가 있을 것으로 기대하며 없으면 network ambient label을 사용합니다. 전달 전에 packet label의 subject가 receiving process에 write access가 있는지 검사하고 없으면 packet을 drop합니다.
CIPSO configuration과 DOI
641-662보통 CIPSO configuration을 지정할 필요는 없습니다. 기본값이 모든 내부 case를 처리하고 Smack은 관리자 개입 없이 사용 중인 label에 맞는 CIPSO label value를 구성합니다. 들어오는 unlabeled packet에는 ambient label을 붙입니다.
Smack이 아닌 CIPSO system, 보통 Trusted Solaris와 통신할 때는 configuration이 필요합니다. CIPSO는 packet마다 DOI(Domain Of Interpretation), level, category set 세 중요 값을 제공합니다.
DOI는 호환 label scheme을 쓰는 system group을 식별하며 remote system과 일치하지 않으면 packet을 버립니다. 기본 DOI는 3이고 `/sys/fs/smackfs/doi`에서 읽거나 같은 file에 써서 바꿉니다.
Label과 category set은 `/etc/smack/cipso` 정의에 따라 Smack label로 mapping됩니다.
Smack/CIPSO mapping
663-687Mapping 형식은 다음과 같습니다.
smack level [category [category]*]
Smack은 level과 category set 사이에 특별한 관계를 기대하지 않고 이 값에 근거해 access를 가정하거나 할당하지 않습니다. Mapping 예입니다.
TopSecret 7
TS:A,B 7 1 2
SecBDE 5 2 4 6
RAFTERS 7 12 26
Smack label에서 `:`와 `,`는 허용되지만 특별한 의미는 없습니다.
Smack label과 CIPSO value mapping은 `/sys/fs/smackfs/cipso2`에 써서 정의합니다.
명시적 mapping 외에 direct CIPSO mapping도 지원합니다. 한 CIPSO level은 packet category set이 실제로 Smack label encoding임을 나타냅니다. 기본 level은 250이고 `/sys/fs/smackfs/direct`에서 읽거나 써서 바꿉니다.
Socket attribute와 UDS
688-708Socket에는 두 attribute가 있습니다. Privileged task만 설정할 수 있지만 모든 task가 자체 socket의 값을 읽을 수 있습니다.
| Attribute | 의미 |
|---|---|
| SMACK64IPIN | Task object의 Smack label입니다. Policy를 강제하는 privileged program은 이를 star label로 설정할 수 있습니다. |
| SMACK64IPOUT | Outgoing packet에 전송할 Smack label입니다. Privileged program은 통신하려는 다른 task label과 맞게 설정할 수 있습니다. |
BSD address를 가진 UNIX domain socket(UDS)은 filesystem의 file이자 socket입니다. File로서는 `SMACK64` attribute를 가지지만 Smack security enforcement에는 쓰이지 않고 변경할 수 없는 label `*`가 할당됩니다.
Netlabel exception
709-742Label이 있는 application이 외부의 unlabeled world와 통신해야 할 때 `/sys/fs/smackfs/netlabel`에 다음 형식의 exception을 추가할 수 있습니다.
@IP1 LABEL1 or
@IP2/MASK LABEL2
Application이 `LABEL1`에 write access가 있으면 `@IP1`에 unlabeled access를, `LABEL2`에 write access가 있으면 `@IP2/MASK` subnet에 access를 갖습니다. Entry는 classless IPv4 routing처럼 가장 긴 mask부터 일치시킵니다.
Special label `@`와 option `-CIPSO`의 의미는 다음과 같습니다.
@ means Internet, any application with any label has access to it
-CIPSO means standard CIPSO networking
CIPSO를 모르고 사용할 계획도 없다면 다음처럼 설정할 수 있습니다.
echo 127.0.0.1 -CIPSO > /sys/fs/smackfs/netlabel
echo 0.0.0.0/0 @ > /sys/fs/smackfs/netlabel
192.168.0.0/16 local network에는 CIPSO를 쓰고 Internet에는 unlabeled access가 필요하면 다음과 같이 설정합니다.
echo 127.0.0.1 -CIPSO > /sys/fs/smackfs/netlabel
echo 192.168.0.0/16 -CIPSO > /sys/fs/smackfs/netlabel
echo 0.0.0.0/0 @ > /sys/fs/smackfs/netlabel
Smack application 유형
743-772Smack system에서 실행되는 application은 Smack과 상호작용하는 방식에 따라 세 종류로 나뉩니다.
| 유형 | 설명 |
|---|---|
| Smack ignorant application | 대부분의 application입니다. Program 호출은 process Smack label에 영향을 주지 않으므로 보통 program execute access만 신경 쓰면 됩니다. |
| Smack relevant application | Smack을 알면 개선되지만 자체 security 결정은 하지 않습니다. `ls(1)`가 예입니다. |
| Smack enforcing application | Smack을 알고 system policy 강제에 참여합니다. 주로 user session을 설정하거나 여러 label의 process에 정보를 제공하는 network service입니다. |
Filesystem API
773-790Smack은 extended attribute로 filesystem object label을 유지합니다. `getxattr(2)`로 file, directory와 다른 filesystem object의 label을 얻을 수 있습니다.
len = getxattr("/", "security.SMACK64", value, sizeof (value));
이 호출은 root directory의 Smack label을 `value`에 넣습니다.
Privileged process는 `setxattr(2)`로 filesystem object label을 설정할 수 있습니다.
len = strlen("Rubble");
rc = setxattr("/foo", "security.SMACK64", "Rubble", len, 0);
Program에 적절한 privilege가 있으면 `/foo`의 Smack label을 `Rubble`로 설정합니다.
Socket API
791-809Socket attribute는 `fgetxattr(2)`로 읽을 수 있습니다.
Privileged process는 `fsetxattr(2)`로 outgoing packet label을 설정할 수 있습니다.
len = strlen("Rubble");
rc = fsetxattr(fd, "security.SMACK64IPOUT", "Rubble", len, 0);
적절한 privilege가 있으면 socket에서 나가는 packet에 label `Rubble`을 설정합니다.
rc = fsetxattr(fd, "security.SMACK64IPIN, "*", strlen("*"), 0);
적절한 privilege가 있으면 incoming packet을 검사할 object label로 Smack label `*`를 설정합니다.
Filesystem mount option
810-836Smack은 모든 filesystem type에 적용되는 다음 mount option을 지원합니다.
| Option | 동작 |
|---|---|
| smackfsdef=label | Smack label extended attribute가 없는 file에 줄 label을 지정합니다. |
| smackfsroot=label | Smack extended attribute가 없는 filesystem root에 할당할 label을 지정합니다. |
| smackfshat=label | Filesystem에 설정된 모든 label에 read access를 가져야 하는 label을 지정합니다. 아직 강제되지 않습니다. |
| smackfsfloor=label | Filesystem에 설정된 모든 label이 read access를 가져야 하는 label을 지정합니다. 아직 강제되지 않습니다. |
| smackfstransmute=label | `smackfsroot`처럼 동작하면서 mount root에 transmute flag도 설정합니다. |
Smack auditing
837-854Smack security event auditing을 사용하려면 kernel configuration에 `CONFIG_AUDIT`을 설정해야 합니다. 기본적으로 모든 denied event를 audit합니다.
`/sys/fs/smackfs/logging`에 한 문자를 써서 동작을 바꿀 수 있습니다.
| 값 | Logging 동작 |
|---|---|
| 0 | Logging 없음 |
| 1 | Denied event 기록(기본값) |
| 2 | Accepted event 기록 |
| 3 | Denied와 accepted event 모두 기록 |
Event는 `key=value` pair로 기록됩니다. 최소한 subject, object, 요청한 right, action, event를 일으킨 kernel function이 포함되며 audit event type에 따라 다른 pair가 추가됩니다.
Bringup mode
855-871Bringup mode는 application configuration과 system bringup을 쉽게 하는 logging 기능을 제공합니다. `CONFIG_SECURITY_SMACK_BRINGUP`으로 kernel을 설정해 활성화합니다.
활성화하면 access mode `b`로 표시한 rule 덕분에 성공한 접근도 기록됩니다. Process에 새 label을 도입할 때 rule을 공격적으로 추가하고 `b`로 표시한 뒤 실제로 어떤 rule이 쓰이는지 log로 추적할 수 있습니다.
또 다른 기능은 `unconfined` option입니다. `/sys/fs/smackfs/unconfined`에 label을 쓰면 그 label의 subject가 모든 object에 접근하고, 그 label의 object에는 모든 subject가 접근할 수 있습니다. 이 때문에 허용된 모든 access가 기록됩니다.
Policy가 강제되었다면 만들 수 없었을 위치에 file과 directory가 생성될 수 있으므로 위험한 기능입니다.
구성과 smackfs
Smack.rst:1-130Smack 구성 요소, utility, mount와 extended attribute를 설명합니다.