Skip to content

Commit 1177a32

Browse files
vmojziszpytela
authored andcommitted
Add default contexts for sshd-seesion
In openssh-9.9 (Fedora 41), the sshd server has been split into a listener binary, sshd(8), and a per-session binary, "sshd-session". sshd-session runs in a new domain sshd_session_t, which is now used to transition into an appropriate login context. Signed-off-by: Vit Mojzis <[email protected]>
1 parent efa131d commit 1177a32

23 files changed

+23
-0
lines changed

config/appconfig-mcs/default_contexts

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -2,6 +2,7 @@ system_r:crond_t:s0 user_r:user_t:s0 staff_r:staff_t:s0 sysadm_r:sysadm_t:s0 un
22
system_r:local_login_t:s0 user_r:user_t:s0 staff_r:staff_t:s0 sysadm_r:sysadm_t:s0 unconfined_r:unconfined_t:s0
33
system_r:remote_login_t:s0 user_r:user_t:s0 staff_r:staff_t:s0 unconfined_r:unconfined_t:s0
44
system_r:sshd_t:s0 user_r:user_t:s0 staff_r:staff_t:s0 sysadm_r:sysadm_t:s0 unconfined_r:unconfined_t:s0
5+
system_r:sshd_session_t:s0 user_r:user_t:s0 staff_r:staff_t:s0 sysadm_r:sysadm_t:s0 unconfined_r:unconfined_t:s0
56
system_r:sulogin_t:s0 sysadm_r:sysadm_t:s0
67
system_r:xdm_t:s0 user_r:user_t:s0 staff_r:staff_t:s0 sysadm_r:sysadm_t:s0 unconfined_r:unconfined_t:s0
78

config/appconfig-mcs/guest_u_default_contexts

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -4,5 +4,6 @@ system_r:initrc_su_t:s0 guest_r:guest_t:s0
44
system_r:local_login_t:s0 guest_r:guest_t:s0
55
system_r:remote_login_t:s0 guest_r:guest_t:s0
66
system_r:sshd_t:s0 guest_r:guest_t:s0
7+
system_r:sshd_session_t:s0 guest_r:guest_t:s0
78
system_r:cockpit_session_t:s0 guest_r:guest_t:s0
89
system_r:init_t:s0 guest_r:guest_t:s0

config/appconfig-mcs/root_default_contexts

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -9,3 +9,4 @@ user_r:user_su_t:s0 unconfined_r:unconfined_t:s0 sysadm_r:sysadm_t:s0 staff_r:s
99
# Uncomment if you want to automatically login as sysadm_r
1010
#
1111
#system_r:sshd_t:s0 unconfined_r:unconfined_t:s0 sysadm_r:sysadm_t:s0 staff_r:staff_t:s0 user_r:user_t:s0
12+
#system_r:sshd_session_t:s0 unconfined_r:unconfined_t:s0 sysadm_r:sysadm_t:s0 staff_r:staff_t:s0 user_r:user_t:s0

config/appconfig-mcs/staff_u_default_contexts

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,7 @@
11
system_r:local_login_t:s0 staff_r:staff_t:s0 sysadm_r:sysadm_t:s0
22
system_r:remote_login_t:s0 staff_r:staff_t:s0
33
system_r:sshd_t:s0 staff_r:staff_t:s0 sysadm_r:sysadm_t:s0
4+
system_r:sshd_session_t:s0 staff_r:staff_t:s0 sysadm_r:sysadm_t:s0
45
system_r:cockpit_session_t:s0 staff_r:staff_t:s0 sysadm_r:sysadm_t:s0
56
system_r:crond_t:s0 staff_r:staff_t:s0 staff_r:cronjob_t:s0
67
system_r:xdm_t:s0 staff_r:staff_t:s0

config/appconfig-mcs/sysadm_u_default_contexts

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,7 @@
11
system_r:local_login_t:s0 sysadm_r:sysadm_t:s0
22
system_r:remote_login_t:s0 sysadm_r:sysadm_t:s0
33
system_r:sshd_t:s0 sysadm_r:sysadm_t:s0
4+
system_r:sshd_session_t:s0 sysadm_r:sysadm_t:s0
45
system_r:cockpit_session_t:s0 sysadm_r:sysadm_t:s0
56
system_r:crond_t:s0 sysadm_r:sysadm_t:s0
67
system_r:xdm_t:s0 sysadm_r:sysadm_t:s0

config/appconfig-mcs/unconfined_u_default_contexts

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -4,6 +4,7 @@ system_r:local_login_t:s0 unconfined_r:unconfined_t:s0
44
system_r:remote_login_t:s0 unconfined_r:unconfined_t:s0
55
system_r:rshd_t:s0 unconfined_r:unconfined_t:s0
66
system_r:sshd_t:s0 unconfined_r:unconfined_t:s0
7+
system_r:sshd_session_t:s0 unconfined_r:unconfined_t:s0
78
system_r:cockpit_session_t:s0 unconfined_r:unconfined_t:s0
89
system_r:sysadm_su_t:s0 unconfined_r:unconfined_t:s0
910
system_r:unconfined_t:s0 unconfined_r:unconfined_t:s0

config/appconfig-mcs/user_u_default_contexts

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -2,6 +2,7 @@ system_r:init_t:s0 user_r:user_t:s0
22
system_r:local_login_t:s0 user_r:user_t:s0
33
system_r:remote_login_t:s0 user_r:user_t:s0
44
system_r:sshd_t:s0 user_r:user_t:s0
5+
system_r:sshd_session_t:s0 user_r:user_t:s0
56
system_r:cockpit_session_t:s0 user_r:user_t:s0
67
system_r:crond_t:s0 user_r:user_t:s0 user_r:cronjob_t:s0
78
system_r:xdm_t:s0 user_r:user_t:s0

config/appconfig-mcs/xguest_u_default_contexts

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -3,6 +3,7 @@ system_r:initrc_su_t:s0 xguest_r:xguest_t:s0
33
system_r:local_login_t:s0 xguest_r:xguest_t:s0
44
system_r:remote_login_t:s0 xguest_r:xguest_t:s0
55
system_r:sshd_t:s0 xguest_r:xguest_t:s0
6+
system_r:sshd_session_t:s0 xguest_r:xguest_t:s0
67
system_r:cockpit_session_t:s0 xguest_r:xguest_t:s0
78
system_r:xdm_t:s0 xguest_r:xguest_t:s0
89
system_r:init_t:s0 xguest_r:xguest_t:s0

config/appconfig-mls/default_contexts

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -2,6 +2,7 @@ system_r:crond_t:s0 user_r:user_t:s0 staff_r:staff_t:s0 sysadm_r:sysadm_t:s0 un
22
system_r:local_login_t:s0 user_r:user_t:s0 staff_r:staff_t:s0 sysadm_r:sysadm_t:s0 unconfined_r:unconfined_t:s0
33
system_r:remote_login_t:s0 user_r:user_t:s0 staff_r:staff_t:s0 unconfined_r:unconfined_t:s0
44
system_r:sshd_t:s0 user_r:user_t:s0 staff_r:staff_t:s0 sysadm_r:sysadm_t:s0 unconfined_r:unconfined_t:s0
5+
system_r:sshd_session_t:s0 user_r:user_t:s0 staff_r:staff_t:s0 sysadm_r:sysadm_t:s0 unconfined_r:unconfined_t:s0
56
system_r:sulogin_t:s0 sysadm_r:sysadm_t:s0
67
system_r:xdm_t:s0 user_r:user_t:s0 staff_r:staff_t:s0 sysadm_r:sysadm_t:s0 unconfined_r:unconfined_t:s0
78

config/appconfig-mls/guest_u_default_contexts

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -3,5 +3,6 @@ system_r:crond_t:s0 guest_r:guest_t:s0
33
system_r:local_login_t:s0 guest_r:guest_t:s0
44
system_r:remote_login_t:s0 guest_r:guest_t:s0
55
system_r:sshd_t:s0 guest_r:guest_t:s0
6+
system_r:sshd_session_t:s0 guest_r:guest_t:s0
67
system_r:cockpit_session_t:s0 guest_r:guest_t:s0
78
system_r:init_t:s0 guest_r:guest_t:s0

0 commit comments

Comments
 (0)