All of lore.kernel.org
 help / color / mirror / Atom feed
* [PATCH 1/2] libsepol: Move the PERMISSION_MASK macro to private.h
@ 2026-08-25 19:41 James Carter
  2026-08-25 19:41 ` [PATCH 2/2] libsepol: Remove junk permissions before optimzing the policy James Carter
  2026-08-25 20:13 ` [PATCH 1/2] libsepol: Move the PERMISSION_MASK macro to private.h Stephen Smalley
  0 siblings, 2 replies; 5+ messages in thread
From: James Carter @ 2026-08-25 19:41 UTC (permalink / raw)
  To: selinux; +Cc: stephen.smalley.work, James Carter

Move the PERMISSION_MASK macro from policydb_validate.c to
private.h so that it can be used in other places.

Signed-off-by: James Carter <jwcart2@gmail.com>
---
 libsepol/src/policydb_validate.c | 3 ---
 libsepol/src/private.h           | 4 ++++
 2 files changed, 4 insertions(+), 3 deletions(-)

diff --git a/libsepol/src/policydb_validate.c b/libsepol/src/policydb_validate.c
index 7d9ae3fd..99d27f88 100644
--- a/libsepol/src/policydb_validate.c
+++ b/libsepol/src/policydb_validate.c
@@ -18,9 +18,6 @@
  * Check that at least one permission bit is valid.
  * Older compilers might set invalid bits for the wildcard permission.
  */
-#define PERMISSION_MASK(nprim)                          \
-	((nprim) == PERM_SYMTAB_SIZE ? (~UINT32_C(0)) : \
-				       ((UINT32_C(1) << (nprim)) - 1))
 #define NO_VALID_PERMS(av, nprim) (!((av) & PERMISSION_MASK(nprim)))
 
 typedef struct validate {
diff --git a/libsepol/src/private.h b/libsepol/src/private.h
index 6fc5fa2d..7f7344a8 100644
--- a/libsepol/src/private.h
+++ b/libsepol/src/private.h
@@ -45,6 +45,10 @@
 
 #define MAX_ALIAS_REPEATS 32
 
+#define PERMISSION_MASK(nprim)                          \
+	((nprim) == PERM_SYMTAB_SIZE ? (~UINT32_C(0)) : \
+				       ((UINT32_C(1) << (nprim)) - 1))
+
 static inline int exceeds_available_bytes(const struct policy_file *fp,
 					  size_t x, size_t req_elem_size)
 {
-- 
2.55.0


^ permalink raw reply related	[flat|nested] 5+ messages in thread

* [PATCH 2/2] libsepol: Remove junk permissions before optimzing the policy
  2026-08-25 19:41 [PATCH 1/2] libsepol: Move the PERMISSION_MASK macro to private.h James Carter
@ 2026-08-25 19:41 ` James Carter
  2026-08-25 20:14   ` Stephen Smalley
  2026-08-25 20:13 ` [PATCH 1/2] libsepol: Move the PERMISSION_MASK macro to private.h Stephen Smalley
  1 sibling, 1 reply; 5+ messages in thread
From: James Carter @ 2026-08-25 19:41 UTC (permalink / raw)
  To: selinux; +Cc: stephen.smalley.work, James Carter

In older policy compilers, a wildcard or complement would cause
all the bits higher than those corresponding to the class's declared
permissions to be set. These junk bits must be removed before
optimization is done to avoid a situation where the only bits left
for an access vector are one or more of these junk bits. If a policy
does not have at least one actual permission bit set, it will fail
validation.

Signed-off-by: James Carter <jwcart2@gmail.com>
---
 libsepol/src/optimize.c | 29 +++++++++++++++++++++++++++++
 1 file changed, 29 insertions(+)

diff --git a/libsepol/src/optimize.c b/libsepol/src/optimize.c
index eeffee7d..1efd3832 100644
--- a/libsepol/src/optimize.c
+++ b/libsepol/src/optimize.c
@@ -446,6 +446,32 @@ static void optimize_cond_avtab(policydb_t *p, const struct type_vec *type_map)
 	}
 }
 
+/*
+ * Older policy compilers could set bits higher than any of the permissions
+ * in the class. These junk bits must be removed before optimization to keep
+ * redundant rules from being kept because of junk bits and to prevent the
+ * failure of policy validation because no actual permission bit is set. 
+ */
+static int remove_junk_permissions(avtab_key_t *k, avtab_datum_t *d, void *args)
+{
+	const policydb_t *p = args;
+	const class_datum_t *tclass;
+	uint32_t mask;
+
+	if (!(k->specified & AVTAB_AV))
+		return 0;
+
+	tclass = p->class_val_to_struct[k->target_class - 1];
+	mask = PERMISSION_MASK(tclass->permissions.nprim);
+
+	if ((k->specified & ~AVTAB_ENABLED) == AVTAB_AUDITDENY)
+		d->data |= ~mask;
+	else
+		d->data &= mask;
+
+	return 0;
+}
+
 int policydb_optimize(policydb_t *p)
 {
 	struct type_vec *type_map;
@@ -453,6 +479,9 @@ int policydb_optimize(policydb_t *p)
 	if (p->policy_type != POLICY_KERN)
 		return -1;
 
+	avtab_map(&p->te_avtab, remove_junk_permissions, p);
+	avtab_map(&p->te_cond_avtab, remove_junk_permissions, p);
+
 	type_map = build_type_map(p);
 	if (!type_map)
 		return -1;
-- 
2.55.0


^ permalink raw reply related	[flat|nested] 5+ messages in thread

* Re: [PATCH 1/2] libsepol: Move the PERMISSION_MASK macro to private.h
  2026-08-25 19:41 [PATCH 1/2] libsepol: Move the PERMISSION_MASK macro to private.h James Carter
  2026-08-25 19:41 ` [PATCH 2/2] libsepol: Remove junk permissions before optimzing the policy James Carter
@ 2026-08-25 20:13 ` Stephen Smalley
  2026-08-26 12:25   ` Stephen Smalley
  1 sibling, 1 reply; 5+ messages in thread
From: Stephen Smalley @ 2026-08-25 20:13 UTC (permalink / raw)
  To: James Carter; +Cc: selinux

On Tue, Aug 25, 2026 at 3:41 PM James Carter <jwcart2@gmail.com> wrote:
>
> Move the PERMISSION_MASK macro from policydb_validate.c to
> private.h so that it can be used in other places.
>
> Signed-off-by: James Carter <jwcart2@gmail.com>

Acked-by: Stephen Smalley <stephen.smalley.work@gmail.com>

^ permalink raw reply	[flat|nested] 5+ messages in thread

* Re: [PATCH 2/2] libsepol: Remove junk permissions before optimzing the policy
  2026-08-25 19:41 ` [PATCH 2/2] libsepol: Remove junk permissions before optimzing the policy James Carter
@ 2026-08-25 20:14   ` Stephen Smalley
  0 siblings, 0 replies; 5+ messages in thread
From: Stephen Smalley @ 2026-08-25 20:14 UTC (permalink / raw)
  To: James Carter; +Cc: selinux

On Tue, Aug 25, 2026 at 3:41 PM James Carter <jwcart2@gmail.com> wrote:
>
> In older policy compilers, a wildcard or complement would cause
> all the bits higher than those corresponding to the class's declared
> permissions to be set. These junk bits must be removed before
> optimization is done to avoid a situation where the only bits left
> for an access vector are one or more of these junk bits. If a policy
> does not have at least one actual permission bit set, it will fail
> validation.
>
> Signed-off-by: James Carter <jwcart2@gmail.com>

Acked-by: Stephen Smalley <stephen.smalley.work@gmail.com>

^ permalink raw reply	[flat|nested] 5+ messages in thread

* Re: [PATCH 1/2] libsepol: Move the PERMISSION_MASK macro to private.h
  2026-08-25 20:13 ` [PATCH 1/2] libsepol: Move the PERMISSION_MASK macro to private.h Stephen Smalley
@ 2026-08-26 12:25   ` Stephen Smalley
  0 siblings, 0 replies; 5+ messages in thread
From: Stephen Smalley @ 2026-08-26 12:25 UTC (permalink / raw)
  To: James Carter; +Cc: selinux

On Tue, Aug 25, 2026 at 4:13 PM Stephen Smalley
<stephen.smalley.work@gmail.com> wrote:
>
> On Tue, Aug 25, 2026 at 3:41 PM James Carter <jwcart2@gmail.com> wrote:
> >
> > Move the PERMISSION_MASK macro from policydb_validate.c to
> > private.h so that it can be used in other places.
> >
> > Signed-off-by: James Carter <jwcart2@gmail.com>
>
> Acked-by: Stephen Smalley <stephen.smalley.work@gmail.com>

Both merged.

^ permalink raw reply	[flat|nested] 5+ messages in thread

end of thread, other threads:[~2026-08-26 12:25 UTC | newest]

Thread overview: 5+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-08-25 19:41 [PATCH 1/2] libsepol: Move the PERMISSION_MASK macro to private.h James Carter
2026-08-25 19:41 ` [PATCH 2/2] libsepol: Remove junk permissions before optimzing the policy James Carter
2026-08-25 20:14   ` Stephen Smalley
2026-08-25 20:13 ` [PATCH 1/2] libsepol: Move the PERMISSION_MASK macro to private.h Stephen Smalley
2026-08-26 12:25   ` Stephen Smalley

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.