All of lore.kernel.org
 help / color / mirror / Atom feed
From: James Carter <jwcart2@gmail.com>
To: selinux@vger.kernel.org
Cc: stephen.smalley.work@gmail.com, James Carter <jwcart2@gmail.com>
Subject: [PATCH 1/2] libsepol/tests: Remove non-MLS downgrade test
Date: Mon, 31 Aug 2026 14:58:50 -0400	[thread overview]
Message-ID: <20260831185851.80078-1-jwcart2@gmail.com> (raw)

The non-MLS downgrade tests are done by reading in an MLS policy
and then just setting the "mls" field to 0. This results in a policy
that could never be created by checkpolicy or secilc. Changing the
mls field does not change the fact that the policy has sensitivities,
categories, levels, and mls constraint expressions. This has limited
the checks that can be done during policy validation.

Remove the downgrade test for the non-mls policy (that is really an
mls policy) and just do it for the mls policy.

Signed-off-by: James Carter <jwcart2@gmail.com>
---
 libsepol/tests/test-downgrade.c | 26 ++++++++------------------
 libsepol/tests/test-downgrade.h |  9 +++------
 2 files changed, 11 insertions(+), 24 deletions(-)

diff --git a/libsepol/tests/test-downgrade.c b/libsepol/tests/test-downgrade.c
index 5f879b39..82af6f39 100644
--- a/libsepol/tests/test-downgrade.c
+++ b/libsepol/tests/test-downgrade.c
@@ -97,15 +97,11 @@ int downgrade_add_tests(CU_pSuite suite)
  * Output: None
  *
  * Description:
- * Tests the backward compatibility of MLS and Non-MLS binary policy versions.
+ * Tests the backward compatibility of MLS binary policy versions.
  */
 void test_downgrade(void)
 {
-	if (do_downgrade_test(0) < 0)
-		fprintf(stderr,
-			"\nError during downgrade testing of Non-MLS policy\n");
-
-	if (do_downgrade_test(1) < 0)
+	if (do_downgrade_test() < 0)
 		fprintf(stderr,
 			"\nError during downgrade testing of MLS policy\n");
 }
@@ -113,8 +109,6 @@ void test_downgrade(void)
 /*
  * Function Name:  do_downgrade_test
  *
- * Input: 0 for Non-MLS policy and 1 for MLS policy downgrade testing
- *
  * Output: 0 on success, negative number upon failure
  *
  * Description: This function handles the downgrade testing.
@@ -123,7 +117,7 @@ void test_downgrade(void)
  *              back out and then read back in again.  The process is
  *              repeated until the minimum policy version is reached.
  */
-int do_downgrade_test(int mls)
+int do_downgrade_test(void)
 {
 	policydb_t policydb_tmp;
 	int hi, lo, version;
@@ -134,15 +128,11 @@ int do_downgrade_test(int mls)
 
 	/* Read in the hi policy from file */
 	if (read_binary_policy(POLICY_BIN_HI, &policydb) != 0) {
-		fprintf(stderr, "error reading %spolicy binary\n",
-			mls ? "mls " : "");
+		fprintf(stderr, "error reading policy binary\n");
 		CU_FAIL("Unable to read the binary policy");
 		return -1;
 	}
 
-	/* Change MLS value based on parameter */
-	policydb.mls = mls ? 1 : 0;
-
 	for (hi = policydb.policyvers; hi >= POLICYDB_VERSION_MIN; hi--) {
 		/* Stash old version number */
 		version = policydb.policyvers;
@@ -156,8 +146,8 @@ int do_downgrade_test(int mls)
 			if (write_binary_policy(POLICY_BIN_LO, &policydb) !=
 			    0) {
 				fprintf(stderr,
-					"error writing %spolicy binary, version %d (downgraded from %d)\n",
-					mls ? "mls " : "", lo, hi);
+					"error writing policy binary, version %d (downgraded from %d)\n",
+					lo, hi);
 				CU_FAIL("Failed to write downgraded binary policy");
 				return -1;
 			}
@@ -171,8 +161,8 @@ int do_downgrade_test(int mls)
 			if (read_binary_policy(POLICY_BIN_LO, &policydb_tmp) !=
 			    0) {
 				fprintf(stderr,
-					"error reading %spolicy binary, version %d (downgraded from %d)\n",
-					mls ? "mls " : "", lo, hi);
+					"error reading policy binary, version %d (downgraded from %d)\n",
+					lo, hi);
 				CU_FAIL("Unable to read downgraded binary policy");
 				return -1;
 			}
diff --git a/libsepol/tests/test-downgrade.h b/libsepol/tests/test-downgrade.h
index 4105defa..ea51c7d9 100644
--- a/libsepol/tests/test-downgrade.h
+++ b/libsepol/tests/test-downgrade.h
@@ -65,17 +65,14 @@ int downgrade_add_tests(CU_pSuite suite);
  * 
  * Output: None
  * 
- * Description: Tests the backward compatibility of MLS and Non-MLS binary
- *		policy versions. 
+ * Description: Tests the backward compatibility of MLS binary policy
+ * versions. 
  */
 void test_downgrade(void);
 
 /*
  * Function Name:  do_downgrade_test
  * 
- * Input: int that represents a 0 for Non-MLS policy and a 
- * 		 1 for MLS policy downgrade testing
- * 
  * Output: (int) 0 on success, negative number upon failure
  * 
  * Description: This function handles the downgrade testing.  A binary policy
@@ -84,7 +81,7 @@ void test_downgrade(void);
  *		back in again. The process is iterative until the minimum
  *		policy version is reached. 
  */
-int do_downgrade_test(int mls);
+int do_downgrade_test(void);
 
 /*
  * Function Name: read_binary_policy
-- 
2.55.0


             reply	other threads:[~2026-08-31 18:59 UTC|newest]

Thread overview: 6+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-08-31 18:58 James Carter [this message]
2026-08-31 18:58 ` [PATCH 2/2] libsepol: Check for mls components in non-mls policy during validation James Carter
2026-09-01 12:26   ` Stephen Smalley
2026-09-01 14:18     ` Stephen Smalley
2026-09-01 12:26 ` [PATCH 1/2] libsepol/tests: Remove non-MLS downgrade test Stephen Smalley
2026-09-01 14:17   ` Stephen Smalley

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260831185851.80078-1-jwcart2@gmail.com \
    --to=jwcart2@gmail.com \
    --cc=selinux@vger.kernel.org \
    --cc=stephen.smalley.work@gmail.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.