All of lore.kernel.org
 help / color / mirror / Atom feed
* [PATCH 1/2] libsepol/tests: Remove non-MLS downgrade test
@ 2026-08-31 18:58 James Carter
  2026-08-31 18:58 ` [PATCH 2/2] libsepol: Check for mls components in non-mls policy during validation James Carter
  2026-09-01 12:26 ` [PATCH 1/2] libsepol/tests: Remove non-MLS downgrade test Stephen Smalley
  0 siblings, 2 replies; 6+ messages in thread
From: James Carter @ 2026-08-31 18:58 UTC (permalink / raw)
  To: selinux; +Cc: stephen.smalley.work, James Carter

The non-MLS downgrade tests are done by reading in an MLS policy
and then just setting the "mls" field to 0. This results in a policy
that could never be created by checkpolicy or secilc. Changing the
mls field does not change the fact that the policy has sensitivities,
categories, levels, and mls constraint expressions. This has limited
the checks that can be done during policy validation.

Remove the downgrade test for the non-mls policy (that is really an
mls policy) and just do it for the mls policy.

Signed-off-by: James Carter <jwcart2@gmail.com>
---
 libsepol/tests/test-downgrade.c | 26 ++++++++------------------
 libsepol/tests/test-downgrade.h |  9 +++------
 2 files changed, 11 insertions(+), 24 deletions(-)

diff --git a/libsepol/tests/test-downgrade.c b/libsepol/tests/test-downgrade.c
index 5f879b39..82af6f39 100644
--- a/libsepol/tests/test-downgrade.c
+++ b/libsepol/tests/test-downgrade.c
@@ -97,15 +97,11 @@ int downgrade_add_tests(CU_pSuite suite)
  * Output: None
  *
  * Description:
- * Tests the backward compatibility of MLS and Non-MLS binary policy versions.
+ * Tests the backward compatibility of MLS binary policy versions.
  */
 void test_downgrade(void)
 {
-	if (do_downgrade_test(0) < 0)
-		fprintf(stderr,
-			"\nError during downgrade testing of Non-MLS policy\n");
-
-	if (do_downgrade_test(1) < 0)
+	if (do_downgrade_test() < 0)
 		fprintf(stderr,
 			"\nError during downgrade testing of MLS policy\n");
 }
@@ -113,8 +109,6 @@ void test_downgrade(void)
 /*
  * Function Name:  do_downgrade_test
  *
- * Input: 0 for Non-MLS policy and 1 for MLS policy downgrade testing
- *
  * Output: 0 on success, negative number upon failure
  *
  * Description: This function handles the downgrade testing.
@@ -123,7 +117,7 @@ void test_downgrade(void)
  *              back out and then read back in again.  The process is
  *              repeated until the minimum policy version is reached.
  */
-int do_downgrade_test(int mls)
+int do_downgrade_test(void)
 {
 	policydb_t policydb_tmp;
 	int hi, lo, version;
@@ -134,15 +128,11 @@ int do_downgrade_test(int mls)
 
 	/* Read in the hi policy from file */
 	if (read_binary_policy(POLICY_BIN_HI, &policydb) != 0) {
-		fprintf(stderr, "error reading %spolicy binary\n",
-			mls ? "mls " : "");
+		fprintf(stderr, "error reading policy binary\n");
 		CU_FAIL("Unable to read the binary policy");
 		return -1;
 	}
 
-	/* Change MLS value based on parameter */
-	policydb.mls = mls ? 1 : 0;
-
 	for (hi = policydb.policyvers; hi >= POLICYDB_VERSION_MIN; hi--) {
 		/* Stash old version number */
 		version = policydb.policyvers;
@@ -156,8 +146,8 @@ int do_downgrade_test(int mls)
 			if (write_binary_policy(POLICY_BIN_LO, &policydb) !=
 			    0) {
 				fprintf(stderr,
-					"error writing %spolicy binary, version %d (downgraded from %d)\n",
-					mls ? "mls " : "", lo, hi);
+					"error writing policy binary, version %d (downgraded from %d)\n",
+					lo, hi);
 				CU_FAIL("Failed to write downgraded binary policy");
 				return -1;
 			}
@@ -171,8 +161,8 @@ int do_downgrade_test(int mls)
 			if (read_binary_policy(POLICY_BIN_LO, &policydb_tmp) !=
 			    0) {
 				fprintf(stderr,
-					"error reading %spolicy binary, version %d (downgraded from %d)\n",
-					mls ? "mls " : "", lo, hi);
+					"error reading policy binary, version %d (downgraded from %d)\n",
+					lo, hi);
 				CU_FAIL("Unable to read downgraded binary policy");
 				return -1;
 			}
diff --git a/libsepol/tests/test-downgrade.h b/libsepol/tests/test-downgrade.h
index 4105defa..ea51c7d9 100644
--- a/libsepol/tests/test-downgrade.h
+++ b/libsepol/tests/test-downgrade.h
@@ -65,17 +65,14 @@ int downgrade_add_tests(CU_pSuite suite);
  * 
  * Output: None
  * 
- * Description: Tests the backward compatibility of MLS and Non-MLS binary
- *		policy versions. 
+ * Description: Tests the backward compatibility of MLS binary policy
+ * versions. 
  */
 void test_downgrade(void);
 
 /*
  * Function Name:  do_downgrade_test
  * 
- * Input: int that represents a 0 for Non-MLS policy and a 
- * 		 1 for MLS policy downgrade testing
- * 
  * Output: (int) 0 on success, negative number upon failure
  * 
  * Description: This function handles the downgrade testing.  A binary policy
@@ -84,7 +81,7 @@ void test_downgrade(void);
  *		back in again. The process is iterative until the minimum
  *		policy version is reached. 
  */
-int do_downgrade_test(int mls);
+int do_downgrade_test(void);
 
 /*
  * Function Name: read_binary_policy
-- 
2.55.0


^ permalink raw reply related	[flat|nested] 6+ messages in thread

end of thread, other threads:[~2026-09-01 14:18 UTC | newest]

Thread overview: 6+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-08-31 18:58 [PATCH 1/2] libsepol/tests: Remove non-MLS downgrade test James Carter
2026-08-31 18:58 ` [PATCH 2/2] libsepol: Check for mls components in non-mls policy during validation James Carter
2026-09-01 12:26   ` Stephen Smalley
2026-09-01 14:18     ` Stephen Smalley
2026-09-01 12:26 ` [PATCH 1/2] libsepol/tests: Remove non-MLS downgrade test Stephen Smalley
2026-09-01 14:17   ` Stephen Smalley

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.