* [PATCH] selinux: treat genfscon lookup failure as non-fatal for booleans
@ 2026-09-08 14:43 Stephen Smalley
2026-09-08 15:00 ` sashiko-bot
2026-09-08 15:30 ` Stephen Smalley
0 siblings, 2 replies; 3+ messages in thread
From: Stephen Smalley @ 2026-09-08 14:43 UTC (permalink / raw)
To: selinux; +Cc: paul, omosnacek, russell, Stephen Smalley
selinuxfs.c:sel_make_bools() labels the inodes representing policy
booleans based on genfscon rules in the policy. If there is no
matching entry, we fall back to assigning the well-defined security
initial SID but propagate the error back to the callers. This ends up
producing a fatal error during policy load, which can halt the system
on first policy load if enforcing. We do not treat similar genfscon
lookup failures as fatal elsewhere in SELinux, so follow the same
approach here.
Link: https://lore.kernel.org/selinux/RvCmRlQYQ3uewSzEeY0utQ@coker.com.au/
Signed-off-by: Stephen Smalley <stephen.smalley.work@gmail.com>
---
security/selinux/selinuxfs.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/security/selinux/selinuxfs.c b/security/selinux/selinuxfs.c
index 292302eb60f3..7ff2ba6623b9 100644
--- a/security/selinux/selinuxfs.c
+++ b/security/selinux/selinuxfs.c
@@ -1277,6 +1277,7 @@ static int sel_make_bools(struct selinux_policy *newpolicy, struct dentry *bool_
pr_warn_ratelimited("SELinux: no sid found, defaulting to security isid for %s\n",
page);
sid = SECINITSID_SECURITY;
+ ret = 0;
}
isec->sid = sid;
--
2.55.0
^ permalink raw reply related [flat|nested] 3+ messages in thread
* Re: [PATCH] selinux: treat genfscon lookup failure as non-fatal for booleans
2026-09-08 14:43 [PATCH] selinux: treat genfscon lookup failure as non-fatal for booleans Stephen Smalley
@ 2026-09-08 15:00 ` sashiko-bot
2026-09-08 15:30 ` Stephen Smalley
1 sibling, 0 replies; 3+ messages in thread
From: sashiko-bot @ 2026-09-08 15:00 UTC (permalink / raw)
Cc: selinux
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [Medium] The patch adds `ret = 0;` to prevent an error code from propagating, but it is a dead store because `ret` is unconditionally overwritten immediately afterward.
--
commit 56d806498916952baebbc4306bdac863b09cae9c
Author: Stephen Smalley <stephen.smalley.work@gmail.com>
selinux: treat genfscon lookup failure as non-fatal for booleans
This commit aims to make genfscon lookup failures non-fatal when labeling
inodes for policy booleans. It resets the error code from
selinux_policy_genfs_sid() to zero to prevent the error from propagating.
Link: https://lore.kernel.org/selinux/RvCmRlQYQ3uewSzEeY0utQ@coker.com.au/
> diff --git a/security/selinux/selinuxfs.c b/security/selinux/selinuxfs.c
> index 5aaaf69410bb0..fb1d11e8fd371 100644
> --- a/security/selinux/selinuxfs.c
> +++ b/security/selinux/selinuxfs.c
> @@ -1278,6 +1278,7 @@ static int sel_make_bools(struct selinux_policy *newpolicy, struct dentry *bool_
> pr_warn_ratelimited("SELinux: no sid found, defaulting to security isid for %s\n",
> page);
> sid = SECINITSID_SECURITY;
> + ret = 0;
[Severity: Medium]
Is this assignment a dead store?
Looking at sel_make_bools(), ret is unconditionally overwritten just a few
lines later by the result of sel_attach_file():
isec->sid = sid;
isec->initialized = LABEL_INITIALIZED;
inode->i_fop = &sel_bool_ops;
inode->i_ino = i|SEL_BOOL_INO_OFFSET;
ret = sel_attach_file(bool_dir, names[i], inode);
Because ret is overwritten regardless of the prior error state, the added
assignment doesn't appear to change the functional behavior of the code.
The error code from selinux_policy_genfs_sid() was already being discarded
by the sel_attach_file() assignment before the loop condition could evaluate
it.
Does sel_attach_file() need to be skipped if selinux_policy_genfs_sid()
initially failed, or is there another way the error was intended to be
handled here?
> }
>
> isec->sid = sid;
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260908144341.17206-1-stephen.smalley.work@gmail.com?part=1
^ permalink raw reply [flat|nested] 3+ messages in thread
* Re: [PATCH] selinux: treat genfscon lookup failure as non-fatal for booleans
2026-09-08 14:43 [PATCH] selinux: treat genfscon lookup failure as non-fatal for booleans Stephen Smalley
2026-09-08 15:00 ` sashiko-bot
@ 2026-09-08 15:30 ` Stephen Smalley
1 sibling, 0 replies; 3+ messages in thread
From: Stephen Smalley @ 2026-09-08 15:30 UTC (permalink / raw)
To: selinux; +Cc: paul, omosnacek, russell
On Tue, Sep 8, 2026 at 10:43 AM Stephen Smalley
<stephen.smalley.work@gmail.com> wrote:
>
> selinuxfs.c:sel_make_bools() labels the inodes representing policy
> booleans based on genfscon rules in the policy. If there is no
> matching entry, we fall back to assigning the well-defined security
> initial SID but propagate the error back to the callers. This ends up
> producing a fatal error during policy load, which can halt the system
> on first policy load if enforcing. We do not treat similar genfscon
> lookup failures as fatal elsewhere in SELinux, so follow the same
> approach here.
>
> Link: https://lore.kernel.org/selinux/RvCmRlQYQ3uewSzEeY0utQ@coker.com.au/
> Signed-off-by: Stephen Smalley <stephen.smalley.work@gmail.com>
> ---
> security/selinux/selinuxfs.c | 1 +
> 1 file changed, 1 insertion(+)
>
> diff --git a/security/selinux/selinuxfs.c b/security/selinux/selinuxfs.c
> index 292302eb60f3..7ff2ba6623b9 100644
> --- a/security/selinux/selinuxfs.c
> +++ b/security/selinux/selinuxfs.c
> @@ -1277,6 +1277,7 @@ static int sel_make_bools(struct selinux_policy *newpolicy, struct dentry *bool_
> pr_warn_ratelimited("SELinux: no sid found, defaulting to security isid for %s\n",
> page);
> sid = SECINITSID_SECURITY;
> + ret = 0;
sashiko correctly pointed out that this is a dead store because ret is
overwritten with the return value from sel_attach_file() a few lines
later, so this patch has no effect. Sorry for the noise. Not sure then
why the policy load is failing on that policy.
^ permalink raw reply [flat|nested] 3+ messages in thread
end of thread, other threads:[~2026-09-08 15:30 UTC | newest]
Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-08 14:43 [PATCH] selinux: treat genfscon lookup failure as non-fatal for booleans Stephen Smalley
2026-09-08 15:00 ` sashiko-bot
2026-09-08 15:30 ` Stephen Smalley
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.