All of lore.kernel.org
 help / color / mirror / Atom feed
* [PATCH] selinux: treat genfscon lookup failure as non-fatal for booleans
@ 2026-09-08 14:43 Stephen Smalley
  2026-09-08 15:00 ` sashiko-bot
  2026-09-08 15:30 ` Stephen Smalley
  0 siblings, 2 replies; 3+ messages in thread
From: Stephen Smalley @ 2026-09-08 14:43 UTC (permalink / raw)
  To: selinux; +Cc: paul, omosnacek, russell, Stephen Smalley

selinuxfs.c:sel_make_bools() labels the inodes representing policy
booleans based on genfscon rules in the policy. If there is no
matching entry, we fall back to assigning the well-defined security
initial SID but propagate the error back to the callers. This ends up
producing a fatal error during policy load, which can halt the system
on first policy load if enforcing. We do not treat similar genfscon
lookup failures as fatal elsewhere in SELinux, so follow the same
approach here.

Link: https://lore.kernel.org/selinux/RvCmRlQYQ3uewSzEeY0utQ@coker.com.au/
Signed-off-by: Stephen Smalley <stephen.smalley.work@gmail.com>
---
 security/selinux/selinuxfs.c | 1 +
 1 file changed, 1 insertion(+)

diff --git a/security/selinux/selinuxfs.c b/security/selinux/selinuxfs.c
index 292302eb60f3..7ff2ba6623b9 100644
--- a/security/selinux/selinuxfs.c
+++ b/security/selinux/selinuxfs.c
@@ -1277,6 +1277,7 @@ static int sel_make_bools(struct selinux_policy *newpolicy, struct dentry *bool_
 			pr_warn_ratelimited("SELinux: no sid found, defaulting to security isid for %s\n",
 					   page);
 			sid = SECINITSID_SECURITY;
+			ret = 0;
 		}
 
 		isec->sid = sid;
-- 
2.55.0


^ permalink raw reply related	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2026-09-08 15:30 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-08 14:43 [PATCH] selinux: treat genfscon lookup failure as non-fatal for booleans Stephen Smalley
2026-09-08 15:00 ` sashiko-bot
2026-09-08 15:30 ` Stephen Smalley

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.