All of lore.kernel.org
 help / color / mirror / Atom feed
From: Petr Lautrbach <lautrbach@redhat.com>
To: James Carter <jwcart2@gmail.com>, selinux@vger.kernel.org
Cc: dburgener@linux.microsoft.com, James Carter <jwcart2@gmail.com>
Subject: Re: [PATCH 0/9 v4] Add CIL Deny Rule
Date: Tue, 15 Aug 2023 17:09:27 +0200	[thread overview]
Message-ID: <87zg2se40o.fsf@redhat.com> (raw)
In-Reply-To: <20230809210157.112275-1-jwcart2@gmail.com>

James Carter <jwcart2@gmail.com> writes:

> This patch series depends on the "Add support for notself and other to
> CIL" patch series from August 9th
>
> These patches add a deny rule to CIL. Deny rules will be processed after
> everything except for neverallow rules. Unlike neverallow rules, they
> remove the permissions in the deny rule rather than reporting an error.
>
> See the individual patches for an explanation of what they do.
>
> Patches 1-8 are unchanged from v3, see:
> https://lore.kernel.org/selinux/20230413193445.588395-1-jwcart2@gmail.com/
>
> Previously, patch 9, as Daniel Burgener noted, did not do what it said it
> was going to do. Now it does.

I've pushed all 16 into
https://github.com/bachradsusi/SELinuxProject-selinux/commits/notself-other-deny
and I'm building it in my COPR repo -
https://copr.fedorainfracloud.org/coprs/plautrba/selinux-patchwork/builds/

I've already run some tests and it looks good.

For all 16 patches - together with notself and other serie:

Acked-by: Petr Lautrbach <lautrbach@redhat.com>

Thanks!



> James Carter (9):
>   libsepol/cil: Parse and add deny rule to AST, but do not process
>   libsepol/cil: Add cil_list_is_empty macro
>   libsepol/cil: Add cil_tree_node_remove function
>   libsepol/cil: Process deny rules
>   libsepol/cil: Add cil_write_post_ast function
>   libsepol: Export the cil_write_post_ast function
>   secilc/secil2tree: Add option to write CIL AST after post processing
>   secilc/test: Add deny rule tests
>   secilc/docs: Add deny rule to CIL documentation
>
>  libsepol/cil/include/cil/cil.h         |    1 +
>  libsepol/cil/src/cil.c                 |   68 ++
>  libsepol/cil/src/cil_build_ast.c       |   56 +
>  libsepol/cil/src/cil_build_ast.h       |    2 +
>  libsepol/cil/src/cil_copy_ast.c        |   19 +
>  libsepol/cil/src/cil_copy_ast.h        |    1 +
>  libsepol/cil/src/cil_deny.c            | 1413 ++++++++++++++++++++++++
>  libsepol/cil/src/cil_deny.h            |   36 +
>  libsepol/cil/src/cil_flavor.h          |    1 +
>  libsepol/cil/src/cil_internal.h        |   10 +
>  libsepol/cil/src/cil_list.h            |    3 +
>  libsepol/cil/src/cil_post.c            |    7 +
>  libsepol/cil/src/cil_reset_ast.c       |    8 +
>  libsepol/cil/src/cil_resolve_ast.c     |   48 +
>  libsepol/cil/src/cil_resolve_ast.h     |    1 +
>  libsepol/cil/src/cil_tree.c            |   35 +
>  libsepol/cil/src/cil_tree.h            |    1 +
>  libsepol/cil/src/cil_verify.c          |    9 +
>  libsepol/cil/src/cil_write_ast.c       |   10 +
>  libsepol/cil/src/cil_write_ast.h       |    1 +
>  libsepol/src/libsepol.map.in           |    5 +
>  secilc/docs/cil_access_vector_rules.md |   41 +-
>  secilc/secil2tree.c                    |    8 +-
>  secilc/test/deny_rule_test1.cil        |  580 ++++++++++
>  secilc/test/deny_rule_test2.cil        |  418 +++++++
>  25 files changed, 2780 insertions(+), 2 deletions(-)
>  create mode 100644 libsepol/cil/src/cil_deny.c
>  create mode 100644 libsepol/cil/src/cil_deny.h
>  create mode 100644 secilc/test/deny_rule_test1.cil
>  create mode 100644 secilc/test/deny_rule_test2.cil
>
> -- 
> 2.41.0


  parent reply	other threads:[~2023-08-15 15:10 UTC|newest]

Thread overview: 18+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2023-08-09 21:01 [PATCH 0/9 v4] Add CIL Deny Rule James Carter
2023-08-09 21:01 ` [PATCH 1/9 v4] libsepol/cil: Parse and add deny rule to AST, but do not process James Carter
2023-08-09 21:01 ` [PATCH 2/9 v4] libsepol/cil: Add cil_list_is_empty macro James Carter
2023-08-09 21:01 ` [PATCH 3/9 v4] libsepol/cil: Add cil_tree_node_remove function James Carter
2023-08-09 21:01 ` [PATCH 4/9 v4] libsepol/cil: Process deny rules James Carter
2023-08-16 17:47   ` James Carter
2023-08-09 21:01 ` [PATCH 5/9 v4] libsepol/cil: Add cil_write_post_ast function James Carter
2023-08-09 21:01 ` [PATCH 6/9 v4] libsepol: Export the " James Carter
2023-08-09 21:01 ` [PATCH 7/9 v4] secilc/secil2tree: Add option to write CIL AST after post processing James Carter
2023-08-09 21:01 ` [PATCH 8/9 v4] secilc/test: Add deny rule tests James Carter
2023-08-09 21:01 ` [PATCH 9/9 v4] secilc/docs: Add deny rule to CIL documentation James Carter
2023-08-10 15:05   ` Daniel Burgener
2023-08-15 15:09 ` Petr Lautrbach [this message]
2023-08-16 17:44   ` [PATCH 0/9 v4] Add CIL Deny Rule James Carter
2023-08-16 17:53     ` Christian Göttsche
2023-08-16 18:05       ` James Carter
2023-08-16 18:08         ` James Carter
2023-08-16 18:26           ` Christian Göttsche

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=87zg2se40o.fsf@redhat.com \
    --to=lautrbach@redhat.com \
    --cc=dburgener@linux.microsoft.com \
    --cc=jwcart2@gmail.com \
    --cc=selinux@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.