* [PATCH v3] selinux_restorecon: Do not exit on directory cycles
@ 2026-07-27 12:47 Johannes Segitz
2026-07-27 13:35 ` Stephen Smalley
0 siblings, 1 reply; 3+ messages in thread
From: Johannes Segitz @ 2026-07-27 12:47 UTC (permalink / raw)
To: selinux; +Cc: Johannes Segitz
All other failures are handled gracefully. Directory cycles can e.g.
happen on BTRFS filesystems with subvolumes. Skip them and continue
instead of exiting
Signed-off-by: Johannes Segitz <jsegitz@suse.de>
---
libselinux/src/selinux_restorecon.c | 11 +++++------
1 file changed, 5 insertions(+), 6 deletions(-)
diff --git a/libselinux/src/selinux_restorecon.c b/libselinux/src/selinux_restorecon.c
index 30f1b836..fdefc92c 100644
--- a/libselinux/src/selinux_restorecon.c
+++ b/libselinux/src/selinux_restorecon.c
@@ -1393,15 +1393,14 @@ static void *selinux_restorecon_thread(void *arg)
if (is_dir) {
if (descend && walk_is_cycle(state, ent_sb.st_dev,
ent_sb.st_ino)) {
- selinux_log(SELINUX_ERROR,
+ selinux_log(SELINUX_WARNING,
"Directory cycle on %s.\n",
ent_path);
close(ent_fd);
- close(rd_fd);
- errno = ELOOP;
- state->error = -1;
- state->abort = true;
- goto finish;
+ if (rd_fd >= 0)
+ close(rd_fd);
+ prune_pathbuf(state);
+ continue;
}
if (state->sfsb.f_type == SYSFS_MAGIC &&
--
2.55.0
^ permalink raw reply related [flat|nested] 3+ messages in thread
* Re: [PATCH v3] selinux_restorecon: Do not exit on directory cycles
2026-07-27 12:47 [PATCH v3] selinux_restorecon: Do not exit on directory cycles Johannes Segitz
@ 2026-07-27 13:35 ` Stephen Smalley
2026-07-28 6:57 ` Johannes Segitz
0 siblings, 1 reply; 3+ messages in thread
From: Stephen Smalley @ 2026-07-27 13:35 UTC (permalink / raw)
To: Johannes Segitz; +Cc: selinux
On Mon, Jul 27, 2026 at 8:53 AM Johannes Segitz <jsegitz@suse.de> wrote:
>
> All other failures are handled gracefully. Directory cycles can e.g.
> happen on BTRFS filesystems with subvolumes. Skip them and continue
> instead of exiting
>
> Signed-off-by: Johannes Segitz <jsegitz@suse.de>
> ---
> libselinux/src/selinux_restorecon.c | 11 +++++------
> 1 file changed, 5 insertions(+), 6 deletions(-)
>
> diff --git a/libselinux/src/selinux_restorecon.c b/libselinux/src/selinux_restorecon.c
> index 30f1b836..fdefc92c 100644
> --- a/libselinux/src/selinux_restorecon.c
> +++ b/libselinux/src/selinux_restorecon.c
> @@ -1393,15 +1393,14 @@ static void *selinux_restorecon_thread(void *arg)
> if (is_dir) {
> if (descend && walk_is_cycle(state, ent_sb.st_dev,
> ent_sb.st_ino)) {
> - selinux_log(SELINUX_ERROR,
> + selinux_log(SELINUX_WARNING,
> "Directory cycle on %s.\n",
> ent_path);
> close(ent_fd);
> - close(rd_fd);
> - errno = ELOOP;
> - state->error = -1;
> - state->abort = true;
> - goto finish;
> + if (rd_fd >= 0)
> + close(rd_fd);
As before, you don't need the if (rd_fd >= 0) test here because this
is under an if (descend...)
so it is a tautology. And i thought you were going to explicitly note
the change in behavior via
e.g. a man page update or similar?
> + prune_pathbuf(state);
> + continue;
> }
>
> if (state->sfsb.f_type == SYSFS_MAGIC &&
> --
> 2.55.0
>
>
^ permalink raw reply [flat|nested] 3+ messages in thread
* Re: [PATCH v3] selinux_restorecon: Do not exit on directory cycles
2026-07-27 13:35 ` Stephen Smalley
@ 2026-07-28 6:57 ` Johannes Segitz
0 siblings, 0 replies; 3+ messages in thread
From: Johannes Segitz @ 2026-07-28 6:57 UTC (permalink / raw)
To: Stephen Smalley; +Cc: selinux
[-- Attachment #1: Type: text/plain, Size: 2459 bytes --]
On Mon, Jul 27, 2026 at 09:35:19AM -0400, Stephen Smalley wrote:
> On Mon, Jul 27, 2026 at 8:53 AM Johannes Segitz <jsegitz@suse.de> wrote:
> >
> > All other failures are handled gracefully. Directory cycles can e.g.
> > happen on BTRFS filesystems with subvolumes. Skip them and continue
> > instead of exiting
> >
> > Signed-off-by: Johannes Segitz <jsegitz@suse.de>
> > ---
> > libselinux/src/selinux_restorecon.c | 11 +++++------
> > 1 file changed, 5 insertions(+), 6 deletions(-)
> >
> > diff --git a/libselinux/src/selinux_restorecon.c b/libselinux/src/selinux_restorecon.c
> > index 30f1b836..fdefc92c 100644
> > --- a/libselinux/src/selinux_restorecon.c
> > +++ b/libselinux/src/selinux_restorecon.c
> > @@ -1393,15 +1393,14 @@ static void *selinux_restorecon_thread(void *arg)
> > if (is_dir) {
> > if (descend && walk_is_cycle(state, ent_sb.st_dev,
> > ent_sb.st_ino)) {
> > - selinux_log(SELINUX_ERROR,
> > + selinux_log(SELINUX_WARNING,
> > "Directory cycle on %s.\n",
> > ent_path);
> > close(ent_fd);
> > - close(rd_fd);
> > - errno = ELOOP;
> > - state->error = -1;
> > - state->abort = true;
> > - goto finish;
> > + if (rd_fd >= 0)
> > + close(rd_fd);
>
> As before, you don't need the if (rd_fd >= 0) test here because this
> is under an if (descend...)
> so it is a tautology. And i thought you were going to explicitly note
> the change in behavior via
> e.g. a man page update or similar?
yes, I might have gotten carried away that I finally beat git send-email
into submission that I sent the wrong patch ... v4 will be there in a sec,
sorry
Johannes
--
GPG Key EE16 6BCE AD56 E034 BFB3 3ADD 7BF7 29D5 E7C8 1FA0
Subkey fingerprint: 250F 43F5 F7CE 6F1E 9C59 4F95 BC27 DD9D 2CC4 FD66
SUSE Software Solutions Germany GmbH, Frankenstr. 146, 90461 Nürnberg, Germany
www.suse.com, Geschäftsführer: Jochen Jaser, Andrew McDonald, Abhinav Puri, (HRB 36809, AG Nürnberg)
[-- Attachment #2: Digital signature --]
[-- Type: application/pgp-signature, Size: 870 bytes --]
^ permalink raw reply [flat|nested] 3+ messages in thread
end of thread, other threads:[~2026-07-28 6:58 UTC | newest]
Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-07-27 12:47 [PATCH v3] selinux_restorecon: Do not exit on directory cycles Johannes Segitz
2026-07-27 13:35 ` Stephen Smalley
2026-07-28 6:57 ` Johannes Segitz
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.