The Linux Kernel Mailing List
 help / color / mirror / Atom feed
From: James Morris <jmorris@namei.org>
To: Linus Torvalds <torvalds@linux-foundation.org>
Cc: linux-kernel@vger.kernel.org, Stephen Smalley <sds@tycho.nsa.gov>
Subject: [PATCH 12/12] selinux: preserve boolean values across policy reloads
Date: Thu, 26 Apr 2007 02:12:00 -0400 (EDT)	[thread overview]
Message-ID: <Line.LNX.4.64.0704260211270.30059@d.namei> (raw)
In-Reply-To: <Line.LNX.4.64.0704260200450.30059@d.namei>

From: Stephen Smalley <sds@tycho.nsa.gov>

At present, the userland policy loading code has to go through contortions 
to preserve boolean values across policy reloads, and cannot do so 
atomically. As this is what we always want to do for reloads, let the 
kernel preserve them instead.

Signed-off-by: Stephen Smalley <sds@tycho.nsa.gov>
Acked-by: Karl MacMillan <kmacmillan@mentalrootkit.com>
Signed-off-by: James Morris <jmorris@namei.org>
---
 security/selinux/ss/services.c |   38 ++++++++++++++++++++++++++++++++++++++
 1 files changed, 38 insertions(+), 0 deletions(-)

diff --git a/security/selinux/ss/services.c b/security/selinux/ss/services.c
index 21b8318..40660ff 100644
--- a/security/selinux/ss/services.c
+++ b/security/selinux/ss/services.c
@@ -1257,6 +1257,7 @@ bad:
 }
 
 extern void selinux_complete_init(void);
+static int security_preserve_bools(struct policydb *p);
 
 /**
  * security_load_policy - Load a security policy configuration.
@@ -1333,6 +1334,12 @@ int security_load_policy(void *data, size_t len)
 		goto err;
 	}
 
+	rc = security_preserve_bools(&newpolicydb);
+	if (rc) {
+		printk(KERN_ERR "security:  unable to preserve booleans\n");
+		goto err;
+	}
+
 	/* Clone the SID table. */
 	sidtab_shutdown(&sidtab);
 	if (sidtab_map(&sidtab, clone_sid, &newsidtab)) {
@@ -1890,6 +1897,37 @@ out:
 	return rc;
 }
 
+static int security_preserve_bools(struct policydb *p)
+{
+	int rc, nbools = 0, *bvalues = NULL, i;
+	char **bnames = NULL;
+	struct cond_bool_datum *booldatum;
+	struct cond_node *cur;
+
+	rc = security_get_bools(&nbools, &bnames, &bvalues);
+	if (rc)
+		goto out;
+	for (i = 0; i < nbools; i++) {
+		booldatum = hashtab_search(p->p_bools.table, bnames[i]);
+		if (booldatum)
+			booldatum->state = bvalues[i];
+	}
+	for (cur = p->cond_list; cur != NULL; cur = cur->next) {
+		rc = evaluate_cond_node(p, cur);
+		if (rc)
+			goto out;
+	}
+
+out:
+	if (bnames) {
+		for (i = 0; i < nbools; i++)
+			kfree(bnames[i]);
+	}
+	kfree(bnames);
+	kfree(bvalues);
+	return rc;
+}
+
 /*
  * security_sid_mls_copy() - computes a new sid based on the given
  * sid and the mls portion of mls_sid.
-- 
1.5.0.6


      parent reply	other threads:[~2007-04-26  6:19 UTC|newest]

Thread overview: 13+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2007-04-26  6:02 [PATCH 0/12] SELinux patches for 2.6.22 James Morris
2007-04-26  6:03 ` [PATCH 01/12] NetLabel: cleanup and document CIPSO constants James Morris
2007-04-26  6:04 ` [PATCH 02/12] NetLabel: convert a BUG_ON in the CIPSO code to a runtime check James Morris
2007-04-26  6:05 ` [PATCH 03/12] SELinux: extract the NetLabel SELinux support from the security server James Morris
2007-04-26  6:06 ` [PATCH 04/12] SELinux: rename selinux_netlabel.h to netlabel.h James Morris
2007-04-26  6:07 ` [PATCH 05/12] MAINTAINERS: update selinux entry James Morris
2007-04-26  6:08 ` [PATCH 06/12] SELinux: move security_skb_extlbl_sid() out of the security server James Morris
2007-04-26  6:08 ` [PATCH 07/12] selinux: remove userland security class and permission definitions James Morris
2007-04-26  6:09 ` [PATCH 08/12] selinux: export initial SID contexts via selinuxfs James Morris
2007-04-26  6:10 ` [PATCH 09/12] selinux: explicitly number all selinuxfs inodes James Morris
2007-04-26  6:10 ` [PATCH 10/12] selinux: remove unused enumeration constant from selinuxfs James Morris
2007-04-26  6:11 ` [PATCH 11/12] selinux: change numbering of boolean directory inodes in selinuxfs James Morris
2007-04-26  6:12 ` James Morris [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=Line.LNX.4.64.0704260211270.30059@d.namei \
    --to=jmorris@namei.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=sds@tycho.nsa.gov \
    --cc=torvalds@linux-foundation.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox