SELinux Security Module development
 help / color / mirror / Atom feed
* [PATCH] selinux: constify avc function parameters
@ 2026-09-17 14:13 Christian Göttsche
  2026-09-17 14:13 ` [PATCH 1/2] selinux: check neveraudit in avc_xperms_audit_required() Christian Göttsche
                   ` (3 more replies)
  0 siblings, 4 replies; 8+ messages in thread
From: Christian Göttsche @ 2026-09-17 14:13 UTC (permalink / raw)
  To: selinux
  Cc: Paul Moore, Stephen Smalley, Ondrej Mosnacek,
	Christian Göttsche

From: Christian Göttsche <cgzones@googlemail.com>

Constify read-only decision structs to ease reasoning where decisions
are actually modified, and where only processed.

Signed-off-by: Christian Göttsche <cgzones@googlemail.com>
---
 security/selinux/avc.c         | 27 ++++++++++++++-------------
 security/selinux/include/avc.h |  4 ++--
 2 files changed, 16 insertions(+), 15 deletions(-)

diff --git a/security/selinux/avc.c b/security/selinux/avc.c
index a9401d6c2e5f..6b86e2b370fe 100644
--- a/security/selinux/avc.c
+++ b/security/selinux/avc.c
@@ -190,8 +190,8 @@ avc_xperms_decision_lookup(u8 driver, u8 base_perm,
 }
 
 static inline unsigned int
-avc_xperms_has_perm(struct extended_perms_decision *xpd,
-					u8 perm, u8 which)
+avc_xperms_has_perm(const struct extended_perms_decision *xpd,
+		    u8 perm, u8 which)
 {
 	unsigned int rc = 0;
 
@@ -247,7 +247,7 @@ static void avc_xperms_free(struct avc_xperms_node *xp_node)
 }
 
 static void avc_copy_xperms_decision(struct extended_perms_decision *dest,
-					struct extended_perms_decision *src)
+					const struct extended_perms_decision *src)
 {
 	dest->base_perm = src->base_perm;
 	dest->driver = src->driver;
@@ -269,7 +269,7 @@ static void avc_copy_xperms_decision(struct extended_perms_decision *dest,
  */
 static inline void avc_quick_copy_xperms_decision(u8 perm,
 			struct extended_perms_decision *dest,
-			struct extended_perms_decision *src)
+			const struct extended_perms_decision *src)
 {
 	/*
 	 * compute index of the u32 of the 256 bits (8 u32s) that contain this
@@ -323,7 +323,7 @@ static struct avc_xperms_decision_node
 }
 
 static int avc_add_xperms_decision(struct avc_node *node,
-			struct extended_perms_decision *src)
+			const struct extended_perms_decision *src)
 {
 	struct avc_xperms_decision_node *dest_xpd;
 
@@ -348,7 +348,7 @@ static struct avc_xperms_node *avc_xperms_alloc(void)
 }
 
 static int avc_xperms_populate(struct avc_node *node,
-				struct avc_xperms_node *src)
+				const struct avc_xperms_node *src)
 {
 	struct avc_xperms_node *dest;
 	struct avc_xperms_decision_node *dest_xpd;
@@ -381,8 +381,8 @@ static int avc_xperms_populate(struct avc_node *node,
 }
 
 static inline u32 avc_xperms_audit_required(u32 requested,
-					struct av_decision *avd,
-					struct extended_perms_decision *xpd,
+					const struct av_decision *avd,
+					const struct extended_perms_decision *xpd,
 					u8 perm,
 					int result,
 					u32 *deniedp)
@@ -411,8 +411,8 @@ static inline u32 avc_xperms_audit_required(u32 requested,
 }
 
 static inline int avc_xperms_audit(u32 ssid, u32 tsid, u16 tclass,
-				   u32 requested, struct av_decision *avd,
-				   struct extended_perms_decision *xpd,
+				   u32 requested, const struct av_decision *avd,
+				   const struct extended_perms_decision *xpd,
 				   u8 perm, int result,
 				   struct common_audit_data *ad)
 {
@@ -509,7 +509,8 @@ static struct avc_node *avc_alloc_node(void)
 	return node;
 }
 
-static void avc_node_populate(struct avc_node *node, u32 ssid, u32 tsid, u16 tclass, struct av_decision *avd)
+static void avc_node_populate(struct avc_node *node, u32 ssid, u32 tsid, u16 tclass,
+			      const struct av_decision *avd)
 {
 	node->ae.ssid = ssid;
 	node->ae.tsid = tsid;
@@ -603,7 +604,7 @@ static int avc_latest_notif_update(u32 seqno, int is_insert)
  * the access vectors into a cache entry.
  */
 static void avc_insert(u32 ssid, u32 tsid, u16 tclass,
-		       struct av_decision *avd, struct avc_xperms_node *xp_node)
+		       const struct av_decision *avd, const struct avc_xperms_node *xp_node)
 {
 	struct avc_node *pos, *node = NULL;
 	u32 hvalue;
@@ -828,7 +829,7 @@ int __init avc_add_callback(int (*callback)(u32 event), u32 events)
  */
 static int avc_update_node(u32 event, u32 perms, u8 driver, u8 base_perm,
 			   u8 xperm, u32 ssid, u32 tsid, u16 tclass, u32 seqno,
-			   struct extended_perms_decision *xpd, u32 flags)
+			   const struct extended_perms_decision *xpd, u32 flags)
 {
 	u32 hvalue;
 	int rc = 0;
diff --git a/security/selinux/include/avc.h b/security/selinux/include/avc.h
index 01b5167fee1a..108d27f31c89 100644
--- a/security/selinux/include/avc.h
+++ b/security/selinux/include/avc.h
@@ -61,7 +61,7 @@ struct selinux_audit_data {
 
 void __init avc_init(void);
 
-static inline u32 avc_audit_required(u32 requested, struct av_decision *avd,
+static inline u32 avc_audit_required(u32 requested, const struct av_decision *avd,
 				     int result, u32 auditdeny, u32 *deniedp)
 {
 	u32 denied, audited;
@@ -121,7 +121,7 @@ int slow_avc_audit(u32 ssid, u32 tsid, u16 tclass, u32 requested, u32 audited,
  * before calling the auditing code.
  */
 static inline int avc_audit(u32 ssid, u32 tsid, u16 tclass, u32 requested,
-			    struct av_decision *avd, int result,
+			    const struct av_decision *avd, int result,
 			    struct common_audit_data *a)
 {
 	u32 audited, denied;
-- 
2.55.0


^ permalink raw reply related	[flat|nested] 8+ messages in thread

* [PATCH 1/2] selinux: check neveraudit in avc_xperms_audit_required()
  2026-09-17 14:13 [PATCH] selinux: constify avc function parameters Christian Göttsche
@ 2026-09-17 14:13 ` Christian Göttsche
  2026-09-18 14:11   ` Stephen Smalley
  2026-09-24 21:36   ` Paul Moore
  2026-09-17 14:26 ` [PATCH] selinux: constify avc function parameters sashiko-bot
                   ` (2 subsequent siblings)
  3 siblings, 2 replies; 8+ messages in thread
From: Christian Göttsche @ 2026-09-17 14:13 UTC (permalink / raw)
  To: selinux
  Cc: Paul Moore, Stephen Smalley, Ondrej Mosnacek,
	Christian Göttsche

From: Christian Göttsche <cgzones@googlemail.com>

avc_audit_required() returns early for a neveraudit domain, while
avc_xperms_audit_required() instead relies on security_compute_av()
(and security_compute_av_user()) having already zeroed
avd->auditallow and avd->auditdeny for such a domain.  That leaves
its "else if (result)" branch as the only way left to audit a
neveraudit domain, and makes the two helpers read differently for
the same rule.

Add the same early return to avc_xperms_audit_required(), so both
audit gates state the neveraudit rule directly and the extended
permission audit path no longer depends on the auditallow/auditdeny
mask having been zeroed elsewhere.

No behavior changes today: avc_has_extended_perms() only reaches the
"result" branch once the identically computed "denied" is already
nonzero, so that branch was already unreachable in practice.

Signed-off-by: Christian Göttsche <cgzones@googlemail.com>
---
 security/selinux/avc.c | 3 +++
 1 file changed, 3 insertions(+)

diff --git a/security/selinux/avc.c b/security/selinux/avc.c
index a9401d6c2e5f..4e06ac9d46bf 100644
--- a/security/selinux/avc.c
+++ b/security/selinux/avc.c
@@ -389,6 +389,9 @@ static inline u32 avc_xperms_audit_required(u32 requested,
 {
 	u32 denied, audited;
 
+	if (avd->flags & AVD_FLAGS_NEVERAUDIT)
+		return 0;
+
 	denied = requested & ~avd->allowed;
 	if (unlikely(denied)) {
 		audited = denied & avd->auditdeny;
-- 
2.55.0


^ permalink raw reply related	[flat|nested] 8+ messages in thread

* Re: [PATCH] selinux: constify avc function parameters
  2026-09-17 14:13 [PATCH] selinux: constify avc function parameters Christian Göttsche
  2026-09-17 14:13 ` [PATCH 1/2] selinux: check neveraudit in avc_xperms_audit_required() Christian Göttsche
@ 2026-09-17 14:26 ` sashiko-bot
  2026-09-18 14:10 ` Stephen Smalley
  2026-09-24 21:04 ` Paul Moore
  3 siblings, 0 replies; 8+ messages in thread
From: sashiko-bot @ 2026-09-17 14:26 UTC (permalink / raw)
  Cc: selinux

> From: Christian Göttsche <cgzones@googlemail.com>
> 
> Constify read-only decision structs to ease reasoning where decisions
> are actually modified, and where only processed.
> 
> Signed-off-by: Christian Göttsche <cgzones@googlemail.com>

Sashiko has reviewed this patch and found no issues. It looks great!

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260917141317.54719-1-cgoettsche@seltendoof.de?part=1


^ permalink raw reply	[flat|nested] 8+ messages in thread

* Re: [PATCH] selinux: constify avc function parameters
  2026-09-17 14:13 [PATCH] selinux: constify avc function parameters Christian Göttsche
  2026-09-17 14:13 ` [PATCH 1/2] selinux: check neveraudit in avc_xperms_audit_required() Christian Göttsche
  2026-09-17 14:26 ` [PATCH] selinux: constify avc function parameters sashiko-bot
@ 2026-09-18 14:10 ` Stephen Smalley
  2026-09-24 21:04 ` Paul Moore
  3 siblings, 0 replies; 8+ messages in thread
From: Stephen Smalley @ 2026-09-18 14:10 UTC (permalink / raw)
  To: cgzones; +Cc: selinux, Paul Moore, Ondrej Mosnacek

On Thu, Sep 17, 2026 at 10:13 AM Christian Göttsche
<cgoettsche@seltendoof.de> wrote:
>
> From: Christian Göttsche <cgzones@googlemail.com>
>
> Constify read-only decision structs to ease reasoning where decisions
> are actually modified, and where only processed.
>
> Signed-off-by: Christian Göttsche <cgzones@googlemail.com>

Acked-by: Stephen Smalley <stephen.smalley.work@gmail.com>

^ permalink raw reply	[flat|nested] 8+ messages in thread

* Re: [PATCH 1/2] selinux: check neveraudit in avc_xperms_audit_required()
  2026-09-17 14:13 ` [PATCH 1/2] selinux: check neveraudit in avc_xperms_audit_required() Christian Göttsche
@ 2026-09-18 14:11   ` Stephen Smalley
  2026-09-21 13:15     ` Christian Göttsche
  2026-09-24 21:36   ` Paul Moore
  1 sibling, 1 reply; 8+ messages in thread
From: Stephen Smalley @ 2026-09-18 14:11 UTC (permalink / raw)
  To: cgzones; +Cc: selinux, Paul Moore, Ondrej Mosnacek

On Thu, Sep 17, 2026 at 10:13 AM Christian Göttsche
<cgoettsche@seltendoof.de> wrote:
>
> From: Christian Göttsche <cgzones@googlemail.com>
>
> avc_audit_required() returns early for a neveraudit domain, while
> avc_xperms_audit_required() instead relies on security_compute_av()
> (and security_compute_av_user()) having already zeroed
> avd->auditallow and avd->auditdeny for such a domain.  That leaves
> its "else if (result)" branch as the only way left to audit a
> neveraudit domain, and makes the two helpers read differently for
> the same rule.
>
> Add the same early return to avc_xperms_audit_required(), so both
> audit gates state the neveraudit rule directly and the extended
> permission audit path no longer depends on the auditallow/auditdeny
> mask having been zeroed elsewhere.
>
> No behavior changes today: avc_has_extended_perms() only reaches the
> "result" branch once the identically computed "denied" is already
> nonzero, so that branch was already unreachable in practice.
>
> Signed-off-by: Christian Göttsche <cgzones@googlemail.com>

Acked-by: Stephen Smalley <stephen.smalley.work@gmail.com>

I didn't see patch 2/2 unless it was one of the other ones.

^ permalink raw reply	[flat|nested] 8+ messages in thread

* Re: [PATCH 1/2] selinux: check neveraudit in avc_xperms_audit_required()
  2026-09-18 14:11   ` Stephen Smalley
@ 2026-09-21 13:15     ` Christian Göttsche
  0 siblings, 0 replies; 8+ messages in thread
From: Christian Göttsche @ 2026-09-21 13:15 UTC (permalink / raw)
  To: Stephen Smalley; +Cc: selinux, Paul Moore, Ondrej Mosnacek

On Fri, 18 Sept 2026 at 16:11, Stephen Smalley
<stephen.smalley.work@gmail.com> wrote:
>
> On Thu, Sep 17, 2026 at 10:13 AM Christian Göttsche
> <cgoettsche@seltendoof.de> wrote:
> >
> > From: Christian Göttsche <cgzones@googlemail.com>
> >
> > avc_audit_required() returns early for a neveraudit domain, while
> > avc_xperms_audit_required() instead relies on security_compute_av()
> > (and security_compute_av_user()) having already zeroed
> > avd->auditallow and avd->auditdeny for such a domain.  That leaves
> > its "else if (result)" branch as the only way left to audit a
> > neveraudit domain, and makes the two helpers read differently for
> > the same rule.
> >
> > Add the same early return to avc_xperms_audit_required(), so both
> > audit gates state the neveraudit rule directly and the extended
> > permission audit path no longer depends on the auditallow/auditdeny
> > mask having been zeroed elsewhere.
> >
> > No behavior changes today: avc_has_extended_perms() only reaches the
> > "result" branch once the identically computed "denied" is already
> > nonzero, so that branch was already unreachable in practice.
> >
> > Signed-off-by: Christian Göttsche <cgzones@googlemail.com>
>
> Acked-by: Stephen Smalley <stephen.smalley.work@gmail.com>
>
> I didn't see patch 2/2 unless it was one of the other ones.

Yeah sorry, this is a standalone patch; messed up patch generation.

^ permalink raw reply	[flat|nested] 8+ messages in thread

* Re: [PATCH] selinux: constify avc function parameters
  2026-09-17 14:13 [PATCH] selinux: constify avc function parameters Christian Göttsche
                   ` (2 preceding siblings ...)
  2026-09-18 14:10 ` Stephen Smalley
@ 2026-09-24 21:04 ` Paul Moore
  3 siblings, 0 replies; 8+ messages in thread
From: Paul Moore @ 2026-09-24 21:04 UTC (permalink / raw)
  To: Christian Göttsche, selinux
  Cc: Stephen Smalley, Ondrej Mosnacek, Christian Göttsche

On Sep 17, 2026 =?UTF-8?q?Christian=20G=C3=B6ttsche?= <cgoettsche@seltendoof.de> wrote:
> 
> Constify read-only decision structs to ease reasoning where decisions
> are actually modified, and where only processed.
> 
> Signed-off-by: Christian Göttsche <cgzones@googlemail.com>
> Acked-by: Stephen Smalley <stephen.smalley.work@gmail.com>
> ---
>  security/selinux/avc.c         | 27 ++++++++++++++-------------
>  security/selinux/include/avc.h |  4 ++--
>  2 files changed, 16 insertions(+), 15 deletions(-)

Merged into selinux/dev with fixes to the line lengths, thanks!

--
paul-moore.com

^ permalink raw reply	[flat|nested] 8+ messages in thread

* Re: [PATCH 1/2] selinux: check neveraudit in avc_xperms_audit_required()
  2026-09-17 14:13 ` [PATCH 1/2] selinux: check neveraudit in avc_xperms_audit_required() Christian Göttsche
  2026-09-18 14:11   ` Stephen Smalley
@ 2026-09-24 21:36   ` Paul Moore
  1 sibling, 0 replies; 8+ messages in thread
From: Paul Moore @ 2026-09-24 21:36 UTC (permalink / raw)
  To: cgzones; +Cc: selinux, Stephen Smalley, Ondrej Mosnacek

On Thu, Sep 17, 2026 at 10:13 AM Christian Göttsche
<cgoettsche@seltendoof.de> wrote:
>
> From: Christian Göttsche <cgzones@googlemail.com>
>
> avc_audit_required() returns early for a neveraudit domain, while
> avc_xperms_audit_required() instead relies on security_compute_av()
> (and security_compute_av_user()) having already zeroed
> avd->auditallow and avd->auditdeny for such a domain.  That leaves
> its "else if (result)" branch as the only way left to audit a
> neveraudit domain, and makes the two helpers read differently for
> the same rule.
>
> Add the same early return to avc_xperms_audit_required(), so both
> audit gates state the neveraudit rule directly and the extended
> permission audit path no longer depends on the auditallow/auditdeny
> mask having been zeroed elsewhere.
>
> No behavior changes today: avc_has_extended_perms() only reaches the
> "result" branch once the identically computed "denied" is already
> nonzero, so that branch was already unreachable in practice.
>
> Signed-off-by: Christian Göttsche <cgzones@googlemail.com>
> ---
>  security/selinux/avc.c | 3 +++
>  1 file changed, 3 insertions(+)

Merged into selinux/dev, thanks!

-- 
paul-moore.com

^ permalink raw reply	[flat|nested] 8+ messages in thread

end of thread, other threads:[~2026-09-24 21:36 UTC | newest]

Thread overview: 8+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-17 14:13 [PATCH] selinux: constify avc function parameters Christian Göttsche
2026-09-17 14:13 ` [PATCH 1/2] selinux: check neveraudit in avc_xperms_audit_required() Christian Göttsche
2026-09-18 14:11   ` Stephen Smalley
2026-09-21 13:15     ` Christian Göttsche
2026-09-24 21:36   ` Paul Moore
2026-09-17 14:26 ` [PATCH] selinux: constify avc function parameters sashiko-bot
2026-09-18 14:10 ` Stephen Smalley
2026-09-24 21:04 ` Paul Moore

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox