* [PATCH] selinux: constify avc function parameters
@ 2026-09-17 14:13 Christian Göttsche
2026-09-17 14:13 ` [PATCH 1/2] selinux: check neveraudit in avc_xperms_audit_required() Christian Göttsche
` (3 more replies)
0 siblings, 4 replies; 8+ messages in thread
From: Christian Göttsche @ 2026-09-17 14:13 UTC (permalink / raw)
To: selinux
Cc: Paul Moore, Stephen Smalley, Ondrej Mosnacek,
Christian Göttsche
From: Christian Göttsche <cgzones@googlemail.com>
Constify read-only decision structs to ease reasoning where decisions
are actually modified, and where only processed.
Signed-off-by: Christian Göttsche <cgzones@googlemail.com>
---
security/selinux/avc.c | 27 ++++++++++++++-------------
security/selinux/include/avc.h | 4 ++--
2 files changed, 16 insertions(+), 15 deletions(-)
diff --git a/security/selinux/avc.c b/security/selinux/avc.c
index a9401d6c2e5f..6b86e2b370fe 100644
--- a/security/selinux/avc.c
+++ b/security/selinux/avc.c
@@ -190,8 +190,8 @@ avc_xperms_decision_lookup(u8 driver, u8 base_perm,
}
static inline unsigned int
-avc_xperms_has_perm(struct extended_perms_decision *xpd,
- u8 perm, u8 which)
+avc_xperms_has_perm(const struct extended_perms_decision *xpd,
+ u8 perm, u8 which)
{
unsigned int rc = 0;
@@ -247,7 +247,7 @@ static void avc_xperms_free(struct avc_xperms_node *xp_node)
}
static void avc_copy_xperms_decision(struct extended_perms_decision *dest,
- struct extended_perms_decision *src)
+ const struct extended_perms_decision *src)
{
dest->base_perm = src->base_perm;
dest->driver = src->driver;
@@ -269,7 +269,7 @@ static void avc_copy_xperms_decision(struct extended_perms_decision *dest,
*/
static inline void avc_quick_copy_xperms_decision(u8 perm,
struct extended_perms_decision *dest,
- struct extended_perms_decision *src)
+ const struct extended_perms_decision *src)
{
/*
* compute index of the u32 of the 256 bits (8 u32s) that contain this
@@ -323,7 +323,7 @@ static struct avc_xperms_decision_node
}
static int avc_add_xperms_decision(struct avc_node *node,
- struct extended_perms_decision *src)
+ const struct extended_perms_decision *src)
{
struct avc_xperms_decision_node *dest_xpd;
@@ -348,7 +348,7 @@ static struct avc_xperms_node *avc_xperms_alloc(void)
}
static int avc_xperms_populate(struct avc_node *node,
- struct avc_xperms_node *src)
+ const struct avc_xperms_node *src)
{
struct avc_xperms_node *dest;
struct avc_xperms_decision_node *dest_xpd;
@@ -381,8 +381,8 @@ static int avc_xperms_populate(struct avc_node *node,
}
static inline u32 avc_xperms_audit_required(u32 requested,
- struct av_decision *avd,
- struct extended_perms_decision *xpd,
+ const struct av_decision *avd,
+ const struct extended_perms_decision *xpd,
u8 perm,
int result,
u32 *deniedp)
@@ -411,8 +411,8 @@ static inline u32 avc_xperms_audit_required(u32 requested,
}
static inline int avc_xperms_audit(u32 ssid, u32 tsid, u16 tclass,
- u32 requested, struct av_decision *avd,
- struct extended_perms_decision *xpd,
+ u32 requested, const struct av_decision *avd,
+ const struct extended_perms_decision *xpd,
u8 perm, int result,
struct common_audit_data *ad)
{
@@ -509,7 +509,8 @@ static struct avc_node *avc_alloc_node(void)
return node;
}
-static void avc_node_populate(struct avc_node *node, u32 ssid, u32 tsid, u16 tclass, struct av_decision *avd)
+static void avc_node_populate(struct avc_node *node, u32 ssid, u32 tsid, u16 tclass,
+ const struct av_decision *avd)
{
node->ae.ssid = ssid;
node->ae.tsid = tsid;
@@ -603,7 +604,7 @@ static int avc_latest_notif_update(u32 seqno, int is_insert)
* the access vectors into a cache entry.
*/
static void avc_insert(u32 ssid, u32 tsid, u16 tclass,
- struct av_decision *avd, struct avc_xperms_node *xp_node)
+ const struct av_decision *avd, const struct avc_xperms_node *xp_node)
{
struct avc_node *pos, *node = NULL;
u32 hvalue;
@@ -828,7 +829,7 @@ int __init avc_add_callback(int (*callback)(u32 event), u32 events)
*/
static int avc_update_node(u32 event, u32 perms, u8 driver, u8 base_perm,
u8 xperm, u32 ssid, u32 tsid, u16 tclass, u32 seqno,
- struct extended_perms_decision *xpd, u32 flags)
+ const struct extended_perms_decision *xpd, u32 flags)
{
u32 hvalue;
int rc = 0;
diff --git a/security/selinux/include/avc.h b/security/selinux/include/avc.h
index 01b5167fee1a..108d27f31c89 100644
--- a/security/selinux/include/avc.h
+++ b/security/selinux/include/avc.h
@@ -61,7 +61,7 @@ struct selinux_audit_data {
void __init avc_init(void);
-static inline u32 avc_audit_required(u32 requested, struct av_decision *avd,
+static inline u32 avc_audit_required(u32 requested, const struct av_decision *avd,
int result, u32 auditdeny, u32 *deniedp)
{
u32 denied, audited;
@@ -121,7 +121,7 @@ int slow_avc_audit(u32 ssid, u32 tsid, u16 tclass, u32 requested, u32 audited,
* before calling the auditing code.
*/
static inline int avc_audit(u32 ssid, u32 tsid, u16 tclass, u32 requested,
- struct av_decision *avd, int result,
+ const struct av_decision *avd, int result,
struct common_audit_data *a)
{
u32 audited, denied;
--
2.55.0
^ permalink raw reply related [flat|nested] 8+ messages in thread
* [PATCH 1/2] selinux: check neveraudit in avc_xperms_audit_required()
2026-09-17 14:13 [PATCH] selinux: constify avc function parameters Christian Göttsche
@ 2026-09-17 14:13 ` Christian Göttsche
2026-09-18 14:11 ` Stephen Smalley
2026-09-24 21:36 ` Paul Moore
2026-09-17 14:26 ` [PATCH] selinux: constify avc function parameters sashiko-bot
` (2 subsequent siblings)
3 siblings, 2 replies; 8+ messages in thread
From: Christian Göttsche @ 2026-09-17 14:13 UTC (permalink / raw)
To: selinux
Cc: Paul Moore, Stephen Smalley, Ondrej Mosnacek,
Christian Göttsche
From: Christian Göttsche <cgzones@googlemail.com>
avc_audit_required() returns early for a neveraudit domain, while
avc_xperms_audit_required() instead relies on security_compute_av()
(and security_compute_av_user()) having already zeroed
avd->auditallow and avd->auditdeny for such a domain. That leaves
its "else if (result)" branch as the only way left to audit a
neveraudit domain, and makes the two helpers read differently for
the same rule.
Add the same early return to avc_xperms_audit_required(), so both
audit gates state the neveraudit rule directly and the extended
permission audit path no longer depends on the auditallow/auditdeny
mask having been zeroed elsewhere.
No behavior changes today: avc_has_extended_perms() only reaches the
"result" branch once the identically computed "denied" is already
nonzero, so that branch was already unreachable in practice.
Signed-off-by: Christian Göttsche <cgzones@googlemail.com>
---
security/selinux/avc.c | 3 +++
1 file changed, 3 insertions(+)
diff --git a/security/selinux/avc.c b/security/selinux/avc.c
index a9401d6c2e5f..4e06ac9d46bf 100644
--- a/security/selinux/avc.c
+++ b/security/selinux/avc.c
@@ -389,6 +389,9 @@ static inline u32 avc_xperms_audit_required(u32 requested,
{
u32 denied, audited;
+ if (avd->flags & AVD_FLAGS_NEVERAUDIT)
+ return 0;
+
denied = requested & ~avd->allowed;
if (unlikely(denied)) {
audited = denied & avd->auditdeny;
--
2.55.0
^ permalink raw reply related [flat|nested] 8+ messages in thread
* Re: [PATCH] selinux: constify avc function parameters
2026-09-17 14:13 [PATCH] selinux: constify avc function parameters Christian Göttsche
2026-09-17 14:13 ` [PATCH 1/2] selinux: check neveraudit in avc_xperms_audit_required() Christian Göttsche
@ 2026-09-17 14:26 ` sashiko-bot
2026-09-18 14:10 ` Stephen Smalley
2026-09-24 21:04 ` Paul Moore
3 siblings, 0 replies; 8+ messages in thread
From: sashiko-bot @ 2026-09-17 14:26 UTC (permalink / raw)
Cc: selinux
> From: Christian Göttsche <cgzones@googlemail.com>
>
> Constify read-only decision structs to ease reasoning where decisions
> are actually modified, and where only processed.
>
> Signed-off-by: Christian Göttsche <cgzones@googlemail.com>
Sashiko has reviewed this patch and found no issues. It looks great!
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260917141317.54719-1-cgoettsche@seltendoof.de?part=1
^ permalink raw reply [flat|nested] 8+ messages in thread
* Re: [PATCH] selinux: constify avc function parameters
2026-09-17 14:13 [PATCH] selinux: constify avc function parameters Christian Göttsche
2026-09-17 14:13 ` [PATCH 1/2] selinux: check neveraudit in avc_xperms_audit_required() Christian Göttsche
2026-09-17 14:26 ` [PATCH] selinux: constify avc function parameters sashiko-bot
@ 2026-09-18 14:10 ` Stephen Smalley
2026-09-24 21:04 ` Paul Moore
3 siblings, 0 replies; 8+ messages in thread
From: Stephen Smalley @ 2026-09-18 14:10 UTC (permalink / raw)
To: cgzones; +Cc: selinux, Paul Moore, Ondrej Mosnacek
On Thu, Sep 17, 2026 at 10:13 AM Christian Göttsche
<cgoettsche@seltendoof.de> wrote:
>
> From: Christian Göttsche <cgzones@googlemail.com>
>
> Constify read-only decision structs to ease reasoning where decisions
> are actually modified, and where only processed.
>
> Signed-off-by: Christian Göttsche <cgzones@googlemail.com>
Acked-by: Stephen Smalley <stephen.smalley.work@gmail.com>
^ permalink raw reply [flat|nested] 8+ messages in thread
* Re: [PATCH 1/2] selinux: check neveraudit in avc_xperms_audit_required()
2026-09-17 14:13 ` [PATCH 1/2] selinux: check neveraudit in avc_xperms_audit_required() Christian Göttsche
@ 2026-09-18 14:11 ` Stephen Smalley
2026-09-21 13:15 ` Christian Göttsche
2026-09-24 21:36 ` Paul Moore
1 sibling, 1 reply; 8+ messages in thread
From: Stephen Smalley @ 2026-09-18 14:11 UTC (permalink / raw)
To: cgzones; +Cc: selinux, Paul Moore, Ondrej Mosnacek
On Thu, Sep 17, 2026 at 10:13 AM Christian Göttsche
<cgoettsche@seltendoof.de> wrote:
>
> From: Christian Göttsche <cgzones@googlemail.com>
>
> avc_audit_required() returns early for a neveraudit domain, while
> avc_xperms_audit_required() instead relies on security_compute_av()
> (and security_compute_av_user()) having already zeroed
> avd->auditallow and avd->auditdeny for such a domain. That leaves
> its "else if (result)" branch as the only way left to audit a
> neveraudit domain, and makes the two helpers read differently for
> the same rule.
>
> Add the same early return to avc_xperms_audit_required(), so both
> audit gates state the neveraudit rule directly and the extended
> permission audit path no longer depends on the auditallow/auditdeny
> mask having been zeroed elsewhere.
>
> No behavior changes today: avc_has_extended_perms() only reaches the
> "result" branch once the identically computed "denied" is already
> nonzero, so that branch was already unreachable in practice.
>
> Signed-off-by: Christian Göttsche <cgzones@googlemail.com>
Acked-by: Stephen Smalley <stephen.smalley.work@gmail.com>
I didn't see patch 2/2 unless it was one of the other ones.
^ permalink raw reply [flat|nested] 8+ messages in thread
* Re: [PATCH 1/2] selinux: check neveraudit in avc_xperms_audit_required()
2026-09-18 14:11 ` Stephen Smalley
@ 2026-09-21 13:15 ` Christian Göttsche
0 siblings, 0 replies; 8+ messages in thread
From: Christian Göttsche @ 2026-09-21 13:15 UTC (permalink / raw)
To: Stephen Smalley; +Cc: selinux, Paul Moore, Ondrej Mosnacek
On Fri, 18 Sept 2026 at 16:11, Stephen Smalley
<stephen.smalley.work@gmail.com> wrote:
>
> On Thu, Sep 17, 2026 at 10:13 AM Christian Göttsche
> <cgoettsche@seltendoof.de> wrote:
> >
> > From: Christian Göttsche <cgzones@googlemail.com>
> >
> > avc_audit_required() returns early for a neveraudit domain, while
> > avc_xperms_audit_required() instead relies on security_compute_av()
> > (and security_compute_av_user()) having already zeroed
> > avd->auditallow and avd->auditdeny for such a domain. That leaves
> > its "else if (result)" branch as the only way left to audit a
> > neveraudit domain, and makes the two helpers read differently for
> > the same rule.
> >
> > Add the same early return to avc_xperms_audit_required(), so both
> > audit gates state the neveraudit rule directly and the extended
> > permission audit path no longer depends on the auditallow/auditdeny
> > mask having been zeroed elsewhere.
> >
> > No behavior changes today: avc_has_extended_perms() only reaches the
> > "result" branch once the identically computed "denied" is already
> > nonzero, so that branch was already unreachable in practice.
> >
> > Signed-off-by: Christian Göttsche <cgzones@googlemail.com>
>
> Acked-by: Stephen Smalley <stephen.smalley.work@gmail.com>
>
> I didn't see patch 2/2 unless it was one of the other ones.
Yeah sorry, this is a standalone patch; messed up patch generation.
^ permalink raw reply [flat|nested] 8+ messages in thread
* Re: [PATCH] selinux: constify avc function parameters
2026-09-17 14:13 [PATCH] selinux: constify avc function parameters Christian Göttsche
` (2 preceding siblings ...)
2026-09-18 14:10 ` Stephen Smalley
@ 2026-09-24 21:04 ` Paul Moore
3 siblings, 0 replies; 8+ messages in thread
From: Paul Moore @ 2026-09-24 21:04 UTC (permalink / raw)
To: Christian Göttsche, selinux
Cc: Stephen Smalley, Ondrej Mosnacek, Christian Göttsche
On Sep 17, 2026 =?UTF-8?q?Christian=20G=C3=B6ttsche?= <cgoettsche@seltendoof.de> wrote:
>
> Constify read-only decision structs to ease reasoning where decisions
> are actually modified, and where only processed.
>
> Signed-off-by: Christian Göttsche <cgzones@googlemail.com>
> Acked-by: Stephen Smalley <stephen.smalley.work@gmail.com>
> ---
> security/selinux/avc.c | 27 ++++++++++++++-------------
> security/selinux/include/avc.h | 4 ++--
> 2 files changed, 16 insertions(+), 15 deletions(-)
Merged into selinux/dev with fixes to the line lengths, thanks!
--
paul-moore.com
^ permalink raw reply [flat|nested] 8+ messages in thread
* Re: [PATCH 1/2] selinux: check neveraudit in avc_xperms_audit_required()
2026-09-17 14:13 ` [PATCH 1/2] selinux: check neveraudit in avc_xperms_audit_required() Christian Göttsche
2026-09-18 14:11 ` Stephen Smalley
@ 2026-09-24 21:36 ` Paul Moore
1 sibling, 0 replies; 8+ messages in thread
From: Paul Moore @ 2026-09-24 21:36 UTC (permalink / raw)
To: cgzones; +Cc: selinux, Stephen Smalley, Ondrej Mosnacek
On Thu, Sep 17, 2026 at 10:13 AM Christian Göttsche
<cgoettsche@seltendoof.de> wrote:
>
> From: Christian Göttsche <cgzones@googlemail.com>
>
> avc_audit_required() returns early for a neveraudit domain, while
> avc_xperms_audit_required() instead relies on security_compute_av()
> (and security_compute_av_user()) having already zeroed
> avd->auditallow and avd->auditdeny for such a domain. That leaves
> its "else if (result)" branch as the only way left to audit a
> neveraudit domain, and makes the two helpers read differently for
> the same rule.
>
> Add the same early return to avc_xperms_audit_required(), so both
> audit gates state the neveraudit rule directly and the extended
> permission audit path no longer depends on the auditallow/auditdeny
> mask having been zeroed elsewhere.
>
> No behavior changes today: avc_has_extended_perms() only reaches the
> "result" branch once the identically computed "denied" is already
> nonzero, so that branch was already unreachable in practice.
>
> Signed-off-by: Christian Göttsche <cgzones@googlemail.com>
> ---
> security/selinux/avc.c | 3 +++
> 1 file changed, 3 insertions(+)
Merged into selinux/dev, thanks!
--
paul-moore.com
^ permalink raw reply [flat|nested] 8+ messages in thread
end of thread, other threads:[~2026-09-24 21:36 UTC | newest]
Thread overview: 8+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-17 14:13 [PATCH] selinux: constify avc function parameters Christian Göttsche
2026-09-17 14:13 ` [PATCH 1/2] selinux: check neveraudit in avc_xperms_audit_required() Christian Göttsche
2026-09-18 14:11 ` Stephen Smalley
2026-09-21 13:15 ` Christian Göttsche
2026-09-24 21:36 ` Paul Moore
2026-09-17 14:26 ` [PATCH] selinux: constify avc function parameters sashiko-bot
2026-09-18 14:10 ` Stephen Smalley
2026-09-24 21:04 ` Paul Moore
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox