SELinux Security Module development
 help / color / mirror / Atom feed
* [PATCH] selinux: constify avc function parameters
@ 2026-09-17 14:13 Christian Göttsche
  2026-09-17 14:13 ` [PATCH 1/2] selinux: check neveraudit in avc_xperms_audit_required() Christian Göttsche
                   ` (3 more replies)
  0 siblings, 4 replies; 8+ messages in thread
From: Christian Göttsche @ 2026-09-17 14:13 UTC (permalink / raw)
  To: selinux
  Cc: Paul Moore, Stephen Smalley, Ondrej Mosnacek,
	Christian Göttsche

From: Christian Göttsche <cgzones@googlemail.com>

Constify read-only decision structs to ease reasoning where decisions
are actually modified, and where only processed.

Signed-off-by: Christian Göttsche <cgzones@googlemail.com>
---
 security/selinux/avc.c         | 27 ++++++++++++++-------------
 security/selinux/include/avc.h |  4 ++--
 2 files changed, 16 insertions(+), 15 deletions(-)

diff --git a/security/selinux/avc.c b/security/selinux/avc.c
index a9401d6c2e5f..6b86e2b370fe 100644
--- a/security/selinux/avc.c
+++ b/security/selinux/avc.c
@@ -190,8 +190,8 @@ avc_xperms_decision_lookup(u8 driver, u8 base_perm,
 }
 
 static inline unsigned int
-avc_xperms_has_perm(struct extended_perms_decision *xpd,
-					u8 perm, u8 which)
+avc_xperms_has_perm(const struct extended_perms_decision *xpd,
+		    u8 perm, u8 which)
 {
 	unsigned int rc = 0;
 
@@ -247,7 +247,7 @@ static void avc_xperms_free(struct avc_xperms_node *xp_node)
 }
 
 static void avc_copy_xperms_decision(struct extended_perms_decision *dest,
-					struct extended_perms_decision *src)
+					const struct extended_perms_decision *src)
 {
 	dest->base_perm = src->base_perm;
 	dest->driver = src->driver;
@@ -269,7 +269,7 @@ static void avc_copy_xperms_decision(struct extended_perms_decision *dest,
  */
 static inline void avc_quick_copy_xperms_decision(u8 perm,
 			struct extended_perms_decision *dest,
-			struct extended_perms_decision *src)
+			const struct extended_perms_decision *src)
 {
 	/*
 	 * compute index of the u32 of the 256 bits (8 u32s) that contain this
@@ -323,7 +323,7 @@ static struct avc_xperms_decision_node
 }
 
 static int avc_add_xperms_decision(struct avc_node *node,
-			struct extended_perms_decision *src)
+			const struct extended_perms_decision *src)
 {
 	struct avc_xperms_decision_node *dest_xpd;
 
@@ -348,7 +348,7 @@ static struct avc_xperms_node *avc_xperms_alloc(void)
 }
 
 static int avc_xperms_populate(struct avc_node *node,
-				struct avc_xperms_node *src)
+				const struct avc_xperms_node *src)
 {
 	struct avc_xperms_node *dest;
 	struct avc_xperms_decision_node *dest_xpd;
@@ -381,8 +381,8 @@ static int avc_xperms_populate(struct avc_node *node,
 }
 
 static inline u32 avc_xperms_audit_required(u32 requested,
-					struct av_decision *avd,
-					struct extended_perms_decision *xpd,
+					const struct av_decision *avd,
+					const struct extended_perms_decision *xpd,
 					u8 perm,
 					int result,
 					u32 *deniedp)
@@ -411,8 +411,8 @@ static inline u32 avc_xperms_audit_required(u32 requested,
 }
 
 static inline int avc_xperms_audit(u32 ssid, u32 tsid, u16 tclass,
-				   u32 requested, struct av_decision *avd,
-				   struct extended_perms_decision *xpd,
+				   u32 requested, const struct av_decision *avd,
+				   const struct extended_perms_decision *xpd,
 				   u8 perm, int result,
 				   struct common_audit_data *ad)
 {
@@ -509,7 +509,8 @@ static struct avc_node *avc_alloc_node(void)
 	return node;
 }
 
-static void avc_node_populate(struct avc_node *node, u32 ssid, u32 tsid, u16 tclass, struct av_decision *avd)
+static void avc_node_populate(struct avc_node *node, u32 ssid, u32 tsid, u16 tclass,
+			      const struct av_decision *avd)
 {
 	node->ae.ssid = ssid;
 	node->ae.tsid = tsid;
@@ -603,7 +604,7 @@ static int avc_latest_notif_update(u32 seqno, int is_insert)
  * the access vectors into a cache entry.
  */
 static void avc_insert(u32 ssid, u32 tsid, u16 tclass,
-		       struct av_decision *avd, struct avc_xperms_node *xp_node)
+		       const struct av_decision *avd, const struct avc_xperms_node *xp_node)
 {
 	struct avc_node *pos, *node = NULL;
 	u32 hvalue;
@@ -828,7 +829,7 @@ int __init avc_add_callback(int (*callback)(u32 event), u32 events)
  */
 static int avc_update_node(u32 event, u32 perms, u8 driver, u8 base_perm,
 			   u8 xperm, u32 ssid, u32 tsid, u16 tclass, u32 seqno,
-			   struct extended_perms_decision *xpd, u32 flags)
+			   const struct extended_perms_decision *xpd, u32 flags)
 {
 	u32 hvalue;
 	int rc = 0;
diff --git a/security/selinux/include/avc.h b/security/selinux/include/avc.h
index 01b5167fee1a..108d27f31c89 100644
--- a/security/selinux/include/avc.h
+++ b/security/selinux/include/avc.h
@@ -61,7 +61,7 @@ struct selinux_audit_data {
 
 void __init avc_init(void);
 
-static inline u32 avc_audit_required(u32 requested, struct av_decision *avd,
+static inline u32 avc_audit_required(u32 requested, const struct av_decision *avd,
 				     int result, u32 auditdeny, u32 *deniedp)
 {
 	u32 denied, audited;
@@ -121,7 +121,7 @@ int slow_avc_audit(u32 ssid, u32 tsid, u16 tclass, u32 requested, u32 audited,
  * before calling the auditing code.
  */
 static inline int avc_audit(u32 ssid, u32 tsid, u16 tclass, u32 requested,
-			    struct av_decision *avd, int result,
+			    const struct av_decision *avd, int result,
 			    struct common_audit_data *a)
 {
 	u32 audited, denied;
-- 
2.55.0


^ permalink raw reply related	[flat|nested] 8+ messages in thread

end of thread, other threads:[~2026-09-24 21:36 UTC | newest]

Thread overview: 8+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-17 14:13 [PATCH] selinux: constify avc function parameters Christian Göttsche
2026-09-17 14:13 ` [PATCH 1/2] selinux: check neveraudit in avc_xperms_audit_required() Christian Göttsche
2026-09-18 14:11   ` Stephen Smalley
2026-09-21 13:15     ` Christian Göttsche
2026-09-24 21:36   ` Paul Moore
2026-09-17 14:26 ` [PATCH] selinux: constify avc function parameters sashiko-bot
2026-09-18 14:10 ` Stephen Smalley
2026-09-24 21:04 ` Paul Moore

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox