From: Juraj Marcin <juraj@jurajmarcin.com>
To: selinux@vger.kernel.org
Subject: [PATCH v2 0/8] checkpolicy,libsepol: add prefix/suffix matching to filename type transitions
Date: Tue, 20 Jun 2023 11:01:15 +0200 [thread overview]
Message-ID: <cover.1687251081.git.juraj@jurajmarcin.com> (raw)
Currently, filename transitions are stored separately from other type
enforcement rules and only support exact name matching. However, in
practice, the names contain variable parts. This leads to many
duplicated rules in the policy that differ only in the part of the name,
or it is even impossible to cover all possible combinations.
This series implements equivalent changes made by this kernel patch
series [1].
First, this series of patches moves the filename transitions to be part
of the avtab and avrule structures. This not only makes the
implementation of prefix/suffix matching and future enhancements easier,
but also reduces the technical debt regarding the filename transitions.
Next, the last three patches implement the support for prefix/suffix
name matching itself by extending the structures added in previous
patches in this series and adding the support to CIL in the last of the
triple.
Even though, moving everything to avtab increases the memory usage and
the size of the binary policy itself and thus the loading time, the
ability to match the prefix or suffix of the name will reduce the
overall number of rules in the policy which should mitigate this issue.
[1]: https://lore.kernel.org/selinux/20230601170302.nrhuay2wh44g6sh4@jmarcin-t14s-01/
Changelog:
v2:
- rebased to the latest upstream main
- added syntax examples to commit messages (suggested by Jim)
- removed the "match_" prefix from keywords and dropped the
"match_exact" keyword (suggested by Jim, discussed with Ondrej)
- fixed the bug Jim found [2] where the output to conf and CIL did not
work
- reworked avtab entry skipping when writing older versions of the
policy
- fixed bug where expand_terule_helper() skipped next entries after
filename transition entry
- fixed memory leak in filenametr_destroy() found by Christian in the
kernel version of the code [3]
[2]: https://lore.kernel.org/selinux/CAP+JOzS1nhxF8EttikRtYBW2QtW=ck+P4mC2dovgP4kp-g9WQQ@mail.gmail.com/
[3]: https://lore.kernel.org/selinux/CAJ2a_DecaSa1Z7HiRs4sGUGx3AyKwhFA41EhAo+BViv-qA9ndg@mail.gmail.com/
Juraj Marcin (8):
checkpolicy,libsepol: move transition to separate structure in avtab
checkpolicy,libsepol: move filename transitions to avtab
checkpolicy,libsepol: move filename transition rules to avrule
libsepol: implement new kernel binary format for avtab
libsepol: implement new module binary format of avrule
checkpolicy,libsepol: add prefix/suffix support to kernel policy
checkpolicy,libsepol: add prefix/suffix support to module policy
libsepol/cil: add support for prefix/suffix filename transtions to CIL
checkpolicy/checkmodule.c | 9 +
checkpolicy/module_compiler.c | 12 -
checkpolicy/module_compiler.h | 1 -
checkpolicy/policy_define.c | 211 +-----
checkpolicy/policy_define.h | 3 +-
checkpolicy/policy_parse.y | 13 +-
checkpolicy/policy_scan.l | 4 +
checkpolicy/test/dismod.c | 39 +-
checkpolicy/test/dispol.c | 106 +--
libsepol/cil/src/cil.c | 6 +
libsepol/cil/src/cil_binary.c | 63 +-
libsepol/cil/src/cil_build_ast.c | 26 +-
libsepol/cil/src/cil_copy_ast.c | 1 +
libsepol/cil/src/cil_internal.h | 4 +
libsepol/cil/src/cil_policy.c | 17 +-
libsepol/cil/src/cil_resolve_ast.c | 10 +
libsepol/cil/src/cil_write_ast.c | 2 +
libsepol/include/sepol/policydb/avtab.h | 19 +-
libsepol/include/sepol/policydb/hashtab.h | 8 +
libsepol/include/sepol/policydb/policydb.h | 50 +-
libsepol/src/avrule_block.c | 1 -
libsepol/src/avtab.c | 338 +++++++++-
libsepol/src/conditional.c | 6 +-
libsepol/src/expand.c | 153 ++---
libsepol/src/kernel_to_cil.c | 182 ++---
libsepol/src/kernel_to_common.h | 10 +
libsepol/src/kernel_to_conf.c | 178 ++---
libsepol/src/link.c | 57 +-
libsepol/src/module_to_cil.c | 86 +--
libsepol/src/optimize.c | 8 +
libsepol/src/policydb.c | 479 +++-----------
libsepol/src/policydb_validate.c | 101 +--
libsepol/src/services.c | 5 +-
libsepol/src/write.c | 735 ++++++++++++++++-----
34 files changed, 1553 insertions(+), 1390 deletions(-)
--
2.40.0
next reply other threads:[~2023-06-20 9:02 UTC|newest]
Thread overview: 13+ messages / expand[flat|nested] mbox.gz Atom feed top
2023-06-20 9:01 Juraj Marcin [this message]
2023-06-20 9:01 ` [PATCH v2 1/8] checkpolicy,libsepol: move transition to separate structure in avtab Juraj Marcin
2023-07-07 18:12 ` James Carter
2023-07-12 17:34 ` James Carter
2023-07-12 19:17 ` Christian Göttsche
2023-07-12 19:49 ` James Carter
2023-06-20 9:01 ` [PATCH v2 2/8] checkpolicy,libsepol: move filename transitions to avtab Juraj Marcin
2023-06-20 9:01 ` [PATCH v2 3/8] checkpolicy,libsepol: move filename transition rules to avrule Juraj Marcin
2023-06-20 9:01 ` [PATCH v2 4/8] libsepol: implement new kernel binary format for avtab Juraj Marcin
2023-06-20 9:01 ` [PATCH v2 5/8] libsepol: implement new module binary format of avrule Juraj Marcin
2023-06-20 9:01 ` [PATCH v2 6/8] checkpolicy,libsepol: add prefix/suffix support to kernel policy Juraj Marcin
2023-06-20 9:01 ` [PATCH v2 7/8] checkpolicy,libsepol: add prefix/suffix support to module policy Juraj Marcin
2023-06-20 9:01 ` [PATCH v2 8/8] libsepol/cil: add support for prefix/suffix filename transtions to CIL Juraj Marcin
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=cover.1687251081.git.juraj@jurajmarcin.com \
--to=juraj@jurajmarcin.com \
--cc=selinux@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox