Re: [PATCH refpolicy] kernel: remove some unused initial SID contexts
"Christopher J. PeBenito" <[email protected]> Mon, 03 Nov 2025 11:40:02 -0500
| Newsgroups | org.kernel.vger.selinux-refpolicy,org.kernel.vger.selinux |
|---|---|
| Message-ID | <[email protected]> |
On Monday, November 3, 2025 9:23:11 AM Eastern Standard Time Stephen Smalley wrote: > On Mon, Nov 3, 2025 at 8:33 AM Stephen Smalley > > <[email protected]> wrote: > > On Sun, Nov 2, 2025 at 8:07 PM Russell Coker <[email protected]> wrote: > > > On Sunday, 2 November 2025 12:28:21 AEDT Russell Coker wrote: > > > > The above is what apparently used to be the policy so it looks like > > > > node_t > > > > is being changed to sysctl_t. > > > > > > allow sshd_t sysctl_t:tcp_socket node_bind; > > > > > > I also tried rebooting a VM running that policy (previously I had loaded > > > it on a running system) and got the same result with TCP as an > > > additional issue. > > > > > > Also I tried kernel 6.12.48+deb13-amd64 (the latest kernel for > > > Debian/Trixie the latest stable release). > > > > My apologies, please revert. Due to differences between Fedora selinux > > policy and refpolicy, I did NOT test loading of the patched refpolicy > > itself but instead manually patched the base module (i.e. semodule -cE > > base, edit base.cil to remove the CIL sidcontext statements for the > > "UNKNOWN*" sids, then semodule -i base.cil) and tested that behavior, > > which worked correctly. Looking at the generated base module from the > > patched refpolicy, it is removed not only the sidcontext statements > > but also the sid declarations and omitting them from the sidorder > > statement, thereby perturbing the SID assignments. Not yet sure where > > this is happening in refpolicy build. > > Ok, if I semodule_unpackage base.pp base.mod and dismod base.mod, then > select 0 (Display initial SIDs), I see the initial SIDs with the > expected SID values and gaps for those that lack a context. But if I > run checkmodule -C -o base.cil base.mod, the resulting CIL file omits > any SID declarations that lack a context and therefore ends up > renumbering them when they are compiled into a kernel policy. I reverted the patch. We can reapply it once a fix for this is in a release checkpolicy. -- Chris PeBenito