[PATCH] libsepol/cil: Output culprit rules from binary policy when CIL AST match fails

"Thiébaud Weksteen" <[email protected]>
Newsgroups org.kernel.vger.selinux
Message-ID <[email protected]>
Commit d8507429f15c ("secilc: Add program that checks CIL neverallows
against a binary policy") added secilcheck to validate neverallows against
a binary policy.

When a violation occurs, secilcheck attempts to locate matching allow
rules in the CIL AST. However, since the CIL AST in secilcheck only
contains neverallow rules and declarations (not allow rules),
cil_find_matching_avrule_in_ast() returns an empty set, resulting in no
culprit allow rules being printed.

Fall back to calling report_assertion_failures() to output the culprit
allow rules from the binary policydb when no matching rules are found in
the CIL AST.

Signed-off-by: Thiébaud Weksteen <[email protected]>
---
 libsepol/cil/src/cil_binary.c              | 16 +++++++++++++---
 libsepol/include/sepol/policydb/policydb.h |  2 ++
 libsepol/src/assertion.c                   |  4 ++--
 3 files changed, 17 insertions(+), 5 deletions(-)

diff --git a/libsepol/cil/src/cil_binary.c b/libsepol/cil/src/cil_binary.c
index 7ec3e781..e99405b4 100644
--- a/libsepol/cil/src/cil_binary.c
+++ b/libsepol/cil/src/cil_binary.c
@@ -5563,7 +5563,9 @@ static void __cil_print_rule(const char *pad, const char *kind,
 }
 
 static int __cil_print_neverallow_failure(const struct cil_db *db,
-					  struct cil_tree_node *node)
+					  policydb_t *pdb,
+					  struct cil_tree_node *node,
+					  const avrule_t *rule)
 {
 	int rc;
 	struct cil_list_item *i2;
@@ -5609,6 +5611,12 @@ static int __cil_print_neverallow_failure(const struct cil_db *db,
 	cil_list_for_each(i2, matching) {
 		num_matching++;
 	}
+	if (num_matching == 0 && pdb != NULL && rule != NULL) {
+		int res = report_assertion_failures(NULL, pdb, rule);
+		if (res < 0) {
+			rc = res;
+		}
+	}
 	cil_list_for_each(i2, matching) {
 		n2 = i2->data;
 		r2 = n2->data;
@@ -5683,7 +5691,8 @@ static int cil_check_neverallow(const struct cil_db *db, policydb_t *pdb,
 		rc = check_assertion(pdb, rule);
 		if (rc == CIL_TRUE) {
 			*violation = CIL_TRUE;
-			rc = __cil_print_neverallow_failure(db, node);
+			rc = __cil_print_neverallow_failure(db, pdb, node,
+							    rule);
 			if (rc != SEPOL_OK) {
 				goto exit;
 			}
@@ -5708,7 +5717,8 @@ static int cil_check_neverallow(const struct cil_db *db, policydb_t *pdb,
 			rc = check_assertion(pdb, rule);
 			if (rc == CIL_TRUE) {
 				*violation = CIL_TRUE;
-				rc = __cil_print_neverallow_failure(db, node);
+				rc = __cil_print_neverallow_failure(db, pdb,
+								    node, rule);
 				if (rc != SEPOL_OK) {
 					goto exit;
 				}
diff --git a/libsepol/include/sepol/policydb/policydb.h b/libsepol/include/sepol/policydb/policydb.h
index a1b5e99b..cf14e26a 100644
--- a/libsepol/include/sepol/policydb/policydb.h
+++ b/libsepol/include/sepol/policydb/policydb.h
@@ -714,6 +714,8 @@ extern void cat_datum_destroy(cat_datum_t *x);
 extern int check_assertion(policydb_t *p, const avrule_t *avrule);
 extern int check_assertions(sepol_handle_t *handle, policydb_t *p,
 			    const avrule_t *avrules);
+extern int report_assertion_failures(sepol_handle_t *handle, policydb_t *p,
+				     const avrule_t *narule);
 
 extern int symtab_insert(policydb_t *x, uint32_t sym, hashtab_key_t key,
 			 hashtab_datum_t datum, uint32_t scope,
diff --git a/libsepol/src/assertion.c b/libsepol/src/assertion.c
index 8f829e7d..94172e5a 100644
--- a/libsepol/src/assertion.c
+++ b/libsepol/src/assertion.c
@@ -504,8 +504,8 @@ exit:
 	return rc;
 }
 
-static int report_assertion_failures(sepol_handle_t *handle, policydb_t *p,
-				     const avrule_t *narule)
+int report_assertion_failures(sepol_handle_t *handle, policydb_t *p,
+			      const avrule_t *narule)
 {
 	int rc;
 	struct avtab_match_args args = {
-- 
2.55.0.679.g6767b8d81c-goog
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.