Re: [PATCH v2] python/sepolicy: add missing socket template attributes

James Carter <[email protected]>
Newsgroups org.kernel.vger.selinux
Message-ID <CAP+JOzSLLAAWHbQFvj53F0uN1B0VYn2ZM=b3=jF+n3dXfx3LPw@mail.gmail.com>
On Fri, Aug 14, 2026 at 10:29 AM Stephen Smalley
<[email protected]> wrote:
>
> generate_fc() unconditionally reads template.fc_sock_file for any
> path that stat()s as a socket, but only var_run, var_lib and rw
> define it, so selecting a socket under /tmp, /etc, /var/cache,
> /var/spool, /var/log or a systemd unit directory in the GUI raises
>
>   AttributeError: module 'sepolicy.templates.tmp' has no
>   attribute 'fc_sock_file'
>
> The tmp template has no fc_* attributes at all, so any explicitly
> added file or directory under /tmp fails the same way on fc_file /
> fc_dir.  generate_te() and generate_if() likewise read
> te_stream_rules / if_stream_rules for a socket path, which var_log
> and unit_file lack.
>
> Add fc_sock_file to every template that already has fc_file (using
> the -s file class), give tmp a full fc_file / fc_sock_file / fc_dir
> set for TEMPLATETYPE_tmp_t, and add empty stream-rule strings to
> var_log and unit_file so a stray socket there no longer takes the
> whole generator down.
>
> Fixes: https://github.com/SELinuxProject/selinux/issues/379
> Signed-off-by: Stephen Smalley <[email protected]>

Oops, Ack'd the wrong patch.

Acked-by: James Carter <[email protected]>

> ---
> v2 changes the fc_sock_file definition in the
> unit_file template to the empty string since there shouldn't
> be any sockets with those types.
>
>  python/sepolicy/sepolicy/templates/etc_rw.py    |  4 ++++
>  python/sepolicy/sepolicy/templates/tmp.py       | 13 +++++++++++++
>  python/sepolicy/sepolicy/templates/unit_file.py |  6 ++++++
>  python/sepolicy/sepolicy/templates/var_cache.py |  4 ++++
>  python/sepolicy/sepolicy/templates/var_log.py   |  8 ++++++++
>  python/sepolicy/sepolicy/templates/var_spool.py |  4 ++++
>  6 files changed, 39 insertions(+)
>
> diff --git a/python/sepolicy/sepolicy/templates/etc_rw.py b/python/sepolicy/sepolicy/templates/etc_rw.py
> index dcf445e0..c78d64a2 100644
> --- a/python/sepolicy/sepolicy/templates/etc_rw.py
> +++ b/python/sepolicy/sepolicy/templates/etc_rw.py
> @@ -134,6 +134,10 @@ fc_file="""\
>  FILENAME               --      gen_context(system_u:object_r:TEMPLATETYPE_etc_rw_t,s0)
>  """
>
> +fc_sock_file="""\
> +FILENAME               -s      gen_context(system_u:object_r:TEMPLATETYPE_etc_rw_t,s0)
> +"""
> +
>  fc_dir="""\
>  FILENAME(/.*)?         gen_context(system_u:object_r:TEMPLATETYPE_etc_rw_t,s0)
>  """
> diff --git a/python/sepolicy/sepolicy/templates/tmp.py b/python/sepolicy/sepolicy/templates/tmp.py
> index c000a75e..54ed1803 100644
> --- a/python/sepolicy/sepolicy/templates/tmp.py
> +++ b/python/sepolicy/sepolicy/templates/tmp.py
> @@ -127,3 +127,16 @@ if_admin_rules="""
>         files_search_tmp($1)
>         admin_pattern($1, TEMPLATETYPE_tmp_t)
>  """
> +
> +########################### File Context ##################################
> +fc_file="""\
> +FILENAME               --      gen_context(system_u:object_r:TEMPLATETYPE_tmp_t,s0)
> +"""
> +
> +fc_sock_file="""\
> +FILENAME               -s      gen_context(system_u:object_r:TEMPLATETYPE_tmp_t,s0)
> +"""
> +
> +fc_dir="""\
> +FILENAME(/.*)?         gen_context(system_u:object_r:TEMPLATETYPE_tmp_t,s0)
> +"""
> diff --git a/python/sepolicy/sepolicy/templates/unit_file.py b/python/sepolicy/sepolicy/templates/unit_file.py
> index e26f5e2a..6d72dcd3 100644
> --- a/python/sepolicy/sepolicy/templates/unit_file.py
> +++ b/python/sepolicy/sepolicy/templates/unit_file.py
> @@ -66,9 +66,15 @@ if_admin_rules="""
>         allow $1 TEMPLATETYPE_unit_file_t:service all_service_perms;
>  """
>
> +te_stream_rules = ""
> +
> +if_stream_rules = ""
> +
>  ########################### File Context ##################################
>  fc_file="""\
>  FILENAME               --      gen_context(system_u:object_r:TEMPLATETYPE_unit_file_t,s0)
>  """
>
> +fc_sock_file = ""
> +
>  fc_dir=""
> diff --git a/python/sepolicy/sepolicy/templates/var_cache.py b/python/sepolicy/sepolicy/templates/var_cache.py
> index 37897231..5a147896 100644
> --- a/python/sepolicy/sepolicy/templates/var_cache.py
> +++ b/python/sepolicy/sepolicy/templates/var_cache.py
> @@ -152,6 +152,10 @@ fc_file="""\
>  FILENAME               --      gen_context(system_u:object_r:TEMPLATETYPE_cache_t,s0)
>  """
>
> +fc_sock_file="""\
> +FILENAME               -s      gen_context(system_u:object_r:TEMPLATETYPE_cache_t,s0)
> +"""
> +
>  fc_dir="""\
>  FILENAME(/.*)?         gen_context(system_u:object_r:TEMPLATETYPE_cache_t,s0)
>  """
> diff --git a/python/sepolicy/sepolicy/templates/var_log.py b/python/sepolicy/sepolicy/templates/var_log.py
> index 371dd7e4..051a0f1e 100644
> --- a/python/sepolicy/sepolicy/templates/var_log.py
> +++ b/python/sepolicy/sepolicy/templates/var_log.py
> @@ -106,10 +106,18 @@ if_admin_rules="""
>  """
>
>  ########################### File Context ##################################
> +te_stream_rules = ""
> +
> +if_stream_rules = ""
> +
>  fc_file="""\
>  FILENAME               --      gen_context(system_u:object_r:TEMPLATETYPE_log_t,s0)
>  """
>
> +fc_sock_file="""\
> +FILENAME               -s      gen_context(system_u:object_r:TEMPLATETYPE_log_t,s0)
> +"""
> +
>  fc_dir="""\
>  FILENAME(/.*)?         gen_context(system_u:object_r:TEMPLATETYPE_log_t,s0)
>  """
> diff --git a/python/sepolicy/sepolicy/templates/var_spool.py b/python/sepolicy/sepolicy/templates/var_spool.py
> index dccb5f16..84933f50 100644
> --- a/python/sepolicy/sepolicy/templates/var_spool.py
> +++ b/python/sepolicy/sepolicy/templates/var_spool.py
> @@ -151,6 +151,10 @@ fc_file="""\
>  FILENAME               --      gen_context(system_u:object_r:TEMPLATETYPE_spool_t,s0)
>  """
>
> +fc_sock_file="""\
> +FILENAME               -s      gen_context(system_u:object_r:TEMPLATETYPE_spool_t,s0)
> +"""
> +
>  fc_dir="""\
>  FILENAME(/.*)?         gen_context(system_u:object_r:TEMPLATETYPE_spool_t,s0)
>  """
> --
> 2.55.0
>
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.