Re: [PATCH v2] python/sepolicy: add missing socket template attributes
James Carter <[email protected]>
| Newsgroups | org.kernel.vger.selinux |
|---|---|
| Message-ID | <CAP+JOzSLLAAWHbQFvj53F0uN1B0VYn2ZM=b3=jF+n3dXfx3LPw@mail.gmail.com> |
On Fri, Aug 14, 2026 at 10:29 AM Stephen Smalley <[email protected]> wrote: > > generate_fc() unconditionally reads template.fc_sock_file for any > path that stat()s as a socket, but only var_run, var_lib and rw > define it, so selecting a socket under /tmp, /etc, /var/cache, > /var/spool, /var/log or a systemd unit directory in the GUI raises > > AttributeError: module 'sepolicy.templates.tmp' has no > attribute 'fc_sock_file' > > The tmp template has no fc_* attributes at all, so any explicitly > added file or directory under /tmp fails the same way on fc_file / > fc_dir. generate_te() and generate_if() likewise read > te_stream_rules / if_stream_rules for a socket path, which var_log > and unit_file lack. > > Add fc_sock_file to every template that already has fc_file (using > the -s file class), give tmp a full fc_file / fc_sock_file / fc_dir > set for TEMPLATETYPE_tmp_t, and add empty stream-rule strings to > var_log and unit_file so a stray socket there no longer takes the > whole generator down. > > Fixes: https://github.com/SELinuxProject/selinux/issues/379 > Signed-off-by: Stephen Smalley <[email protected]> Oops, Ack'd the wrong patch. Acked-by: James Carter <[email protected]> > --- > v2 changes the fc_sock_file definition in the > unit_file template to the empty string since there shouldn't > be any sockets with those types. > > python/sepolicy/sepolicy/templates/etc_rw.py | 4 ++++ > python/sepolicy/sepolicy/templates/tmp.py | 13 +++++++++++++ > python/sepolicy/sepolicy/templates/unit_file.py | 6 ++++++ > python/sepolicy/sepolicy/templates/var_cache.py | 4 ++++ > python/sepolicy/sepolicy/templates/var_log.py | 8 ++++++++ > python/sepolicy/sepolicy/templates/var_spool.py | 4 ++++ > 6 files changed, 39 insertions(+) > > diff --git a/python/sepolicy/sepolicy/templates/etc_rw.py b/python/sepolicy/sepolicy/templates/etc_rw.py > index dcf445e0..c78d64a2 100644 > --- a/python/sepolicy/sepolicy/templates/etc_rw.py > +++ b/python/sepolicy/sepolicy/templates/etc_rw.py > @@ -134,6 +134,10 @@ fc_file="""\ > FILENAME -- gen_context(system_u:object_r:TEMPLATETYPE_etc_rw_t,s0) > """ > > +fc_sock_file="""\ > +FILENAME -s gen_context(system_u:object_r:TEMPLATETYPE_etc_rw_t,s0) > +""" > + > fc_dir="""\ > FILENAME(/.*)? gen_context(system_u:object_r:TEMPLATETYPE_etc_rw_t,s0) > """ > diff --git a/python/sepolicy/sepolicy/templates/tmp.py b/python/sepolicy/sepolicy/templates/tmp.py > index c000a75e..54ed1803 100644 > --- a/python/sepolicy/sepolicy/templates/tmp.py > +++ b/python/sepolicy/sepolicy/templates/tmp.py > @@ -127,3 +127,16 @@ if_admin_rules=""" > files_search_tmp($1) > admin_pattern($1, TEMPLATETYPE_tmp_t) > """ > + > +########################### File Context ################################## > +fc_file="""\ > +FILENAME -- gen_context(system_u:object_r:TEMPLATETYPE_tmp_t,s0) > +""" > + > +fc_sock_file="""\ > +FILENAME -s gen_context(system_u:object_r:TEMPLATETYPE_tmp_t,s0) > +""" > + > +fc_dir="""\ > +FILENAME(/.*)? gen_context(system_u:object_r:TEMPLATETYPE_tmp_t,s0) > +""" > diff --git a/python/sepolicy/sepolicy/templates/unit_file.py b/python/sepolicy/sepolicy/templates/unit_file.py > index e26f5e2a..6d72dcd3 100644 > --- a/python/sepolicy/sepolicy/templates/unit_file.py > +++ b/python/sepolicy/sepolicy/templates/unit_file.py > @@ -66,9 +66,15 @@ if_admin_rules=""" > allow $1 TEMPLATETYPE_unit_file_t:service all_service_perms; > """ > > +te_stream_rules = "" > + > +if_stream_rules = "" > + > ########################### File Context ################################## > fc_file="""\ > FILENAME -- gen_context(system_u:object_r:TEMPLATETYPE_unit_file_t,s0) > """ > > +fc_sock_file = "" > + > fc_dir="" > diff --git a/python/sepolicy/sepolicy/templates/var_cache.py b/python/sepolicy/sepolicy/templates/var_cache.py > index 37897231..5a147896 100644 > --- a/python/sepolicy/sepolicy/templates/var_cache.py > +++ b/python/sepolicy/sepolicy/templates/var_cache.py > @@ -152,6 +152,10 @@ fc_file="""\ > FILENAME -- gen_context(system_u:object_r:TEMPLATETYPE_cache_t,s0) > """ > > +fc_sock_file="""\ > +FILENAME -s gen_context(system_u:object_r:TEMPLATETYPE_cache_t,s0) > +""" > + > fc_dir="""\ > FILENAME(/.*)? gen_context(system_u:object_r:TEMPLATETYPE_cache_t,s0) > """ > diff --git a/python/sepolicy/sepolicy/templates/var_log.py b/python/sepolicy/sepolicy/templates/var_log.py > index 371dd7e4..051a0f1e 100644 > --- a/python/sepolicy/sepolicy/templates/var_log.py > +++ b/python/sepolicy/sepolicy/templates/var_log.py > @@ -106,10 +106,18 @@ if_admin_rules=""" > """ > > ########################### File Context ################################## > +te_stream_rules = "" > + > +if_stream_rules = "" > + > fc_file="""\ > FILENAME -- gen_context(system_u:object_r:TEMPLATETYPE_log_t,s0) > """ > > +fc_sock_file="""\ > +FILENAME -s gen_context(system_u:object_r:TEMPLATETYPE_log_t,s0) > +""" > + > fc_dir="""\ > FILENAME(/.*)? gen_context(system_u:object_r:TEMPLATETYPE_log_t,s0) > """ > diff --git a/python/sepolicy/sepolicy/templates/var_spool.py b/python/sepolicy/sepolicy/templates/var_spool.py > index dccb5f16..84933f50 100644 > --- a/python/sepolicy/sepolicy/templates/var_spool.py > +++ b/python/sepolicy/sepolicy/templates/var_spool.py > @@ -151,6 +151,10 @@ fc_file="""\ > FILENAME -- gen_context(system_u:object_r:TEMPLATETYPE_spool_t,s0) > """ > > +fc_sock_file="""\ > +FILENAME -s gen_context(system_u:object_r:TEMPLATETYPE_spool_t,s0) > +""" > + > fc_dir="""\ > FILENAME(/.*)? gen_context(system_u:object_r:TEMPLATETYPE_spool_t,s0) > """ > -- > 2.55.0 >