Note: This bug is displayed in read-only format because the product is no longer active in Red Hat Bugzilla.
RHEL Engineering is moving the tracking of its product development work on RHEL 6 through RHEL 9 to Red Hat Jira (issues.redhat.com). If you're a Red Hat customer, please continue to file support cases via the Red Hat customer portal. If you're not, please head to the "RHEL project" in Red Hat Jira and file new tickets here. Individual Bugzilla bugs in the statuses "NEW", "ASSIGNED", and "POST" are being migrated throughout September 2023. Bugs of Red Hat partners with an assigned Engineering Partner Manager (EPM) are migrated in late September as per pre-agreed dates. Bugs against components "kernel", "kernel-rt", and "kpatch" are only migrated if still in "NEW" or "ASSIGNED". If you cannot log in to RH Jira, please consult article #7032570. That failing, please send an e-mail to the RH Jira admins at rh-issues@redhat.com to troubleshoot your issue as a user management inquiry. The email creates a ServiceNow ticket with Red Hat. Individual Bugzilla bugs that are migrated will be moved to status "CLOSED", resolution "MIGRATED", and set with "MigratedToJIRA" in "Keywords". The link to the successor Jira issue will be found under "Links", have a little "two-footprint" icon next to it, and direct you to the "RHEL project" in Red Hat Jira (issue links are of type "https://issues.redhat.com/browse/RHEL-XXXX", where "X" is a digit). This same link will be available in a blue banner at the top of the page informing you that that bug has been migrated.

Bug 924107

Summary: --newtype policy generated by sepolicy generate is empty
Product: Red Hat Enterprise Linux 7 Reporter: Michal Trunecka <mtruneck>
Component: policycoreutilsAssignee: Miroslav Grepl <mgrepl>
Status: CLOSED CURRENTRELEASE QA Contact: Michal Trunecka <mtruneck>
Severity: medium Docs Contact:
Priority: medium    
Version: 7.0CC: dwalsh, ebenes, mgrepl, mmalik
Target Milestone: rc   
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2014-06-13 10:56:06 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On:    
Bug Blocks: 917049    
Attachments:
Description Flags
policycoreutils-templates_executable.patch none

Description Michal Trunecka 2013-03-21 08:37:57 UTC
Description of problem:

The policy generated by the command:
 # sepolicy generate --newtype -t newtype_t
is empty (The -t option may be used incorrectly, as it is not described in documentation - See Bug 924105)


Version-Release number of selected component (if applicable):
policycoreutils-python-2.1.14-23.el7.x86_64


Steps to reproduce:

# sepolicy generate --newtype -n mypolicy -t newtype_t
Created the following files:
/root/policies/mypolicy.te # Type Enforcement file
/root/policies/mypolicy.if # Interface file
/root/policies/mypolicy.fc # File Contexts file
/root/policies/mypolicy_selinux.spec # Spec file
/root/policies/mypolicy.sh # Setup Script

# cat mypolicy.te 

########################################
#
# mypolicy local policy
#
# cat mypolicy.if 

## <summary>policy for mypolicy</summary> # <<<<<< missing end of line___
[root@dhcp-25-105 policies]# 
[root@dhcp-25-105 policies]# cat mypolicy.fc 
[root@dhcp-25-105 policies]#

Comment 1 Michal Trunecka 2013-03-22 09:12:12 UTC
The newline is missing in all generated .if files where no interface is defined (and the .te file is sane), which causes following error when compiling:

m4:testpolicy.if:2: ERROR: end of file in comment

Comment 2 Michal Trunecka 2013-03-25 10:07:25 UTC
Another additional info - when used --newtype with -w parameter, the policy is not empty, but it still doesn't contain the module macro, so the compilation fails:

testpolicy.te":3:ERROR 'Building a policy module, but no module specification found.
' at token 'type' on line 981:

Comment 3 Miroslav Grepl 2013-03-26 13:11:37 UTC
Yes, I see a bug.

Comment 4 Miroslav Grepl 2013-03-27 18:19:29 UTC
Fixed in policycoreutils-2.1.14-28.el7

Comment 5 Michal Trunecka 2013-05-14 07:12:53 UTC
The empty module problem is fixed, but there is still the issue, that if no interface is defined in .if file, running setup script will throw an error:

m4:testpolicy.if:2: ERROR: end of file in comment

Although it's not fatal, I believe policy generated by our tools shouldn't do that.

Comment 6 Michal Trunecka 2013-05-14 07:33:49 UTC
Can be reproduced by following command:

sepolicy generate -n mypolicy -d httpd_sys_script_t --customize;  ./mypolicy.sh | grep ERROR

Comment 7 Miroslav Grepl 2013-05-14 07:52:06 UTC
Created attachment 747545 [details]
policycoreutils-templates_executable.patch

You can re-test it with the following patch.

Comment 8 Michal Trunecka 2013-05-14 08:02:14 UTC
Yes, it works.

Comment 9 Michal Trunecka 2013-05-14 11:52:18 UTC
  Now I see the bug is not completely fixed. The policies generated by --newtype are missing module header, so the setup script fails with errors:


# sepolicy generate -n testpolicy --newtype -t newtype_var_run_t 
  ...
# cat testpolicy.te

  type newtype_var_run_t;
  files_pid_file(newtype_var_run_t)
  
  ########################################
  #
  # testpolicy local policy
  #

  manage_dirs_pattern(newtype_t, newtype_var_run_t, newtype_var_run_t)
  manage_files_pattern(newtype_t, newtype_var_run_t, newtype_var_run_t)
  manage_lnk_files_pattern(newtype_t, newtype_var_run_t, newtype_var_run_t)
  files_pid_filetrans(newtype_t, newtype_var_run_t, { dir file lnk_file })

# ./testpolicy.sh

  Building and Loading Policy
  + make -f /usr/share/selinux/devel/Makefile testpolicy.pp
  make[1]: Entering directory `/root/policycoreutils/Sanity/sepolicy-generate  /mypolicy'
  Compiling targeted testpolicy module
  /usr/bin/checkmodule:  loading policy configuration from tmp/testpolicy.tmp
  testpolicy.te":3:ERROR 'Building a policy module, but no module specification found.
  ' at token 'type' on line 981:

  type newtype_var_run_t;
  /usr/bin/checkmodule:  error(s) encountered while parsing configuration
  make[1]: *** [tmp/testpolicy.mod] Error 1
  make[1]: Leaving directory `/root/policycoreutils/Sanity/sepolicy-generate/mypolicy'
  + exit

Comment 10 Miroslav Grepl 2013-05-14 12:22:26 UTC
Ok, we should not generate *.sh script for --newtype at all.

Comment 11 Michal Trunecka 2013-05-14 12:29:08 UTC
Well, it depends on the expected purpose of the --newtype option.


And here is next --newtype fail, to not file extra bug for it:

# sepolicy generate -p mypolicy -w /home   -n testpolicy --newtype -t newtype_port_t
Traceback (most recent call last):
  File "/usr/bin/sepolicy", line 568, in <module>
    args.func(args)
  File "/usr/bin/sepolicy", line 448, in generate
    print mypolicy.generate(args.path)
  File "/usr/lib64/python2.7/site-packages/sepolicy/generate.py", line 1351, in generate
    out += "%s # %s\n" % (self.write_te(out_dir), _("Type Enforcement file"))
  File "/usr/lib64/python2.7/site-packages/sepolicy/generate.py", line 1216, in write_te
    fd.write(self.generate_te())
  File "/usr/lib64/python2.7/site-packages/sepolicy/generate.py", line 1040, in generate_te
    newte += self.generate_default_rules()
  File "/usr/lib64/python2.7/site-packages/sepolicy/generate.py", line 1005, in generate_default_rules
    return self.DEFAULT_TYPES[self.type][1]()
  File "/usr/lib64/python2.7/site-packages/sepolicy/generate.py", line 878, in generate_new_rules
    newte += re.sub("TEMPLATETYPE", t[:-len(i)], self.DEFAULT_EXT[i].te_rules)
AttributeError: 'module' object has no attribute 'te_rules'

Comment 12 Miroslav Grepl 2013-05-14 13:05:44 UTC
Well, --newtype is just about a new type which then should be used in the <whatever>.te.

Comment 13 Daniel Walsh 2013-07-11 22:23:49 UTC
Fixed in policycoreutils-2.1.14-63.el7

Comment 14 Michal Trunecka 2013-07-16 12:01:52 UTC
The setup shell script is still generated with --newtype option.

Comment 15 Daniel Walsh 2013-07-16 15:56:30 UTC
 policycoreutils-2.1.14-65

Should remove spec file and shell script.

Comment 17 Ludek Smid 2014-06-13 10:56:06 UTC
This request was resolved in Red Hat Enterprise Linux 7.0.

Contact your manager or support representative in case you have further questions about the request.