Bug 924107
| Summary: | --newtype policy generated by sepolicy generate is empty | ||||||
|---|---|---|---|---|---|---|---|
| Product: | Red Hat Enterprise Linux 7 | Reporter: | Michal Trunecka <mtruneck> | ||||
| Component: | policycoreutils | Assignee: | Miroslav Grepl <mgrepl> | ||||
| Status: | CLOSED CURRENTRELEASE | QA Contact: | Michal Trunecka <mtruneck> | ||||
| Severity: | medium | Docs Contact: | |||||
| Priority: | medium | ||||||
| Version: | 7.0 | CC: | dwalsh, ebenes, mgrepl, mmalik | ||||
| Target Milestone: | rc | ||||||
| Target Release: | --- | ||||||
| Hardware: | All | ||||||
| OS: | Linux | ||||||
| Whiteboard: | |||||||
| Fixed In Version: | Doc Type: | Bug Fix | |||||
| Doc Text: | Story Points: | --- | |||||
| Clone Of: | Environment: | ||||||
| Last Closed: | 2014-06-13 10:56:06 UTC | Type: | Bug | ||||
| Regression: | --- | Mount Type: | --- | ||||
| Documentation: | --- | CRM: | |||||
| Verified Versions: | Category: | --- | |||||
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |||||
| Cloudforms Team: | --- | Target Upstream Version: | |||||
| Embargoed: | |||||||
| Bug Depends On: | |||||||
| Bug Blocks: | 917049 | ||||||
| Attachments: |
|
||||||
|
Description
Michal Trunecka
2013-03-21 08:37:57 UTC
The newline is missing in all generated .if files where no interface is defined (and the .te file is sane), which causes following error when compiling: m4:testpolicy.if:2: ERROR: end of file in comment Another additional info - when used --newtype with -w parameter, the policy is not empty, but it still doesn't contain the module macro, so the compilation fails: testpolicy.te":3:ERROR 'Building a policy module, but no module specification found. ' at token 'type' on line 981: Yes, I see a bug. Fixed in policycoreutils-2.1.14-28.el7 The empty module problem is fixed, but there is still the issue, that if no interface is defined in .if file, running setup script will throw an error: m4:testpolicy.if:2: ERROR: end of file in comment Although it's not fatal, I believe policy generated by our tools shouldn't do that. Can be reproduced by following command: sepolicy generate -n mypolicy -d httpd_sys_script_t --customize; ./mypolicy.sh | grep ERROR Created attachment 747545 [details]
policycoreutils-templates_executable.patch
You can re-test it with the following patch.
Yes, it works. Now I see the bug is not completely fixed. The policies generated by --newtype are missing module header, so the setup script fails with errors:
# sepolicy generate -n testpolicy --newtype -t newtype_var_run_t
...
# cat testpolicy.te
type newtype_var_run_t;
files_pid_file(newtype_var_run_t)
########################################
#
# testpolicy local policy
#
manage_dirs_pattern(newtype_t, newtype_var_run_t, newtype_var_run_t)
manage_files_pattern(newtype_t, newtype_var_run_t, newtype_var_run_t)
manage_lnk_files_pattern(newtype_t, newtype_var_run_t, newtype_var_run_t)
files_pid_filetrans(newtype_t, newtype_var_run_t, { dir file lnk_file })
# ./testpolicy.sh
Building and Loading Policy
+ make -f /usr/share/selinux/devel/Makefile testpolicy.pp
make[1]: Entering directory `/root/policycoreutils/Sanity/sepolicy-generate /mypolicy'
Compiling targeted testpolicy module
/usr/bin/checkmodule: loading policy configuration from tmp/testpolicy.tmp
testpolicy.te":3:ERROR 'Building a policy module, but no module specification found.
' at token 'type' on line 981:
type newtype_var_run_t;
/usr/bin/checkmodule: error(s) encountered while parsing configuration
make[1]: *** [tmp/testpolicy.mod] Error 1
make[1]: Leaving directory `/root/policycoreutils/Sanity/sepolicy-generate/mypolicy'
+ exit
Ok, we should not generate *.sh script for --newtype at all. Well, it depends on the expected purpose of the --newtype option.
And here is next --newtype fail, to not file extra bug for it:
# sepolicy generate -p mypolicy -w /home -n testpolicy --newtype -t newtype_port_t
Traceback (most recent call last):
File "/usr/bin/sepolicy", line 568, in <module>
args.func(args)
File "/usr/bin/sepolicy", line 448, in generate
print mypolicy.generate(args.path)
File "/usr/lib64/python2.7/site-packages/sepolicy/generate.py", line 1351, in generate
out += "%s # %s\n" % (self.write_te(out_dir), _("Type Enforcement file"))
File "/usr/lib64/python2.7/site-packages/sepolicy/generate.py", line 1216, in write_te
fd.write(self.generate_te())
File "/usr/lib64/python2.7/site-packages/sepolicy/generate.py", line 1040, in generate_te
newte += self.generate_default_rules()
File "/usr/lib64/python2.7/site-packages/sepolicy/generate.py", line 1005, in generate_default_rules
return self.DEFAULT_TYPES[self.type][1]()
File "/usr/lib64/python2.7/site-packages/sepolicy/generate.py", line 878, in generate_new_rules
newte += re.sub("TEMPLATETYPE", t[:-len(i)], self.DEFAULT_EXT[i].te_rules)
AttributeError: 'module' object has no attribute 'te_rules'
Well, --newtype is just about a new type which then should be used in the <whatever>.te. Fixed in policycoreutils-2.1.14-63.el7 The setup shell script is still generated with --newtype option. policycoreutils-2.1.14-65 Should remove spec file and shell script. This request was resolved in Red Hat Enterprise Linux 7.0. Contact your manager or support representative in case you have further questions about the request. |