Compare commits
3 commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
56091d64c2 | ||
|
|
c3420615fe | ||
|
|
dd3e42f544 |
5 changed files with 127 additions and 2 deletions
27
0008-Revert-sepolgen-ifgen-allow-M4-escaped-filenames.patch
Normal file
27
0008-Revert-sepolgen-ifgen-allow-M4-escaped-filenames.patch
Normal file
|
|
@ -0,0 +1,27 @@
|
||||||
|
From ff715249c75afc5ef83a57351f267e2bdaf49e10 Mon Sep 17 00:00:00 2001
|
||||||
|
From: Petr Lautrbach <lautrbach@redhat.com>
|
||||||
|
Date: Thu, 19 Dec 2024 15:29:59 +0100
|
||||||
|
Subject: [PATCH] Revert "sepolgen-ifgen: allow M4 escaped filenames"
|
||||||
|
Content-type: text/plain
|
||||||
|
|
||||||
|
This reverts commit 97ca3b1df253a78c54ebdd6cec01f0d03ff1393c.
|
||||||
|
---
|
||||||
|
python/sepolgen/src/sepolgen/refparser.py | 2 +-
|
||||||
|
1 file changed, 1 insertion(+), 1 deletion(-)
|
||||||
|
|
||||||
|
diff --git a/python/sepolgen/src/sepolgen/refparser.py b/python/sepolgen/src/sepolgen/refparser.py
|
||||||
|
index 9622ee9a29ce..e261d3f78f87 100644
|
||||||
|
--- a/python/sepolgen/src/sepolgen/refparser.py
|
||||||
|
+++ b/python/sepolgen/src/sepolgen/refparser.py
|
||||||
|
@@ -261,7 +261,7 @@ def t_IDENTIFIER(t):
|
||||||
|
return t
|
||||||
|
|
||||||
|
def t_FILENAME(t):
|
||||||
|
- r'\"`*[a-zA-Z0-9_\-\+\.\$\*~ :\[\]]+\'*\"'
|
||||||
|
+ r'\"[a-zA-Z0-9_\-\+\.\$\*~ :\[\]]+\"'
|
||||||
|
# Handle any keywords
|
||||||
|
t.type = reserved.get(t.value,'FILENAME')
|
||||||
|
return t
|
||||||
|
--
|
||||||
|
2.47.1
|
||||||
|
|
||||||
56
0009-sepolgen-ifgen-allow-M4-escaped-filenames.patch
Normal file
56
0009-sepolgen-ifgen-allow-M4-escaped-filenames.patch
Normal file
|
|
@ -0,0 +1,56 @@
|
||||||
|
From cdfd6ff668293f1b33f3d4b8da678fe0e2088c35 Mon Sep 17 00:00:00 2001
|
||||||
|
From: Petr Lautrbach <lautrbach@redhat.com>
|
||||||
|
Date: Mon, 26 Aug 2024 22:18:35 +0200
|
||||||
|
Subject: [PATCH] sepolgen-ifgen: allow M4 escaped filenames
|
||||||
|
Content-type: text/plain
|
||||||
|
|
||||||
|
When a file name in type transition rule used in an interface is same as
|
||||||
|
a keyword, it needs to be M4 escaped so that the keyword is not expanded
|
||||||
|
by M4, e.g.
|
||||||
|
|
||||||
|
- filetrans_pattern($1, virt_var_run_t, virtinterfaced_var_run_t, dir, "interface")
|
||||||
|
+ filetrans_pattern($1, virt_var_run_t, virtinterfaced_var_run_t, dir, ``"interface"'')
|
||||||
|
|
||||||
|
But sepolgen-ifgen could not parse such string:
|
||||||
|
|
||||||
|
# sepolgen-ifgen
|
||||||
|
Illegal character '`'
|
||||||
|
|
||||||
|
This change allows M4 escaping inside quoted strings and fixed described
|
||||||
|
problem.
|
||||||
|
|
||||||
|
https://bugzilla.redhat.com/show_bug.cgi?id=2254206
|
||||||
|
|
||||||
|
Signed-off-by: Petr Lautrbach <lautrbach@redhat.com>
|
||||||
|
---
|
||||||
|
python/sepolgen/src/sepolgen/refparser.py | 7 ++++++-
|
||||||
|
1 file changed, 6 insertions(+), 1 deletion(-)
|
||||||
|
|
||||||
|
diff --git a/python/sepolgen/src/sepolgen/refparser.py b/python/sepolgen/src/sepolgen/refparser.py
|
||||||
|
index e261d3f78f87..c8a3eb54d679 100644
|
||||||
|
--- a/python/sepolgen/src/sepolgen/refparser.py
|
||||||
|
+++ b/python/sepolgen/src/sepolgen/refparser.py
|
||||||
|
@@ -486,7 +486,7 @@ def p_interface_call_param(p):
|
||||||
|
| nested_id_set
|
||||||
|
| TRUE
|
||||||
|
| FALSE
|
||||||
|
- | FILENAME
|
||||||
|
+ | quoted_filename
|
||||||
|
'''
|
||||||
|
# Intentionally let single identifiers pass through
|
||||||
|
# List means set, non-list identifier
|
||||||
|
@@ -1027,6 +1027,11 @@ def p_optional_semi(p):
|
||||||
|
| empty'''
|
||||||
|
pass
|
||||||
|
|
||||||
|
+def p_quoted_filename(p):
|
||||||
|
+ '''quoted_filename : TICK quoted_filename SQUOTE
|
||||||
|
+ | FILENAME
|
||||||
|
+ '''
|
||||||
|
+ p[0] = p[1]
|
||||||
|
|
||||||
|
#
|
||||||
|
# Interface to the parser
|
||||||
|
--
|
||||||
|
2.47.1
|
||||||
|
|
||||||
29
0010-sepolgen-initialize-gen_cil.patch
Normal file
29
0010-sepolgen-initialize-gen_cil.patch
Normal file
|
|
@ -0,0 +1,29 @@
|
||||||
|
From cf98a3f2f0ea3d477cc22c19da6ca1bc36422df6 Mon Sep 17 00:00:00 2001
|
||||||
|
From: Dmitry Sharshakov <dmitry.sharshakov@siderolabs.com>
|
||||||
|
Date: Thu, 1 Aug 2024 22:32:40 +0300
|
||||||
|
Subject: [PATCH] sepolgen: initialize gen_cil
|
||||||
|
Content-type: text/plain
|
||||||
|
|
||||||
|
Avoid errors when adding comments to CIL output like in audit2allow
|
||||||
|
|
||||||
|
Signed-off-by: Dmitry Sharshakov <dmitry.sharshakov@siderolabs.com>
|
||||||
|
Acked-by: James Carter <jwcart2@gmail.com>
|
||||||
|
---
|
||||||
|
python/sepolgen/src/sepolgen/refpolicy.py | 1 +
|
||||||
|
1 file changed, 1 insertion(+)
|
||||||
|
|
||||||
|
diff --git a/python/sepolgen/src/sepolgen/refpolicy.py b/python/sepolgen/src/sepolgen/refpolicy.py
|
||||||
|
index 2ec75fbad56a..32278896ce0b 100644
|
||||||
|
--- a/python/sepolgen/src/sepolgen/refpolicy.py
|
||||||
|
+++ b/python/sepolgen/src/sepolgen/refpolicy.py
|
||||||
|
@@ -1217,6 +1217,7 @@ class Comment:
|
||||||
|
self.lines = l
|
||||||
|
else:
|
||||||
|
self.lines = []
|
||||||
|
+ self.gen_cil = False
|
||||||
|
|
||||||
|
def to_string(self):
|
||||||
|
# If there are no lines, treat this as a spacer between
|
||||||
|
--
|
||||||
|
2.49.0
|
||||||
|
|
||||||
|
|
@ -1,3 +1,12 @@
|
||||||
|
* Wed Apr 23 2025 Petr Lautrbach <lautrbach@redhat.com> - 3.7-8
|
||||||
|
- Fix `audit2llow -v` (bz#2361279)
|
||||||
|
|
||||||
|
* Wed Jan 22 2025 Petr Lautrbach <lautrbach@redhat.com> - 3.8-7
|
||||||
|
- Make `rpm` a weak dependency (bz#2338647)
|
||||||
|
|
||||||
|
* Thu Dec 19 2024 Petr Lautrbach <lautrbach@redhat.com> - 3.7-6
|
||||||
|
- Use upstream version of "sepolgen-ifgen: allow M4 escaped filenames"
|
||||||
|
|
||||||
* Wed Nov 13 2024 Petr Lautrbach <lautrbach@redhat.com> - 3.7-5
|
* Wed Nov 13 2024 Petr Lautrbach <lautrbach@redhat.com> - 3.7-5
|
||||||
- fixfiles: use `grep -F` when search in mounts (bz#2323728)
|
- fixfiles: use `grep -F` when search in mounts (bz#2323728)
|
||||||
|
|
||||||
|
|
|
||||||
|
|
@ -11,7 +11,7 @@
|
||||||
Summary: SELinux policy core utilities
|
Summary: SELinux policy core utilities
|
||||||
Name: policycoreutils
|
Name: policycoreutils
|
||||||
Version: 3.7
|
Version: 3.7
|
||||||
Release: 5%{?dist}
|
Release: 8%{?dist}
|
||||||
License: GPL-2.0-or-later
|
License: GPL-2.0-or-later
|
||||||
# https://github.com/SELinuxProject/selinux/wiki/Releases
|
# https://github.com/SELinuxProject/selinux/wiki/Releases
|
||||||
Source0: https://github.com/SELinuxProject/selinux/releases/download/3.7/selinux-3.7.tar.gz
|
Source0: https://github.com/SELinuxProject/selinux/releases/download/3.7/selinux-3.7.tar.gz
|
||||||
|
|
@ -45,6 +45,9 @@ Patch0004: 0004-Use-SHA-2-instead-of-SHA-1.patch
|
||||||
Patch0005: 0005-python-sepolicy-Fix-spec-file-dependencies.patch
|
Patch0005: 0005-python-sepolicy-Fix-spec-file-dependencies.patch
|
||||||
Patch0006: 0006-sepolgen-ifgen-allow-M4-escaped-filenames.patch
|
Patch0006: 0006-sepolgen-ifgen-allow-M4-escaped-filenames.patch
|
||||||
Patch0007: 0007-fixfiles-use-grep-F-when-search-in-mounts.patch
|
Patch0007: 0007-fixfiles-use-grep-F-when-search-in-mounts.patch
|
||||||
|
Patch0008: 0008-Revert-sepolgen-ifgen-allow-M4-escaped-filenames.patch
|
||||||
|
Patch0009: 0009-sepolgen-ifgen-allow-M4-escaped-filenames.patch
|
||||||
|
Patch0010: 0010-sepolgen-initialize-gen_cil.patch
|
||||||
# Patch list end
|
# Patch list end
|
||||||
|
|
||||||
Obsoletes: policycoreutils < 2.0.61-2
|
Obsoletes: policycoreutils < 2.0.61-2
|
||||||
|
|
@ -72,8 +75,9 @@ BuildRequires: python3-devel python3-setuptools python3-wheel python3-pip
|
||||||
BuildRequires: systemd
|
BuildRequires: systemd
|
||||||
BuildRequires: git-core
|
BuildRequires: git-core
|
||||||
BuildRequires: gnupg2
|
BuildRequires: gnupg2
|
||||||
Requires: util-linux grep gawk diffutils rpm sed
|
Requires: util-linux grep gawk diffutils sed
|
||||||
Requires: libsepol >= %{libsepolver} coreutils libselinux-utils >= %{libselinuxver}
|
Requires: libsepol >= %{libsepolver} coreutils libselinux-utils >= %{libselinuxver}
|
||||||
|
Recommends: rpm
|
||||||
|
|
||||||
%description
|
%description
|
||||||
Security-enhanced Linux is a feature of the Linux® kernel and a number
|
Security-enhanced Linux is a feature of the Linux® kernel and a number
|
||||||
|
|
|
||||||
Loading…
Add table
Add a link
Reference in a new issue