Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
libsepol/cil: Check common perms when verifiying "all"
Commit e81c466 "Fix class permission verification in CIL", added a check for the use of "all" in a permission expression for a class that had no permissions. Unfortunately, that change did not take into account a class that had common permissions, so a class that has no permmissions of its own, but inherits permissions from a common, will fail the verification check. If the class inherits from a common, then add those permissions to the permmission list when verifying the permission expression. Example/ (common co1 (cop1)) (class cl1 ()) (classcommon cl1 co1) (classorder (CLASS cl1)) (classpermission cp1) (classpermissionset cp1 (cl1 (all))) (classmap cm1 (cmp1)) (classmapping cm1 cmp1 (cl1 (all))) Previously, both the classpermissionset and the classmapping rules would fail verification, but now they pass as expected. Patch originally from Ben Cressey <[email protected]>, I have expanded the explanation. Reported-by: Ben Cressey <[email protected]> Signed-off-by: James Carter <[email protected]>
- Loading branch information