All of lore.kernel.org
 help / color / mirror / Atom feed
From: Nicolas Iooss <nicolas.iooss@m4x.org>
To: selinux@vger.kernel.org
Subject: [PATCH 2/2] python/chcat: fix removing categories on users with Fedora default setup
Date: Sun,  9 Dec 2018 15:23:23 +0100	[thread overview]
Message-ID: <20181209142323.21149-2-nicolas.iooss@m4x.org> (raw)
In-Reply-To: <20181209142323.21149-1-nicolas.iooss@m4x.org>

Using Vagrant with fedora/28-cloud-base image, SELinux logins are
configured this way:

    # semanage login -l
    Login Name           SELinux User         MLS/MCS Range        Service

    __default__          unconfined_u         s0-s0:c0.c1023       *
    root                 unconfined_u         s0-s0:c0.c1023       *
    vagrant              unconfined_u         s0-s0:c0.c1023       *

Using "chcat -l +c42 vagrant" successfully adds the category to user
vagrant, but "chcat -l -- -c42 vagrant" fails to remove it.
semanage login -l returns:

    vagrant              unconfined_u         s0-s0:c0.c1023,c42   *

This issue is caused by expandCats(), which refuses to return a list of
more than 25 categories. This causes chcat_user_remove() to work with
cats=['c0.c1023,c42'] instead of cats=['c0.c102','c42'], which leads to
it not been able to remove 'c42' from the list.

Fix this issue by splitting the list of categories before calling
expandCats().

Signed-off-by: Nicolas Iooss <nicolas.iooss@m4x.org>
---
 python/chcat/chcat | 6 ++----
 1 file changed, 2 insertions(+), 4 deletions(-)

diff --git a/python/chcat/chcat b/python/chcat/chcat
index 73f757258807..5bef0073b7a4 100755
--- a/python/chcat/chcat
+++ b/python/chcat/chcat
@@ -82,8 +82,7 @@ def chcat_user_add(newcat, users):
         if len(serange) > 1:
             top = serange[1].split(":")
             if len(top) > 1:
-                cats.append(top[1])
-                cats = expandCats(cats)
+                cats = expandCats(top[1].split(','))
 
         for i in newcat[1:]:
             if i not in cats:
@@ -163,8 +162,7 @@ def chcat_user_remove(newcat, users):
         if len(serange) > 1:
             top = serange[1].split(":")
             if len(top) > 1:
-                cats.append(top[1])
-                cats = expandCats(cats)
+                cats = expandCats(top[1].split(','))
 
         for i in newcat[1:]:
             if i in cats:
-- 
2.19.1


  reply	other threads:[~2018-12-09 14:23 UTC|newest]

Thread overview: 5+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2018-12-09 14:23 [PATCH 1/2] python/chcat: improve the code readability Nicolas Iooss
2018-12-09 14:23 ` Nicolas Iooss [this message]
2018-12-11  9:56   ` [PATCH 2/2] python/chcat: fix removing categories on users with Fedora default setup Petr Lautrbach
2018-12-12  9:38     ` Petr Lautrbach
2018-12-11  9:55 ` [PATCH 1/2] python/chcat: improve the code readability Petr Lautrbach

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20181209142323.21149-2-nicolas.iooss@m4x.org \
    --to=nicolas.iooss@m4x.org \
    --cc=selinux@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.