selinux.vger.kernel.org archive mirror
 help / color / mirror / Atom feed
* [RFC PATCH v2] libsepol/cil: raise default attrs_expand_size to 2
@ 2020-03-05 13:53 Ondrej Mosnacek
  2020-03-09 13:17 ` James Carter
  2020-05-11 12:27 ` Petr Lautrbach
  0 siblings, 2 replies; 13+ messages in thread
From: Ondrej Mosnacek @ 2020-03-05 13:53 UTC (permalink / raw)
  To: selinux; +Cc: Stephen Smalley, James Carter

The value attrs_expand_size == 1 removes all empty attributes, but it
also makes sense to expand all attributes that have only one type. This
removes some redundant rules (there is sometimes the same rule for the
type and the attribute) and reduces the number of attributes that the
kernel has to go through when looking up rules.

Signed-off-by: Ondrej Mosnacek <omosnace@redhat.com>
---

v2: fix typos (Tne -> The; cointains -> contains)

 libsepol/cil/src/cil.c | 3 ++-
 1 file changed, 2 insertions(+), 1 deletion(-)

diff --git a/libsepol/cil/src/cil.c b/libsepol/cil/src/cil.c
index d222ad3a..c010ca2a 100644
--- a/libsepol/cil/src/cil.c
+++ b/libsepol/cil/src/cil.c
@@ -452,7 +452,8 @@ void cil_db_init(struct cil_db **db)
 	(*db)->disable_dontaudit = CIL_FALSE;
 	(*db)->disable_neverallow = CIL_FALSE;
 	(*db)->attrs_expand_generated = CIL_FALSE;
-	(*db)->attrs_expand_size = 1;
+	/* 2 == remove attributes that contain none or just 1 type */
+	(*db)->attrs_expand_size = 2;
 	(*db)->preserve_tunables = CIL_FALSE;
 	(*db)->handle_unknown = -1;
 	(*db)->mls = -1;
-- 
2.24.1


^ permalink raw reply related	[flat|nested] 13+ messages in thread

end of thread, other threads:[~2020-05-12 19:58 UTC | newest]

Thread overview: 13+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2020-03-05 13:53 [RFC PATCH v2] libsepol/cil: raise default attrs_expand_size to 2 Ondrej Mosnacek
2020-03-09 13:17 ` James Carter
2020-03-11 18:29   ` James Carter
2020-05-11 12:27 ` Petr Lautrbach
2020-05-11 13:25   ` James Carter
2020-05-11 18:03     ` James Carter
2020-05-11 18:08       ` Stephen Smalley
2020-05-11 19:01         ` James Carter
2020-05-12 17:16           ` Petr Lautrbach
2020-05-12 17:27             ` Stephen Smalley
2020-05-12 19:33               ` James Carter
2020-05-12 19:48                 ` James Carter
2020-05-12 19:57               ` James Carter

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).