Skip to content

Commit 5ccb919

Browse files
committed
AVC parser overwrites existing syscall success status
parse_avc assigns s->success based on the AVC message whenever a success filter is set, even if s->success already contains the authoritative syscall result. Updated parse_avc so the AVC result only sets s->success when it hasn't already been determined, preserving earlier success values.
1 parent 80ebc60 commit 5ccb919

File tree

1 file changed

+4
-4
lines changed

1 file changed

+4
-4
lines changed

src/ausearch-parse.c

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -1959,12 +1959,12 @@ static int parse_avc(const lnode *n, search_items *s)
19591959
term = n->message;
19601960
goto other_avc;
19611961
}
1962-
if (event_success != S_UNSET) {
1962+
// Do not override syscall success if already set.
1963+
// Syscall pass/fail is the authoritative value.
1964+
if (event_success != S_UNSET && s->success == S_UNSET) {
19631965
*term = 0;
1964-
// FIXME. Do not override syscall success if already
1965-
// set. Syscall pass/fail is the authoritative value.
19661966
if (strstr(str, "denied")) {
1967-
s->success = S_FAILED;
1967+
s->success = S_FAILED;
19681968
an.avc_result = AVC_DENIED;
19691969
} else {
19701970
s->success = S_SUCCESS;

0 commit comments

Comments
 (0)