Skip to content

fix: preserve SELinux hook resources and bound panic logs - #7

Open
JavSaia wants to merge 1 commit into
LyraVoid:mainfrom
JavSaia:fix/selinux-hook-stability
Open

JavSaia wants to merge 1 commit into
LyraVoid:mainfrom
JavSaia:fix/selinux-hook-stability

Conversation

@JavSaia

@JavSaia JavSaia commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

Disabling SELinux hiding currently unhooks and frees original-call trampolines and a status page that can still be executing or mapped by an application. Keep the five handler hooks and their original-call trampolines resident until reboot; disabling switches each handler back to the original implementation. Serialize enable/disable attempts and reuse partial successful installations on retry.

Remove the fallback that overwrites write_op/file_operations slots using hardcoded offsets when handler symbols are unavailable. Missing required symbols now return -ENOENT. Check policy-hook registration results, mark installations complete only on success, avoid registering the policy-load hook twice, and propagate initialization/snapshot errors. Zero the status page before mapping it and validate the page-protection value with the existing helper.

Bound print_bootlog() to its 1,024-byte stack buffer by flushing long lines in chunks, including a final unterminated line.

Tradeoff: disabling hiding retains a fixed set of trampolines and the status page until reboot, with forwarding overhead; kernels lacking the required symbols cannot enable this feature.

Related manager changes and local kernel artifact support: LyraVoid/FolkPatch#220.

Validation:

  • python3 tests/test_stability.py passes with AddressSanitizer and UndefinedBehaviorSanitizer: missing symbols, partial install/retry, resident disable/re-enable, busy control, policy-load retry, and 8,192-byte panic logs.
  • The three modified C files compiled to ARM64 objects with NDK r26b Clang and the project's Android compile flags. Existing header warnings remain.
  • git diff --check passes.
  • The host regressions use stubs for kernel operations. Full kpimg linking and device validation have not been performed; these fixes do not establish the cause of any particular device's random reboot.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant