Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Disabling SELinux hiding currently unhooks and frees original-call trampolines and a status page that can still be executing or mapped by an application. Keep the five handler hooks and their original-call trampolines resident until reboot; disabling switches each handler back to the original implementation. Serialize enable/disable attempts and reuse partial successful installations on retry.
Remove the fallback that overwrites write_op/file_operations slots using hardcoded offsets when handler symbols are unavailable. Missing required symbols now return
-ENOENT. Check policy-hook registration results, mark installations complete only on success, avoid registering the policy-load hook twice, and propagate initialization/snapshot errors. Zero the status page before mapping it and validate the page-protection value with the existing helper.Bound
print_bootlog()to its 1,024-byte stack buffer by flushing long lines in chunks, including a final unterminated line.Tradeoff: disabling hiding retains a fixed set of trampolines and the status page until reboot, with forwarding overhead; kernels lacking the required symbols cannot enable this feature.
Related manager changes and local kernel artifact support: LyraVoid/FolkPatch#220.
Validation:
python3 tests/test_stability.pypasses with AddressSanitizer and UndefinedBehaviorSanitizer: missing symbols, partial install/retry, resident disable/re-enable, busy control, policy-load retry, and 8,192-byte panic logs.git diff --checkpasses.