All of lore.kernel.org
 help / color / mirror / Atom feed
From: James Carter <jwcart2@gmail.com>
To: selinux@vger.kernel.org
Cc: stephen.smalley.work@gmail.com, James Carter <jwcart2@gmail.com>
Subject: [PATCH] libsepol: Tighten validation of scope index class_perm_map array
Date: Mon, 31 Aug 2026 10:16:49 -0400	[thread overview]
Message-ID: <20260831141649.39561-1-jwcart2@gmail.com> (raw)

Commit 94e9e7cf ("libsepol: Validate scope index class_perm_map array")
verified that for each class in the array either the permission bitmap
was empty or that it contained at least one valid permission. This was
based on the belief that older compilers would set bits higher than
than the highest valid permission bit when "*" or "~" was used. But
this is only true for AV and constraint rules and does not apply to
declarations or requires. This means that stricter validation can be
done.

Fail validation if any invalid (junk) permissions are set.

Signed-off-by: James Carter <jwcart2@gmail.com>
---
 libsepol/src/policydb_validate.c | 13 ++++---------
 1 file changed, 4 insertions(+), 9 deletions(-)

diff --git a/libsepol/src/policydb_validate.c b/libsepol/src/policydb_validate.c
index 99d27f88..1a32456f 100644
--- a/libsepol/src/policydb_validate.c
+++ b/libsepol/src/policydb_validate.c
@@ -1755,21 +1755,16 @@ static int validate_scope_index(sepol_handle_t *handle,
 		for (i = 0; i < scope_index->class_perms_len; i++) {
 			const ebitmap_t *map;
 			class_datum_t *class;
-			ebitmap_node_t *node;
-			unsigned int bit = 0;
 			if (validate_value(i + 1, &flavors[SYM_CLASSES]))
 				goto bad;
 			map = &scope_index->class_perms_map[i];
 			class = p->class_val_to_struct[i];
-			/* Either there are no perms */
+			/* Having no perms is allowed */
 			if (ebitmap_is_empty(map))
 				continue;
-			/* Or at least one valid perm */
-			ebitmap_for_each_positive_bit(map, node, bit) {
-				if (bit < class->permissions.nprim)
-					break;
-			}
-			if (bit >= class->permissions.nprim)
+			/* Having junk perms is not */
+			if (ebitmap_highest_set_bit(map) >=
+			    class->permissions.nprim)
 				goto bad;
 		}
 	} else {
-- 
2.55.0


             reply	other threads:[~2026-08-31 14:17 UTC|newest]

Thread overview: 3+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-08-31 14:16 James Carter [this message]
2026-08-31 16:25 ` [PATCH] libsepol: Tighten validation of scope index class_perm_map array Stephen Smalley
2026-08-31 20:15   ` Stephen Smalley

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260831141649.39561-1-jwcart2@gmail.com \
    --to=jwcart2@gmail.com \
    --cc=selinux@vger.kernel.org \
    --cc=stephen.smalley.work@gmail.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.