All of lore.kernel.org
 help / color / mirror / Atom feed
* [PATCH] libsepol: Tighten validation of scope index class_perm_map array
@ 2026-08-31 14:16 James Carter
  2026-08-31 16:25 ` Stephen Smalley
  0 siblings, 1 reply; 3+ messages in thread
From: James Carter @ 2026-08-31 14:16 UTC (permalink / raw)
  To: selinux; +Cc: stephen.smalley.work, James Carter

Commit 94e9e7cf ("libsepol: Validate scope index class_perm_map array")
verified that for each class in the array either the permission bitmap
was empty or that it contained at least one valid permission. This was
based on the belief that older compilers would set bits higher than
than the highest valid permission bit when "*" or "~" was used. But
this is only true for AV and constraint rules and does not apply to
declarations or requires. This means that stricter validation can be
done.

Fail validation if any invalid (junk) permissions are set.

Signed-off-by: James Carter <jwcart2@gmail.com>
---
 libsepol/src/policydb_validate.c | 13 ++++---------
 1 file changed, 4 insertions(+), 9 deletions(-)

diff --git a/libsepol/src/policydb_validate.c b/libsepol/src/policydb_validate.c
index 99d27f88..1a32456f 100644
--- a/libsepol/src/policydb_validate.c
+++ b/libsepol/src/policydb_validate.c
@@ -1755,21 +1755,16 @@ static int validate_scope_index(sepol_handle_t *handle,
 		for (i = 0; i < scope_index->class_perms_len; i++) {
 			const ebitmap_t *map;
 			class_datum_t *class;
-			ebitmap_node_t *node;
-			unsigned int bit = 0;
 			if (validate_value(i + 1, &flavors[SYM_CLASSES]))
 				goto bad;
 			map = &scope_index->class_perms_map[i];
 			class = p->class_val_to_struct[i];
-			/* Either there are no perms */
+			/* Having no perms is allowed */
 			if (ebitmap_is_empty(map))
 				continue;
-			/* Or at least one valid perm */
-			ebitmap_for_each_positive_bit(map, node, bit) {
-				if (bit < class->permissions.nprim)
-					break;
-			}
-			if (bit >= class->permissions.nprim)
+			/* Having junk perms is not */
+			if (ebitmap_highest_set_bit(map) >=
+			    class->permissions.nprim)
 				goto bad;
 		}
 	} else {
-- 
2.55.0


^ permalink raw reply related	[flat|nested] 3+ messages in thread

* Re: [PATCH] libsepol: Tighten validation of scope index class_perm_map array
  2026-08-31 14:16 [PATCH] libsepol: Tighten validation of scope index class_perm_map array James Carter
@ 2026-08-31 16:25 ` Stephen Smalley
  2026-08-31 20:15   ` Stephen Smalley
  0 siblings, 1 reply; 3+ messages in thread
From: Stephen Smalley @ 2026-08-31 16:25 UTC (permalink / raw)
  To: James Carter; +Cc: selinux

On Mon, Aug 31, 2026 at 10:17 AM James Carter <jwcart2@gmail.com> wrote:
>
> Commit 94e9e7cf ("libsepol: Validate scope index class_perm_map array")
> verified that for each class in the array either the permission bitmap
> was empty or that it contained at least one valid permission. This was
> based on the belief that older compilers would set bits higher than
> than the highest valid permission bit when "*" or "~" was used. But
> this is only true for AV and constraint rules and does not apply to
> declarations or requires. This means that stricter validation can be
> done.
>
> Fail validation if any invalid (junk) permissions are set.
>
> Signed-off-by: James Carter <jwcart2@gmail.com>

Acked-by: Stephen Smalley <stephen.smalley.work@gmail.com>

^ permalink raw reply	[flat|nested] 3+ messages in thread

* Re: [PATCH] libsepol: Tighten validation of scope index class_perm_map array
  2026-08-31 16:25 ` Stephen Smalley
@ 2026-08-31 20:15   ` Stephen Smalley
  0 siblings, 0 replies; 3+ messages in thread
From: Stephen Smalley @ 2026-08-31 20:15 UTC (permalink / raw)
  To: James Carter; +Cc: selinux

On Mon, Aug 31, 2026 at 12:25 PM Stephen Smalley
<stephen.smalley.work@gmail.com> wrote:
>
> On Mon, Aug 31, 2026 at 10:17 AM James Carter <jwcart2@gmail.com> wrote:
> >
> > Commit 94e9e7cf ("libsepol: Validate scope index class_perm_map array")
> > verified that for each class in the array either the permission bitmap
> > was empty or that it contained at least one valid permission. This was
> > based on the belief that older compilers would set bits higher than
> > than the highest valid permission bit when "*" or "~" was used. But
> > this is only true for AV and constraint rules and does not apply to
> > declarations or requires. This means that stricter validation can be
> > done.
> >
> > Fail validation if any invalid (junk) permissions are set.
> >
> > Signed-off-by: James Carter <jwcart2@gmail.com>
>
> Acked-by: Stephen Smalley <stephen.smalley.work@gmail.com>

Thanks, merged.

^ permalink raw reply	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2026-08-31 20:15 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-08-31 14:16 [PATCH] libsepol: Tighten validation of scope index class_perm_map array James Carter
2026-08-31 16:25 ` Stephen Smalley
2026-08-31 20:15   ` Stephen Smalley

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.