All of lore.kernel.org
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
Cc: selinux@vger.kernel.org
Subject: Re: [PATCH] selinux: reject writable opens of status file, drop mmap write checks
Date: Fri, 11 Sep 2026 14:09:57 +0000	[thread overview]
Message-ID: <20260911140958.5EEA81F00901@smtp.kernel.org> (raw)
In-Reply-To: <20260911135147.15355-1-stephen.smalley.work@gmail.com>

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:

Pre-existing issues:
- [High] The patch fails to fully prevent truncation of the SELinux status file, leaving it vulnerable to path-based `truncate()` and `open(O_RDONLY | O_TRUNC)`.
--

commit 4651117ec33990214895f2560efc1a4e7aea0f83
Author: Stephen Smalley <stephen.smalley.work@gmail.com>

selinux: reject writable opens of status file, drop mmap write checks

This commit updates the .open handler for the SELinux status file to reject
writable opens, while removing mmap write checks. The stated goal is to
prevent userspace tools like systemd from segfaulting when the mmap'd status
file is truncated.

Link: https://lore.kernel.org/selinux/aqPUqU3eZeFrykj3@gremlin/
Link: https://lore.kernel.org/selinux/CAJ2a_Df6GOirF8TnNWTqNMpdWLHgjT9_v7G-PiL4e7LU2nr1PA@mail.gmail.com/

> diff --git a/security/selinux/selinuxfs.c b/security/selinux/selinuxfs.c
> index 5aaaf69410bb0..c787e2204717f 100644
> --- a/security/selinux/selinuxfs.c
> +++ b/security/selinux/selinuxfs.c
> @@ -219,6 +219,9 @@ static int sel_open_handle_status(struct inode *inode, struct file *filp)
>  	if (!status)
>  		return -ENOMEM;
>  
> +	if (filp->f_mode & FMODE_WRITE)
> +		return -EACCES;
> +

[Severity: High]
This is a pre-existing issue, but it looks like this might be an incomplete
fix for the truncation problem. Does this check fully prevent truncation of
the SELinux status file?

Because open(O_RDONLY | O_TRUNC) only sets FMODE_READ (and not FMODE_WRITE),
it bypasses this check in sel_open_handle_status() while still triggering
VFS truncation.

Additionally, a privileged process can invoke the path-based truncate()
syscall, which bypasses the .open() handler completely and falls back to
simple_setattr() to truncate the pagecache.

Since the goal of this patch is to prevent truncation to stop libselinux
users like systemd from segfaulting, it seems both of these paths still
allow the file to be truncated and trigger the crash.

[ ... ]

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260911135147.15355-1-stephen.smalley.work@gmail.com?part=1

      reply	other threads:[~2026-09-11 14:09 UTC|newest]

Thread overview: 2+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-11 13:51 [PATCH] selinux: reject writable opens of status file, drop mmap write checks Stephen Smalley
2026-09-11 14:09 ` sashiko-bot [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260911140958.5EEA81F00901@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    --cc=selinux@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.