From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 6A81E48165E; Tue, 25 Aug 2026 13:36:10 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787664971; cv=none; b=Na6IobIx9IgE01ebOI+n9JyhvwdpTvY7Mi7KfX/d0JqzdKjM6rVdUTfbb4J8jgrSmo14tc0znMPVtWU5111SSeWL1z3GiZMUqUpy3RFDZyzcm3ME3vh4bCDevH5xcDSAF3EuCK16wF8ivs6VJXDqePjG2V95/8aJUH59+EkH270= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787664971; c=relaxed/simple; bh=kWF+rJOjJQVXM3J8k9wUyfUWIOR3eeOajPEGzWx2HoM=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version:Content-Type; b=ZTr8lfEAD9pAHfQYDqKckmKQ3wQQpglk5yOT1uD9am03UgU1yVXBVxxTMp8vNaDtVR+vxnPlJ+bUjLOrJh+kpoVChzsf7zXXFoKjvS+cMypOgq1tZsgBnxgWWF+TSMxPogNKP/a1cYmlvpnphk0p+uWkPqiB6Y5PxbRnYiTsnMs= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=2V2Kzogm; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="2V2Kzogm" Received: by smtp.kernel.org (Postfix) with ESMTPSA id C32981F000E9; Tue, 25 Aug 2026 13:36:09 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1787664970; bh=8UShEKbvhf5C4AlZdvE4M7ygL8K6mY2ely9FiF4b3zs=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=2V2Kzogm24mRZ7ShUtEbTfeGQQPlBiVWeEIasuatNMW7HYYrC+HNDE1ouDyqJ9LBd heelpti1pUkAiIij8wt0+ghBs+62FXKHq9n2m4cg8wTcAO1nTchCif6mPA5R2S+gpr z7IQwygwU5RC6HYP6gmned82aU/ufnmx9JtQWyqE= From: Greg Kroah-Hartman To: stable@vger.kernel.org Cc: Greg Kroah-Hartman , patches@lists.linux.dev, =?UTF-8?q?Christian=20G=C3=B6ttsche?= , Stephen Smalley , Paul Moore , Sasha Levin Subject: [PATCH 7.1 066/101] selinux: use u16 for security classes Date: Tue, 25 Aug 2026 15:25:44 +0200 Message-ID: <20260825132544.583301575@linuxfoundation.org> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260825132541.986300899@linuxfoundation.org> References: <20260825132541.986300899@linuxfoundation.org> User-Agent: quilt/0.69 X-stable: review X-Patchwork-Hint: ignore Precedence: bulk X-Mailing-List: patches@lists.linux.dev List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit 7.1-stable review patch. If anyone has any objections, please let me know. ------------------ From: Christian Göttsche [ Upstream commit fa79a596848fe38c55ccab8832ac35dac07fb00c ] Security class identifiers are limited to 2^16, thus use the appropriate type u16 consistently. Signed-off-by: Christian Göttsche Acked-by: Stephen Smalley Signed-off-by: Paul Moore Stable-dep-of: b98a8ac50775 ("selinux: require a class's permission values to cover its permission count") Signed-off-by: Sasha Levin Signed-off-by: Greg Kroah-Hartman --- security/selinux/ss/policydb.c | 5 +++-- security/selinux/ss/policydb.h | 10 +++++----- security/selinux/ss/services.c | 2 +- 3 files changed, 9 insertions(+), 8 deletions(-) --- a/security/selinux/ss/policydb.c +++ b/security/selinux/ss/policydb.c @@ -950,7 +950,7 @@ int policydb_load_isids(struct policydb return 0; } -int policydb_class_isvalid(struct policydb *p, unsigned int class) +int policydb_class_isvalid(struct policydb *p, u16 class) { if (!class || class > p->p_classes.nprim) return 0; @@ -2039,7 +2039,8 @@ static int filename_trans_read_helper(st struct filename_trans_key *ft = NULL; struct filename_trans_datum **dst, *datum, *first = NULL; char *name = NULL; - u32 len, ttype, tclass, ndatum, i; + u32 len, ttype, ndatum, i; + u16 tclass; __le32 buf[3]; int rc; --- a/security/selinux/ss/policydb.h +++ b/security/selinux/ss/policydb.h @@ -48,7 +48,7 @@ struct common_datum { /* Class attributes */ struct class_datum { - u32 value; /* class value */ + u16 value; /* class value */ char *comkey; /* common name */ struct common_datum *comdatum; /* common datum */ struct symtab permissions; /* class-specific permission symbol table */ @@ -82,7 +82,7 @@ struct role_datum { struct role_trans_key { u32 role; /* current role */ u32 type; /* program executable type, or new object type */ - u32 tclass; /* process class, or new object class */ + u16 tclass; /* process class, or new object class */ }; struct role_trans_datum { @@ -139,7 +139,7 @@ struct cat_datum { struct range_trans { u32 source_type; u32 target_type; - u32 target_class; + u16 target_class; }; /* Boolean data type */ @@ -195,7 +195,7 @@ struct ocontext { } ibendport; } u; union { - u32 sclass; /* security class for genfs */ + u16 sclass; /* security class for genfs */ u32 behavior; /* labeling behavior for fs_use */ } v; struct context context[2]; /* security context(s) */ @@ -322,7 +322,7 @@ struct policy_file { extern void policydb_destroy(struct policydb *p); extern int policydb_load_isids(struct policydb *p, struct sidtab *s); extern int policydb_context_isvalid(struct policydb *p, struct context *c); -extern int policydb_class_isvalid(struct policydb *p, unsigned int class); +extern int policydb_class_isvalid(struct policydb *p, u16 class); extern int policydb_type_isvalid(struct policydb *p, unsigned int type); extern int policydb_role_isvalid(struct policydb *p, unsigned int role); extern int policydb_read(struct policydb *p, struct policy_file *fp); --- a/security/selinux/ss/services.c +++ b/security/selinux/ss/services.c @@ -3290,7 +3290,7 @@ static int get_classes_callback(void *k, { struct class_datum *datum = d; char *name = k, **classes = args; - u32 value = datum->value - 1; + u16 value = datum->value - 1; classes[value] = kstrdup(name, GFP_ATOMIC); if (!classes[value])