Linux Security Modules development
 help / color / mirror / Atom feed
* [PATCH] smackfs: fix IPv6 netlabel prefix mask for non-16-aligned lengths
@ 2026-09-22 14:47 Hongjian Dai
  2026-09-22 14:57 ` sashiko-bot
  0 siblings, 1 reply; 2+ messages in thread
From: Hongjian Dai @ 2026-09-22 14:47 UTC (permalink / raw)
  To: casey, paul, jmorris, serge
  Cc: linux-security-module, linux-kernel, Hongjian Dai

smk_write_net6addr() builds the partial-word mask as (1 << m) - 1,
which keeps the low m bits instead of the high m bits (e.g. /33
yields 0x0001 instead of 0x8000), and stores it without htons()
while the address words are in network byte order. Any prefix with
mask % 16 != 0 is truncated to the wrong network and mislabeled.

Take the high m bits and convert to network byte order, matching
how newname words are stored with htons().

Fixes: 21abb1ec414c ("Smack: IPv6 host labeling")
---
 security/smack/smackfs.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/security/smack/smackfs.c b/security/smack/smackfs.c
index a72bc7fabea9..6d680424a8c3 100644
--- a/security/smack/smackfs.c
+++ b/security/smack/smackfs.c
@@ -1506,7 +1506,7 @@ static ssize_t smk_write_net6addr(struct file *file, const char __user *buf,
 			fullmask.s6_addr16[i] = 0xffff;
 			m -= 16;
 		} else if (m > 0) {
-			fullmask.s6_addr16[i] = (1 << m) - 1;
+			fullmask.s6_addr16[i] = htons(0xffff << (16 - m));
 			m = 0;
 		} else
 			fullmask.s6_addr16[i] = 0;
-- 
2.43.0


^ permalink raw reply related	[flat|nested] 2+ messages in thread

* Re: [PATCH] smackfs: fix IPv6 netlabel prefix mask for non-16-aligned lengths
  2026-09-22 14:47 [PATCH] smackfs: fix IPv6 netlabel prefix mask for non-16-aligned lengths Hongjian Dai
@ 2026-09-22 14:57 ` sashiko-bot
  0 siblings, 0 replies; 2+ messages in thread
From: sashiko-bot @ 2026-09-22 14:57 UTC (permalink / raw)
  Cc: linux-security-module

> smk_write_net6addr() builds the partial-word mask as (1 << m) - 1,
> which keeps the low m bits instead of the high m bits (e.g. /33
> yields 0x0001 instead of 0x8000), and stores it without htons()
> while the address words are in network byte order. Any prefix with
> mask % 16 != 0 is truncated to the wrong network and mislabeled.
> 
> Take the high m bits and convert to network byte order, matching
> how newname words are stored with htons().
> 
> Fixes: 21abb1ec414c ("Smack: IPv6 host labeling")

Sashiko has reviewed this patch and found no issues. It looks great!

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/A82C90B4956EE3A9+20260922144738.9594-1-daihongjian@kylinsec.com.cn?part=1


^ permalink raw reply	[flat|nested] 2+ messages in thread

end of thread, other threads:[~2026-09-22 14:57 UTC | newest]

Thread overview: 2+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-22 14:47 [PATCH] smackfs: fix IPv6 netlabel prefix mask for non-16-aligned lengths Hongjian Dai
2026-09-22 14:57 ` sashiko-bot

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox