* [PATCH] libsepol: Do not convert mls rules to CIL for a non-mls policy
@ 2026-08-04 18:48 James Carter
2026-08-04 19:24 ` Stephen Smalley
0 siblings, 1 reply; 3+ messages in thread
From: James Carter @ 2026-08-04 18:48 UTC (permalink / raw)
To: selinux; +Cc: stephen.smalley.work, James Carter
When converting a module policydb to CIL mls rules for sensitivies
and categories are processed if they exist even for a non-mls
policy. This allows for a maliciously crafted policy to cause an
OOB access.
If the policy is not an mls policy, then skip sensitivity,
category, and the ordering rules for sensitivies and categories.
Signed-off-by: James Carter <jwcart2@gmail.com>
---
libsepol/src/module_to_cil.c | 12 ++++++++++++
1 file changed, 12 insertions(+)
diff --git a/libsepol/src/module_to_cil.c b/libsepol/src/module_to_cil.c
index 06fbdc30..6876bd76 100644
--- a/libsepol/src/module_to_cil.c
+++ b/libsepol/src/module_to_cil.c
@@ -2711,6 +2711,9 @@ static int sens_to_cil(int indent, struct policydb *pdb,
{
level_datum_t *level = datum;
+ if (!pdb->mls)
+ return 0;
+
if (scope == SCOPE_DECL) {
if (!level->isalias) {
cil_println(indent, "(sensitivity %s)", key);
@@ -2738,6 +2741,9 @@ static int sens_order_to_cil(int indent, struct policydb *pdb,
struct ebitmap_node *node;
uint32_t i;
+ if (!pdb->mls)
+ return 0;
+
if (ebitmap_is_empty(&order)) {
return 0;
}
@@ -2761,6 +2767,9 @@ static int cat_to_cil(int indent, struct policydb *pdb,
{
struct cat_datum *cat = datum;
+ if (!pdb->mls)
+ return 0;
+
if (scope == SCOPE_REQ) {
return 0;
}
@@ -2783,6 +2792,9 @@ static int cat_order_to_cil(int indent, struct policydb *pdb,
struct ebitmap_node *node;
uint32_t i;
+ if (!pdb->mls)
+ return 0;
+
if (ebitmap_is_empty(&order)) {
rc = 0;
goto exit;
--
2.55.0
^ permalink raw reply related [flat|nested] 3+ messages in thread* Re: [PATCH] libsepol: Do not convert mls rules to CIL for a non-mls policy
2026-08-04 18:48 [PATCH] libsepol: Do not convert mls rules to CIL for a non-mls policy James Carter
@ 2026-08-04 19:24 ` Stephen Smalley
2026-08-04 20:35 ` Stephen Smalley
0 siblings, 1 reply; 3+ messages in thread
From: Stephen Smalley @ 2026-08-04 19:24 UTC (permalink / raw)
To: James Carter; +Cc: selinux
On Tue, Aug 4, 2026 at 2:48 PM James Carter <jwcart2@gmail.com> wrote:
>
> When converting a module policydb to CIL mls rules for sensitivies
> and categories are processed if they exist even for a non-mls
> policy. This allows for a maliciously crafted policy to cause an
> OOB access.
>
> If the policy is not an mls policy, then skip sensitivity,
> category, and the ordering rules for sensitivies and categories.
>
> Signed-off-by: James Carter <jwcart2@gmail.com>
Acked-by: Stephen Smalley <stephen.smalley.work@gmail.com>
> ---
> libsepol/src/module_to_cil.c | 12 ++++++++++++
> 1 file changed, 12 insertions(+)
>
> diff --git a/libsepol/src/module_to_cil.c b/libsepol/src/module_to_cil.c
> index 06fbdc30..6876bd76 100644
> --- a/libsepol/src/module_to_cil.c
> +++ b/libsepol/src/module_to_cil.c
> @@ -2711,6 +2711,9 @@ static int sens_to_cil(int indent, struct policydb *pdb,
> {
> level_datum_t *level = datum;
>
> + if (!pdb->mls)
> + return 0;
> +
> if (scope == SCOPE_DECL) {
> if (!level->isalias) {
> cil_println(indent, "(sensitivity %s)", key);
> @@ -2738,6 +2741,9 @@ static int sens_order_to_cil(int indent, struct policydb *pdb,
> struct ebitmap_node *node;
> uint32_t i;
>
> + if (!pdb->mls)
> + return 0;
> +
> if (ebitmap_is_empty(&order)) {
> return 0;
> }
> @@ -2761,6 +2767,9 @@ static int cat_to_cil(int indent, struct policydb *pdb,
> {
> struct cat_datum *cat = datum;
>
> + if (!pdb->mls)
> + return 0;
> +
> if (scope == SCOPE_REQ) {
> return 0;
> }
> @@ -2783,6 +2792,9 @@ static int cat_order_to_cil(int indent, struct policydb *pdb,
> struct ebitmap_node *node;
> uint32_t i;
>
> + if (!pdb->mls)
> + return 0;
> +
> if (ebitmap_is_empty(&order)) {
> rc = 0;
> goto exit;
> --
> 2.55.0
>
^ permalink raw reply [flat|nested] 3+ messages in thread* Re: [PATCH] libsepol: Do not convert mls rules to CIL for a non-mls policy
2026-08-04 19:24 ` Stephen Smalley
@ 2026-08-04 20:35 ` Stephen Smalley
0 siblings, 0 replies; 3+ messages in thread
From: Stephen Smalley @ 2026-08-04 20:35 UTC (permalink / raw)
To: James Carter; +Cc: selinux
On Tue, Aug 4, 2026 at 3:24 PM Stephen Smalley
<stephen.smalley.work@gmail.com> wrote:
>
> On Tue, Aug 4, 2026 at 2:48 PM James Carter <jwcart2@gmail.com> wrote:
> >
> > When converting a module policydb to CIL mls rules for sensitivies
> > and categories are processed if they exist even for a non-mls
> > policy. This allows for a maliciously crafted policy to cause an
> > OOB access.
> >
> > If the policy is not an mls policy, then skip sensitivity,
> > category, and the ordering rules for sensitivies and categories.
> >
> > Signed-off-by: James Carter <jwcart2@gmail.com>
>
> Acked-by: Stephen Smalley <stephen.smalley.work@gmail.com>
Merged.
^ permalink raw reply [flat|nested] 3+ messages in thread
end of thread, other threads:[~2026-08-04 20:36 UTC | newest]
Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-08-04 18:48 [PATCH] libsepol: Do not convert mls rules to CIL for a non-mls policy James Carter
2026-08-04 19:24 ` Stephen Smalley
2026-08-04 20:35 ` Stephen Smalley
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox