* [PATCH v2 2/3] selinux: validate user MLS range and default level at load
@ 2026-09-28 16:52 Christian Göttsche
2026-09-28 16:52 ` [PATCH v2 3/3] selinux: validate permissive and neveraudit map types " Christian Göttsche
` (5 more replies)
0 siblings, 6 replies; 15+ messages in thread
From: Christian Göttsche @ 2026-09-28 16:52 UTC (permalink / raw)
To: selinux
Cc: Paul Moore, Stephen Smalley, Ondrej Mosnacek,
Christian Göttsche
From: Christian Göttsche <cgzones@googlemail.com>
user_read() reads each user's MLS range and default level but, unlike
range transitions and security contexts, never validates them.
Validate usr->range and usr->dfltlevel in user_index_check() when MLS is
enabled, once the level and category symbol tables are populated.
Signed-off-by: Christian Göttsche <cgzones@googlemail.com>
---
security/selinux/ss/policydb.c | 14 ++++++++++++++
1 file changed, 14 insertions(+)
diff --git a/security/selinux/ss/policydb.c b/security/selinux/ss/policydb.c
index e0304297def4..e51293e3ca8c 100644
--- a/security/selinux/ss/policydb.c
+++ b/security/selinux/ss/policydb.c
@@ -748,6 +748,20 @@ static int user_index_check(void *key, void *datum, void *datap)
}
}
+ if (p->mls_enabled) {
+ if (!mls_range_isvalid(p, &usr->range)) {
+ pr_err("SELinux: user %s has an invalid MLS range\n",
+ (const char *)key);
+ return -EINVAL;
+ }
+
+ if (!mls_level_isvalid(p, &usr->dfltlevel)) {
+ pr_err("SELinux: user %s has an invalid MLS default level\n",
+ (const char *)key);
+ return -EINVAL;
+ }
+ }
+
return 0;
}
--
2.55.0
^ permalink raw reply related [flat|nested] 15+ messages in thread
* [PATCH v2 3/3] selinux: validate permissive and neveraudit map types at load
2026-09-28 16:52 [PATCH v2 2/3] selinux: validate user MLS range and default level at load Christian Göttsche
@ 2026-09-28 16:52 ` Christian Göttsche
2026-09-28 17:07 ` sashiko-bot
` (2 more replies)
2026-09-28 16:52 ` [PATCH v2 1/3] selinux: bounds-check role and user membership bitmaps " Christian Göttsche
` (4 subsequent siblings)
5 siblings, 3 replies; 15+ messages in thread
From: Christian Göttsche @ 2026-09-28 16:52 UTC (permalink / raw)
To: selinux
Cc: Paul Moore, Stephen Smalley, Ondrej Mosnacek,
Christian Göttsche
From: Christian Göttsche <cgzones@googlemail.com>
The permissive and neveraudit maps are read as ebitmaps and indexed by
type value, but their set bits are never checked. A bit that is not a
defined, non-attribute type is silently accepted. Validate every set bit
of both maps in policydb_index() with policydb_simpletype_isvalid().
Signed-off-by: Christian Göttsche <cgzones@googlemail.com>
---
v2: inline block scope
---
security/selinux/ss/policydb.c | 20 +++++++++++++++++++-
1 file changed, 19 insertions(+), 1 deletion(-)
diff --git a/security/selinux/ss/policydb.c b/security/selinux/ss/policydb.c
index e51293e3ca8c..fe0c0792583f 100644
--- a/security/selinux/ss/policydb.c
+++ b/security/selinux/ss/policydb.c
@@ -818,8 +818,9 @@ static inline void symtab_hash_eval(struct symtab *s)
*/
static int policydb_index(struct policydb *p)
{
+ struct ebitmap_node *node;
int i, rc;
- u32 v;
+ u32 bit, v;
if (p->mls_enabled)
pr_debug(
@@ -902,6 +903,23 @@ static int policydb_index(struct policydb *p)
if (rc)
goto out;
+ ebitmap_for_each_positive_bit(&p->permissive_map, node, bit) {
+ if (!policydb_simpletype_isvalid(p, bit)) {
+ pr_err("SELinux: permissive map refers to invalid type %u\n",
+ bit);
+ rc = -EINVAL;
+ goto out;
+ }
+ }
+ ebitmap_for_each_positive_bit(&p->neveraudit_map, node, bit) {
+ if (!policydb_simpletype_isvalid(p, bit)) {
+ pr_err("SELinux: neveraudit map refers to invalid type %u\n",
+ bit);
+ rc = -EINVAL;
+ goto out;
+ }
+ }
+
rc = 0;
out:
return rc;
--
2.55.0
^ permalink raw reply related [flat|nested] 15+ messages in thread
* [PATCH v2 1/3] selinux: bounds-check role and user membership bitmaps at load
2026-09-28 16:52 [PATCH v2 2/3] selinux: validate user MLS range and default level at load Christian Göttsche
2026-09-28 16:52 ` [PATCH v2 3/3] selinux: validate permissive and neveraudit map types " Christian Göttsche
@ 2026-09-28 16:52 ` Christian Göttsche
2026-09-28 17:03 ` sashiko-bot
` (2 more replies)
2026-09-28 17:01 ` [PATCH v2 2/3] selinux: validate user MLS range and default level " sashiko-bot
` (3 subsequent siblings)
5 siblings, 3 replies; 15+ messages in thread
From: Christian Göttsche @ 2026-09-28 16:52 UTC (permalink / raw)
To: selinux
Cc: Paul Moore, Stephen Smalley, Ondrej Mosnacek,
Christian Göttsche
From: Christian Göttsche <cgzones@googlemail.com>
role->dominates, role->types and user->roles are read as ebitmaps but
their set bits are never checked against the role and type symbol
tables. A bit naming an undefined value is silently accepted, and an
out-of-range one is used to index those tables later; in particular
role_bounds_sanity_check() passes such a bit straight to sym_name(),
reading p->sym_val_to_name[] out of bounds on a crafted bounded role.
Validate the three bitmaps in policydb_index() once every symbol table
is populated (roles are read before types, so this cannot be done in
role_read()).
Signed-off-by: Christian Göttsche <cgzones@googlemail.com>
---
v2: check each bit instead of just comparing the highest bit against
nprim
---
security/selinux/ss/policydb.c | 52 ++++++++++++++++++++++++++++++++++
1 file changed, 52 insertions(+)
diff --git a/security/selinux/ss/policydb.c b/security/selinux/ss/policydb.c
index 13d88e47db3c..e0304297def4 100644
--- a/security/selinux/ss/policydb.c
+++ b/security/selinux/ss/policydb.c
@@ -707,6 +707,50 @@ static int sens_cat_index_check(void *key, void *datum, void *datap)
return 0;
}
+static int role_index_check(void *key, void *datum, void *datap)
+{
+ const struct policydb *p = datap;
+ const struct role_datum *role = datum;
+ struct ebitmap_node *node;
+ u32 bit;
+
+ ebitmap_for_each_positive_bit(&role->dominates, node, bit) {
+ if (!policydb_role_isvalid(p, bit + 1)) {
+ pr_err("SELinux: role %s declares dominance on undefined role %u\n",
+ (const char *)key, bit + 1);
+ return -EINVAL;
+ }
+ }
+
+ ebitmap_for_each_positive_bit(&role->types, node, bit) {
+ if (!policydb_type_isvalid(p, bit + 1)) {
+ pr_err("SELinux: role %s authorizes undefined type %u\n",
+ (const char *)key, bit + 1);
+ return -EINVAL;
+ }
+ }
+
+ return 0;
+}
+
+static int user_index_check(void *key, void *datum, void *datap)
+{
+ const struct policydb *p = datap;
+ const struct user_datum *usr = datum;
+ struct ebitmap_node *node;
+ u32 bit;
+
+ ebitmap_for_each_positive_bit(&usr->roles, node, bit) {
+ if (!policydb_role_isvalid(p, bit + 1)) {
+ pr_err("SELinux: user %s authorizes undefined role %u\n",
+ (const char *)key, bit + 1);
+ return -EINVAL;
+ }
+ }
+
+ return 0;
+}
+
/* clang-format off */
static int (*const index_f[SYM_NUM])(void *key, void *datum, void *datap) = {
common_index,
@@ -836,6 +880,14 @@ static int policydb_index(struct policydb *p)
goto out;
}
+ rc = hashtab_map(&p->p_roles.table, role_index_check, p);
+ if (rc)
+ goto out;
+
+ rc = hashtab_map(&p->p_users.table, user_index_check, p);
+ if (rc)
+ goto out;
+
rc = 0;
out:
return rc;
--
2.55.0
^ permalink raw reply related [flat|nested] 15+ messages in thread
* Re: [PATCH v2 2/3] selinux: validate user MLS range and default level at load
2026-09-28 16:52 [PATCH v2 2/3] selinux: validate user MLS range and default level at load Christian Göttsche
2026-09-28 16:52 ` [PATCH v2 3/3] selinux: validate permissive and neveraudit map types " Christian Göttsche
2026-09-28 16:52 ` [PATCH v2 1/3] selinux: bounds-check role and user membership bitmaps " Christian Göttsche
@ 2026-09-28 17:01 ` sashiko-bot
2026-09-28 19:48 ` [RFC PATCH 15/32] selinux: make mls_level_isvalid() static Stephen Smalley
` (2 subsequent siblings)
5 siblings, 0 replies; 15+ messages in thread
From: sashiko-bot @ 2026-09-28 17:01 UTC (permalink / raw)
Cc: selinux
> From: Christian Göttsche <cgzones@googlemail.com>
>
> user_read() reads each user's MLS range and default level but, unlike
> range transitions and security contexts, never validates them.
> Validate usr->range and usr->dfltlevel in user_index_check() when MLS is
> enabled, once the level and category symbol tables are populated.
>
> Signed-off-by: Christian Göttsche <cgzones@googlemail.com>
Sashiko has reviewed this patch and found no issues. It looks great!
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260928165253.2388012-3-cgoettsche@seltendoof.de?part=2
^ permalink raw reply [flat|nested] 15+ messages in thread
* Re: [PATCH v2 1/3] selinux: bounds-check role and user membership bitmaps at load
2026-09-28 16:52 ` [PATCH v2 1/3] selinux: bounds-check role and user membership bitmaps " Christian Göttsche
@ 2026-09-28 17:03 ` sashiko-bot
2026-09-28 17:49 ` Stephen Smalley
2026-09-30 20:59 ` Paul Moore
2 siblings, 0 replies; 15+ messages in thread
From: sashiko-bot @ 2026-09-28 17:03 UTC (permalink / raw)
Cc: selinux
> From: Christian Göttsche <cgzones@googlemail.com>
>
> role->dominates, role->types and user->roles are read as ebitmaps but
> their set bits are never checked against the role and type symbol
> tables. A bit naming an undefined value is silently accepted, and an
> out-of-range one is used to index those tables later; in particular
> role_bounds_sanity_check() passes such a bit straight to sym_name(),
> reading p->sym_val_to_name[] out of bounds on a crafted bounded role.
>
> Validate the three bitmaps in policydb_index() once every symbol table
> is populated (roles are read before types, so this cannot be done in
> role_read()).
>
> Signed-off-by: Christian Göttsche <cgzones@googlemail.com>
Sashiko has reviewed this patch and found no issues. It looks great!
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260928165253.2388012-3-cgoettsche@seltendoof.de?part=1
^ permalink raw reply [flat|nested] 15+ messages in thread
* Re: [PATCH v2 3/3] selinux: validate permissive and neveraudit map types at load
2026-09-28 16:52 ` [PATCH v2 3/3] selinux: validate permissive and neveraudit map types " Christian Göttsche
@ 2026-09-28 17:07 ` sashiko-bot
2026-09-29 13:11 ` Stephen Smalley
2026-09-30 20:59 ` Paul Moore
2 siblings, 0 replies; 15+ messages in thread
From: sashiko-bot @ 2026-09-28 17:07 UTC (permalink / raw)
Cc: selinux
> From: Christian Göttsche <cgzones@googlemail.com>
>
> The permissive and neveraudit maps are read as ebitmaps and indexed by
> type value, but their set bits are never checked. A bit that is not a
> defined, non-attribute type is silently accepted. Validate every set bit
> of both maps in policydb_index() with policydb_simpletype_isvalid().
>
> Signed-off-by: Christian Göttsche <cgzones@googlemail.com>
Sashiko has reviewed this patch and found no issues. It looks great!
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260928165253.2388012-3-cgoettsche@seltendoof.de?part=3
^ permalink raw reply [flat|nested] 15+ messages in thread
* Re: [PATCH v2 1/3] selinux: bounds-check role and user membership bitmaps at load
2026-09-28 16:52 ` [PATCH v2 1/3] selinux: bounds-check role and user membership bitmaps " Christian Göttsche
2026-09-28 17:03 ` sashiko-bot
@ 2026-09-28 17:49 ` Stephen Smalley
2026-09-28 17:54 ` Stephen Smalley
2026-09-30 20:59 ` Paul Moore
2 siblings, 1 reply; 15+ messages in thread
From: Stephen Smalley @ 2026-09-28 17:49 UTC (permalink / raw)
To: cgzones; +Cc: selinux, Paul Moore, Ondrej Mosnacek
On Mon, Sep 28, 2026 at 12:53 PM Christian Göttsche
<cgoettsche@seltendoof.de> wrote:
>
> From: Christian Göttsche <cgzones@googlemail.com>
>
> role->dominates, role->types and user->roles are read as ebitmaps but
> their set bits are never checked against the role and type symbol
> tables. A bit naming an undefined value is silently accepted, and an
> out-of-range one is used to index those tables later; in particular
> role_bounds_sanity_check() passes such a bit straight to sym_name(),
> reading p->sym_val_to_name[] out of bounds on a crafted bounded role.
>
> Validate the three bitmaps in policydb_index() once every symbol table
> is populated (roles are read before types, so this cannot be done in
> role_read()).
>
> Signed-off-by: Christian Göttsche <cgzones@googlemail.com>
Acked-by: Stephen Smalley <stephen.smalley.work@gmail.com>
^ permalink raw reply [flat|nested] 15+ messages in thread
* Re: [PATCH v2 1/3] selinux: bounds-check role and user membership bitmaps at load
2026-09-28 17:49 ` Stephen Smalley
@ 2026-09-28 17:54 ` Stephen Smalley
2026-09-28 18:20 ` Stephen Smalley
0 siblings, 1 reply; 15+ messages in thread
From: Stephen Smalley @ 2026-09-28 17:54 UTC (permalink / raw)
To: cgzones; +Cc: selinux, Paul Moore, Ondrej Mosnacek
On Mon, Sep 28, 2026 at 1:49 PM Stephen Smalley
<stephen.smalley.work@gmail.com> wrote:
>
> On Mon, Sep 28, 2026 at 12:53 PM Christian Göttsche
> <cgoettsche@seltendoof.de> wrote:
> >
> > From: Christian Göttsche <cgzones@googlemail.com>
> >
> > role->dominates, role->types and user->roles are read as ebitmaps but
> > their set bits are never checked against the role and type symbol
> > tables. A bit naming an undefined value is silently accepted, and an
> > out-of-range one is used to index those tables later; in particular
> > role_bounds_sanity_check() passes such a bit straight to sym_name(),
> > reading p->sym_val_to_name[] out of bounds on a crafted bounded role.
> >
> > Validate the three bitmaps in policydb_index() once every symbol table
> > is populated (roles are read before types, so this cannot be done in
> > role_read()).
> >
> > Signed-off-by: Christian Göttsche <cgzones@googlemail.com>
>
> Acked-by: Stephen Smalley <stephen.smalley.work@gmail.com>
I don't appear to have received patches 2/3 or 3/3 as of yet although
I did get sashiko responses to both.
Not sure why. Regardless, you or Paul can feel free to add my Acked-by
to the ones I see on patchwork and lore.
^ permalink raw reply [flat|nested] 15+ messages in thread
* Re: [PATCH v2 1/3] selinux: bounds-check role and user membership bitmaps at load
2026-09-28 17:54 ` Stephen Smalley
@ 2026-09-28 18:20 ` Stephen Smalley
0 siblings, 0 replies; 15+ messages in thread
From: Stephen Smalley @ 2026-09-28 18:20 UTC (permalink / raw)
To: cgzones; +Cc: selinux, Paul Moore, Ondrej Mosnacek
On Mon, Sep 28, 2026 at 1:54 PM Stephen Smalley
<stephen.smalley.work@gmail.com> wrote:
>
> On Mon, Sep 28, 2026 at 1:49 PM Stephen Smalley
> <stephen.smalley.work@gmail.com> wrote:
> >
> > On Mon, Sep 28, 2026 at 12:53 PM Christian Göttsche
> > <cgoettsche@seltendoof.de> wrote:
> > >
> > > From: Christian Göttsche <cgzones@googlemail.com>
> > >
> > > role->dominates, role->types and user->roles are read as ebitmaps but
> > > their set bits are never checked against the role and type symbol
> > > tables. A bit naming an undefined value is silently accepted, and an
> > > out-of-range one is used to index those tables later; in particular
> > > role_bounds_sanity_check() passes such a bit straight to sym_name(),
> > > reading p->sym_val_to_name[] out of bounds on a crafted bounded role.
> > >
> > > Validate the three bitmaps in policydb_index() once every symbol table
> > > is populated (roles are read before types, so this cannot be done in
> > > role_read()).
> > >
> > > Signed-off-by: Christian Göttsche <cgzones@googlemail.com>
> >
> > Acked-by: Stephen Smalley <stephen.smalley.work@gmail.com>
>
> I don't appear to have received patches 2/3 or 3/3 as of yet although
> I did get sashiko responses to both.
> Not sure why. Regardless, you or Paul can feel free to add my Acked-by
> to the ones I see on patchwork and lore.
I do notice that the From: address differs on these emails from your
usual, not sure if that is causing them to go to the bitbucket in the
sky for me. Maybe you should directly cc me on any you want me to
review to be safe - still waiting for the RFC series to show up
likewise for me.
^ permalink raw reply [flat|nested] 15+ messages in thread
* [RFC PATCH 15/32] selinux: make mls_level_isvalid() static
2026-09-28 16:52 [PATCH v2 2/3] selinux: validate user MLS range and default level at load Christian Göttsche
` (2 preceding siblings ...)
2026-09-28 17:01 ` [PATCH v2 2/3] selinux: validate user MLS range and default level " sashiko-bot
@ 2026-09-28 19:48 ` Stephen Smalley
2026-09-29 13:11 ` [PATCH v2 2/3] selinux: validate user MLS range and default level at load Stephen Smalley
2026-09-30 20:59 ` Paul Moore
5 siblings, 0 replies; 15+ messages in thread
From: Stephen Smalley @ 2026-09-28 19:48 UTC (permalink / raw)
To: cgoettsche; +Cc: cgzones, omosnacek, paul, selinux, stephen.smalley.work
>It is only used within mls.c.
>Assisted-by: Claude:claude-opus-5-5
>Signed-off-by: Christian Göttsche <cgzones@googlemail.com>
You have a patch submitted at:
https://lore.kernel.org/selinux/20260928165253.2388012-1-cgoettsche@seltendoof.de/
that re-introduces a call to this function from outside of mls.c.
So if that patch is merged first, this one needs to be dropped, or
if this one is merged first, then it will need to be reverted again
for that one.
^ permalink raw reply [flat|nested] 15+ messages in thread
* Re: [PATCH v2 2/3] selinux: validate user MLS range and default level at load
2026-09-28 16:52 [PATCH v2 2/3] selinux: validate user MLS range and default level at load Christian Göttsche
` (3 preceding siblings ...)
2026-09-28 19:48 ` [RFC PATCH 15/32] selinux: make mls_level_isvalid() static Stephen Smalley
@ 2026-09-29 13:11 ` Stephen Smalley
2026-09-30 20:59 ` Paul Moore
5 siblings, 0 replies; 15+ messages in thread
From: Stephen Smalley @ 2026-09-29 13:11 UTC (permalink / raw)
To: cgzones; +Cc: selinux, Paul Moore, Ondrej Mosnacek
On Mon, Sep 28, 2026 at 5:38 PM Christian Göttsche
<cgoettsche@seltendoof.de> wrote:
>
> From: Christian Göttsche <cgzones@googlemail.com>
>
> user_read() reads each user's MLS range and default level but, unlike
> range transitions and security contexts, never validates them.
> Validate usr->range and usr->dfltlevel in user_index_check() when MLS is
> enabled, once the level and category symbol tables are populated.
>
> Signed-off-by: Christian Göttsche <cgzones@googlemail.com>
Acked-by: Stephen Smalley <stephen.smalley.work@gmail.com>
^ permalink raw reply [flat|nested] 15+ messages in thread
* Re: [PATCH v2 3/3] selinux: validate permissive and neveraudit map types at load
2026-09-28 16:52 ` [PATCH v2 3/3] selinux: validate permissive and neveraudit map types " Christian Göttsche
2026-09-28 17:07 ` sashiko-bot
@ 2026-09-29 13:11 ` Stephen Smalley
2026-09-30 20:59 ` Paul Moore
2 siblings, 0 replies; 15+ messages in thread
From: Stephen Smalley @ 2026-09-29 13:11 UTC (permalink / raw)
To: cgzones; +Cc: selinux, Paul Moore, Ondrej Mosnacek
On Mon, Sep 28, 2026 at 5:38 PM Christian Göttsche
<cgoettsche@seltendoof.de> wrote:
>
> From: Christian Göttsche <cgzones@googlemail.com>
>
> The permissive and neveraudit maps are read as ebitmaps and indexed by
> type value, but their set bits are never checked. A bit that is not a
> defined, non-attribute type is silently accepted. Validate every set bit
> of both maps in policydb_index() with policydb_simpletype_isvalid().
>
> Signed-off-by: Christian Göttsche <cgzones@googlemail.com>
Acked-by: Stephen Smalley <stephen.smalley.work@gmail.com>
^ permalink raw reply [flat|nested] 15+ messages in thread
* Re: [PATCH v2 1/3] selinux: bounds-check role and user membership bitmaps at load
2026-09-28 16:52 ` [PATCH v2 1/3] selinux: bounds-check role and user membership bitmaps " Christian Göttsche
2026-09-28 17:03 ` sashiko-bot
2026-09-28 17:49 ` Stephen Smalley
@ 2026-09-30 20:59 ` Paul Moore
2 siblings, 0 replies; 15+ messages in thread
From: Paul Moore @ 2026-09-30 20:59 UTC (permalink / raw)
To: Christian Göttsche, selinux
Cc: Stephen Smalley, Ondrej Mosnacek, Christian Göttsche
On Sep 28, 2026 =?UTF-8?q?Christian=20G=C3=B6ttsche?= <cgoettsche@seltendoof.de> wrote:
>
> role->dominates, role->types and user->roles are read as ebitmaps but
> their set bits are never checked against the role and type symbol
> tables. A bit naming an undefined value is silently accepted, and an
> out-of-range one is used to index those tables later; in particular
> role_bounds_sanity_check() passes such a bit straight to sym_name(),
> reading p->sym_val_to_name[] out of bounds on a crafted bounded role.
>
> Validate the three bitmaps in policydb_index() once every symbol table
> is populated (roles are read before types, so this cannot be done in
> role_read()).
>
> Signed-off-by: Christian Göttsche <cgzones@googlemail.com>
> Acked-by: Stephen Smalley <stephen.smalley.work@gmail.com>
> ---
> v2: check each bit instead of just comparing the highest bit against
> nprim
> ---
> security/selinux/ss/policydb.c | 52 ++++++++++++++++++++++++++++++++++
> 1 file changed, 52 insertions(+)
Merged into selinux/dev, thanks!
--
paul-moore.com
^ permalink raw reply [flat|nested] 15+ messages in thread
* Re: [PATCH v2 2/3] selinux: validate user MLS range and default level at load
2026-09-28 16:52 [PATCH v2 2/3] selinux: validate user MLS range and default level at load Christian Göttsche
` (4 preceding siblings ...)
2026-09-29 13:11 ` [PATCH v2 2/3] selinux: validate user MLS range and default level at load Stephen Smalley
@ 2026-09-30 20:59 ` Paul Moore
5 siblings, 0 replies; 15+ messages in thread
From: Paul Moore @ 2026-09-30 20:59 UTC (permalink / raw)
To: Christian Göttsche, selinux
Cc: Stephen Smalley, Ondrej Mosnacek, Christian Göttsche
On Sep 28, 2026 =?UTF-8?q?Christian=20G=C3=B6ttsche?= <cgoettsche@seltendoof.de> wrote:
>
> user_read() reads each user's MLS range and default level but, unlike
> range transitions and security contexts, never validates them.
> Validate usr->range and usr->dfltlevel in user_index_check() when MLS is
> enabled, once the level and category symbol tables are populated.
>
> Signed-off-by: Christian Göttsche <cgzones@googlemail.com>
> Acked-by: Stephen Smalley <stephen.smalley.work@gmail.com>
> ---
> security/selinux/ss/policydb.c | 14 ++++++++++++++
> 1 file changed, 14 insertions(+)
Merged into selinux/dev, thanks!
--
paul-moore.com
^ permalink raw reply [flat|nested] 15+ messages in thread
* Re: [PATCH v2 3/3] selinux: validate permissive and neveraudit map types at load
2026-09-28 16:52 ` [PATCH v2 3/3] selinux: validate permissive and neveraudit map types " Christian Göttsche
2026-09-28 17:07 ` sashiko-bot
2026-09-29 13:11 ` Stephen Smalley
@ 2026-09-30 20:59 ` Paul Moore
2 siblings, 0 replies; 15+ messages in thread
From: Paul Moore @ 2026-09-30 20:59 UTC (permalink / raw)
To: Christian Göttsche, selinux
Cc: Stephen Smalley, Ondrej Mosnacek, Christian Göttsche
On Sep 28, 2026 =?UTF-8?q?Christian=20G=C3=B6ttsche?= <cgoettsche@seltendoof.de> wrote:
>
> The permissive and neveraudit maps are read as ebitmaps and indexed by
> type value, but their set bits are never checked. A bit that is not a
> defined, non-attribute type is silently accepted. Validate every set bit
> of both maps in policydb_index() with policydb_simpletype_isvalid().
>
> Signed-off-by: Christian Göttsche <cgzones@googlemail.com>
> Acked-by: Stephen Smalley <stephen.smalley.work@gmail.com>
> ---
> v2: inline block scope
> ---
> security/selinux/ss/policydb.c | 20 +++++++++++++++++++-
> 1 file changed, 19 insertions(+), 1 deletion(-)
Merged into selinux/dev, thanks!
--
paul-moore.com
^ permalink raw reply [flat|nested] 15+ messages in thread
end of thread, other threads:[~2026-09-30 20:59 UTC | newest]
Thread overview: 15+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-28 16:52 [PATCH v2 2/3] selinux: validate user MLS range and default level at load Christian Göttsche
2026-09-28 16:52 ` [PATCH v2 3/3] selinux: validate permissive and neveraudit map types " Christian Göttsche
2026-09-28 17:07 ` sashiko-bot
2026-09-29 13:11 ` Stephen Smalley
2026-09-30 20:59 ` Paul Moore
2026-09-28 16:52 ` [PATCH v2 1/3] selinux: bounds-check role and user membership bitmaps " Christian Göttsche
2026-09-28 17:03 ` sashiko-bot
2026-09-28 17:49 ` Stephen Smalley
2026-09-28 17:54 ` Stephen Smalley
2026-09-28 18:20 ` Stephen Smalley
2026-09-30 20:59 ` Paul Moore
2026-09-28 17:01 ` [PATCH v2 2/3] selinux: validate user MLS range and default level " sashiko-bot
2026-09-28 19:48 ` [RFC PATCH 15/32] selinux: make mls_level_isvalid() static Stephen Smalley
2026-09-29 13:11 ` [PATCH v2 2/3] selinux: validate user MLS range and default level at load Stephen Smalley
2026-09-30 20:59 ` Paul Moore
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox