Re: [PATCH 4/4] selinux: require every boolean value to be defined

Paul Moore <[email protected]>
Newsgroups org.kernel.vger.linux-kernel,org.kernel.vger.selinux
Message-ID <[email protected]>
On Jul 31, 2026 Bryam Vargas <[email protected]> wrote:
> 
> p_bools.nprim comes from the policy image independently of how many
> booleans follow it, and cond_index_bool() fills bool_val_to_struct[] at
> value - 1, so a count larger than the values present leaves NULL entries.
> Every user of that array then walks it by index and dereferences each
> entry: cond_evaluate_expr() on the access-vector path,
> security_get_bools() and security_get_bool_value() behind selinuxfs, and
> security_set_bools(). A sparse class value is absorbed by
> policydb_class_isvalid() and its siblings; booleans have no such
> predicate, and no consumer that could use one.
> 
> Reject a boolean value that no boolean defines, once, where the array is
> built. Conforming policies define every boolean they declare and are
> unaffected.
> 
> Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
> Cc: [email protected]
> Signed-off-by: Bryam Vargas <[email protected]>
> Acked-by: Stephen Smalley <[email protected]>
> ---
>  security/selinux/ss/policydb.c | 19 +++++++++++++++++++
>  1 file changed, 19 insertions(+)

Merged into selinux/stable-7.2, thanks!

--
paul-moore.com
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.