Re: [PATCH] apparmor: leverage audit_log_n_untrustedstring() when possible
Ryan Lee <[email protected]> Fri, 17 Jul 2026 16:52:31 -0700
| Newsgroups | org.kernel.vger.linux-security-module |
|---|---|
| Message-ID | <CAKCV-6u-jAoQgghXrp828JLRLvoSyTp_OcPyGQNDHM6FYn8DOA@mail.gmail.com> |
On Fri, Jul 17, 2026 at 2:58 PM Paul Moore <[email protected]> wrote: > > On Fri, Jul 17, 2026 at 5:54 PM Paul Moore <[email protected]> wrote: > > On Fri, Jul 17, 2026 at 5:52 PM Paul Moore <[email protected]> wrote: > > > > > > Make use of the audit_log_n_untrustedstring() function to simplify the > > > code in aa_label_xaudit(). > > > > > > Signed-off-by: Paul Moore <[email protected]> > > > --- > > > security/apparmor/label.c | 5 +---- > > > 1 file changed, 1 insertion(+), 4 deletions(-) > > > > Untested beyond a basic compile, but I noticed this while looking at > > something else (unrelated) and wanted to send it to the list before I > > forgot about it ... > > My apologies Georgia, I thought I had copied your email into the > original posting but it appears I copied John's email twice into my > posting script (which helpfully de-duped it). > > Sorry about that. > > > > diff --git a/security/apparmor/label.c b/security/apparmor/label.c > > > index 3fd384d8c41a..a165cadf8249 100644 > > > --- a/security/apparmor/label.c > > > +++ b/security/apparmor/label.c > > > @@ -1743,10 +1743,7 @@ void aa_label_xaudit(struct audit_buffer *ab, struct aa_ns *ns, > > > str = (char *) label->hname; > > > len = strlen(str); > > > } > > > - if (audit_string_contains_control(str, len)) > > > - audit_log_n_hex(ab, str, len); > > > - else > > > - audit_log_n_string(ab, str, len); > > > + audit_log_n_untrustedstring(ab, str, len); > > > > > > kfree(name); > > > } > > > -- > > > 2.55.0 > > -- > paul-moore.com > Reviewed-By: Ryan Lee <[email protected]>