Re: [PATCH] selinux: validate constraint expression attr and op at load time

[email protected] Mon, 27 Jul 2026 14:50:24 +0000
Newsgroups org.kernel.vger.selinux
Message-ID <[email protected]>
> read_cons_helper() validates the expression type and stack depth
> of each constraint node but leaves e->attr and e->op unchecked,
> so a policy with an invalid operator or attribute value is
> accepted at load and only detected when the constraint is evaluated.
> constraint_expr_eval() handles such unrecognized cases with BUG()
> so the first permission check that reaches such a node oopses in
> the context of the checking process or panics with panic_on_oops.
> 
> Reject these expresssions when the policy is loaded, matching what
> the libsepol validator already does.
> 
> Signed-off-by: Stephen Smalley <[email protected]>

Sashiko has reviewed this patch and found no issues. It looks great!

-- 
Sashiko AI review ยท https://sashiko.dev/#/patchset/[email protected]?part=1