Re: [PATCH] selinux: validate constraint expression attr and op at load time
[email protected] Mon, 27 Jul 2026 14:50:24 +0000
| Newsgroups | org.kernel.vger.selinux |
|---|---|
| Message-ID | <[email protected]> |
> read_cons_helper() validates the expression type and stack depth > of each constraint node but leaves e->attr and e->op unchecked, > so a policy with an invalid operator or attribute value is > accepted at load and only detected when the constraint is evaluated. > constraint_expr_eval() handles such unrecognized cases with BUG() > so the first permission check that reaches such a node oopses in > the context of the checking process or panics with panic_on_oops. > > Reject these expresssions when the policy is loaded, matching what > the libsepol validator already does. > > Signed-off-by: Stephen Smalley <[email protected]> Sashiko has reviewed this patch and found no issues. It looks great! -- Sashiko AI review ยท https://sashiko.dev/#/patchset/[email protected]?part=1