Re: [PATCH 1/4] selinux: do not cancel a policy conversion that never started
Stephen Smalley <[email protected]> Fri, 31 Jul 2026 15:40:52 -0400
| Newsgroups | org.kernel.vger.selinux,org.kernel.vger.linux-kernel |
|---|---|
| Message-ID | <CAEjxPJ7dbZx8tKuR0L4=7dxqVi=mvbf16y3n4X=mVSx+DfhxUw@mail.gmail.com> |
On Fri, Jul 31, 2026 at 1:44=E2=80=AFPM Bryam Vargas via B4 Relay <[email protected]> wrote: > > From: Bryam Vargas <[email protected]> > > sel_write_load() calls selinux_policy_cancel() when sel_make_policy_nodes= () > fails, and that helper dereferences the outgoing policy to cancel its > sidtab conversion. On the first policy load there is no outgoing policy: > security_load_policy() returns early for that case, before it converts > anything, and state->policy is still NULL. A first load that fails while > building the selinuxfs tree therefore takes a NULL dereference in > selinux_policy_cancel(), reached from a write(2) to /sys/fs/selinux/load. > > Skip the cancel when there is no old policy, mirroring the check > security_load_policy() already makes before it converts. > > Fixes: 02a52c5c8c3b ("selinux: move policy commit after updating selinuxf= s") > Cc: [email protected] > Signed-off-by: Bryam Vargas <[email protected]> Acked-by: Stephen Smalley <[email protected]>