Re: [PATCH 4/4] selinux: require every boolean value to be defined

Paul Moore <[email protected]> Mon, 03 Aug 2026 16:03:52 -0400
Newsgroups org.kernel.vger.selinux,org.kernel.vger.linux-kernel
Message-ID <[email protected]>
On Jul 31, 2026 Bryam Vargas <[email protected]> wrote:
> 
> p_bools.nprim comes from the policy image independently of how many
> booleans follow it, and cond_index_bool() fills bool_val_to_struct[] at
> value - 1, so a count larger than the values present leaves NULL entries.
> Every user of that array then walks it by index and dereferences each
> entry: cond_evaluate_expr() on the access-vector path,
> security_get_bools() and security_get_bool_value() behind selinuxfs, and
> security_set_bools(). A sparse class value is absorbed by
> policydb_class_isvalid() and its siblings; booleans have no such
> predicate, and no consumer that could use one.
> 
> Reject a boolean value that no boolean defines, once, where the array is
> built. Conforming policies define every boolean they declare and are
> unaffected.
> 
> Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
> Cc: [email protected]
> Signed-off-by: Bryam Vargas <[email protected]>
> Acked-by: Stephen Smalley <[email protected]>
> ---
>  security/selinux/ss/policydb.c | 19 +++++++++++++++++++
>  1 file changed, 19 insertions(+)

Merged into selinux/stable-7.2, thanks!

--
paul-moore.com