Re: [PATCH] libsepol: reject policies with no avtab entries in expand_module()

Stephen Smalley <[email protected]>
Newsgroups org.kernel.vger.selinux
Message-ID <CAEjxPJ42hQhx66icUnDzhgHhe62xbKKEzNRNAoCBHpRouyixeg@mail.gmail.com>
On Tue, Aug 4, 2026 at 11:04 AM Stephen Smalley
<[email protected]> wrote:
>
> avtab_read() already rejects policies that have no avtab entries in
> both libsepol and the kernel, but expand_module() can produce a
> policydb that has none. Check and reject such policies in
> expand_module() so that checkpolicy (and its fuzzer) will fail rather
> than writing out an invalid binary policy.
>
> Reported-by: oss-fuzz (issue 541553475)
> Signed-off-by: Stephen Smalley <[email protected]>

This breaks test-expander in libsepol; apparently some of the test
policies there lack any avrules.
Should I fix the test policies, or is this change incorrect?
Also seems to run afoul of sanitizers due to memory leak on failed
expand_modules().

> ---
>  libsepol/src/expand.c | 5 +++++
>  1 file changed, 5 insertions(+)
>
> diff --git a/libsepol/src/expand.c b/libsepol/src/expand.c
> index 8cb62d82..466d5bc1 100644
> --- a/libsepol/src/expand.c
> +++ b/libsepol/src/expand.c
> @@ -3494,6 +3494,11 @@ int expand_module(sepol_handle_t *handle, policydb_t *base, policydb_t *out,
>                 goto cleanup;
>         }
>
> +       if (out->te_avtab.nel == 0) {
> +               ERR(handle, "avtab must contain at least one entry");
> +               goto cleanup;
> +       }
> +
>         /* copy constraints */
>         if (hashtab_map(state.base->p_classes.table, constraint_copy_callback,
>                         &state)) {
> --
> 2.55.0
>
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.