Re: [PATCH] libsepol: Free context on genfscon wildcard error in kernel_to_*

Stephen Smalley <[email protected]>
Newsgroups org.kernel.vger.selinux
Message-ID <CAEjxPJ4oMi6HuVhPrnzOqC45j27TaN7uzhncpjb1sYgnqebw+w@mail.gmail.com>
On Wed, Aug 12, 2026 at 11:58 AM James Carter <[email protected]> wrote:
>
> A policy with the policy capability genfs_seclabel_wildcard should
> have all of its genfscon paths end with "*" (which is added for
> backwards compatibility when compiling the policy). When converting
> a kernel policy to CIL or a policy.conf, an error occurs if the
> genfscon path does not end with "*". On this error path the context
> is not freed in either kernel_to_cil or kernel_to_conf.
>
> Free the context when exiting with an error for a genfscon path not
> ending with a "*" when required.
>
> Signed-off-by: James Carter <[email protected]>

Acked-by: Stephen Smalley <[email protected]>
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.