diff options
| author | Christian Göttsche <cgzones@googlemail.com> | 2026-09-03 13:43:38 +0200 |
|---|---|---|
| committer | Paul Moore <paul@paul-moore.com> | 2026-09-15 17:51:31 -0400 |
| commit | 8861db305103107199b1426f25fde1fb6d465583 (patch) | |
| tree | 019c85ed5022b0acec9a218ab8fc56b7ec2aa606 /security | |
| parent | df2908090cda368b01ff43709f51890076c56157 (diff) | |
| download | linux-next-8861db305103107199b1426f25fde1fb6d465583.tar.gz linux-next-8861db305103107199b1426f25fde1fb6d465583.zip | |
selinux: always fill AVC decision in avc_has_perm_noaudit()
avc_has_perm_noaudit() is documented to return a copy of the access
decision in @avd, but its early return for an empty requested permission
set leaves the buffer untouched. All callers pass an uninitialized
stack variable and afterwards feed it to avc_audit(), and the inode hook
even stores it in the per-task decision cache.
Fill in a deny-all, audit-all decision, similar to avd_init(), so every
caller receives a defined value at no cost on the hot path.
Cc: stable@vger.kernel.org
Fixes: e6f2f381e4015386 ("selinux: replace BUG_ONs with WARN_ONs in avc.c")
Signed-off-by: Christian Göttsche <cgzones@googlemail.com>
Reviewed-by: Stephen Smalley <stephen.smalley.work@gmail.com>
Signed-off-by: Paul Moore <paul@paul-moore.com>
Diffstat (limited to 'security')
| -rw-r--r-- | security/selinux/avc.c | 5 |
1 files changed, 4 insertions, 1 deletions
diff --git a/security/selinux/avc.c b/security/selinux/avc.c index a9401d6c2e5f..560a82c6d682 100644 --- a/security/selinux/avc.c +++ b/security/selinux/avc.c @@ -1149,8 +1149,11 @@ inline int avc_has_perm_noaudit(u32 ssid, u32 tsid, u32 denied; struct avc_node *node; - if (WARN_ON(!requested)) + if (WARN_ON(!requested)) { + /* Provide a deny-all, audit-all decision to the caller. */ + *avd = (struct av_decision){ .auditdeny = 0xffffffff }; return -EACCES; + } rcu_read_lock(); node = avc_lookup(ssid, tsid, tclass); |
