summaryrefslogtreecommitdiff
path: root/security
diff options
context:
space:
mode:
authorChristian Göttsche <cgzones@googlemail.com>2026-09-03 13:43:38 +0200
committerPaul Moore <paul@paul-moore.com>2026-09-15 17:51:31 -0400
commit8861db305103107199b1426f25fde1fb6d465583 (patch)
tree019c85ed5022b0acec9a218ab8fc56b7ec2aa606 /security
parentdf2908090cda368b01ff43709f51890076c56157 (diff)
downloadlinux-next-8861db305103107199b1426f25fde1fb6d465583.tar.gz
linux-next-8861db305103107199b1426f25fde1fb6d465583.zip
selinux: always fill AVC decision in avc_has_perm_noaudit()
avc_has_perm_noaudit() is documented to return a copy of the access decision in @avd, but its early return for an empty requested permission set leaves the buffer untouched. All callers pass an uninitialized stack variable and afterwards feed it to avc_audit(), and the inode hook even stores it in the per-task decision cache. Fill in a deny-all, audit-all decision, similar to avd_init(), so every caller receives a defined value at no cost on the hot path. Cc: stable@vger.kernel.org Fixes: e6f2f381e4015386 ("selinux: replace BUG_ONs with WARN_ONs in avc.c") Signed-off-by: Christian Göttsche <cgzones@googlemail.com> Reviewed-by: Stephen Smalley <stephen.smalley.work@gmail.com> Signed-off-by: Paul Moore <paul@paul-moore.com>
Diffstat (limited to 'security')
-rw-r--r--security/selinux/avc.c5
1 files changed, 4 insertions, 1 deletions
diff --git a/security/selinux/avc.c b/security/selinux/avc.c
index a9401d6c2e5f..560a82c6d682 100644
--- a/security/selinux/avc.c
+++ b/security/selinux/avc.c
@@ -1149,8 +1149,11 @@ inline int avc_has_perm_noaudit(u32 ssid, u32 tsid,
u32 denied;
struct avc_node *node;
- if (WARN_ON(!requested))
+ if (WARN_ON(!requested)) {
+ /* Provide a deny-all, audit-all decision to the caller. */
+ *avd = (struct av_decision){ .auditdeny = 0xffffffff };
return -EACCES;
+ }
rcu_read_lock();
node = avc_lookup(ssid, tsid, tclass);