Files
linux/security
Stephen Smalley fd6e2388a3 selinux: validate constraint expression attr and op at load time
read_cons_helper() validates the expression type and stack depth
of each constraint node but leaves e->attr and e->op unchecked,
so a policy with an invalid operator or attribute value is
accepted at load and only detected when the constraint is evaluated.
constraint_expr_eval() handles such unrecognized cases with BUG()
so the first permission check that reaches such a node oopses in
the context of the checking process or panics with panic_on_oops.

Reject these expresssions when the policy is loaded, matching what
the libsepol validator already does.

Signed-off-by: Stephen Smalley <stephen.smalley.work@gmail.com>
Signed-off-by: Paul Moore <paul@paul-moore.com>
2026-07-27 17:17:33 -04:00
..
2026-04-03 16:53:50 -04:00
2026-04-03 16:53:50 -04:00