• Paul Moore's avatar
    selinux: add proper NULL termination to the secclass_map permissions · e4c82eaf
    Paul Moore authored
    This patch adds the missing NULL termination to the "bpf" and
    "perf_event" object class permission lists.
    
    This missing NULL termination should really only affect the tools
    under scripts/selinux, with the most important being genheaders.c,
    although in practice this has not been an issue on any of my dev/test
    systems.  If the problem were to manifest itself it would likely
    result in bogus permissions added to the end of the object class;
    thankfully with no access control checks using these bogus
    permissions and no policies defining these permissions the impact
    would likely be limited to some noise about undefined permissions
    during policy load.
    
    Cc: stable@vger.kernel.org
    Fixes: ec27c356 ("selinux: bpf: Add selinux check for eBPF syscall operations")
    Fixes: da97e184 ("perf_event: Add support for LSM and SELinux checks")
    Signed-off-by: default avatarPaul Moore <paul@paul-moore.com>
    e4c82eaf
classmap.h 8.19 KB