diff options
| author | Ondrej Mosnacek <omosnace@redhat.com> | 2019-06-11 10:07:19 +0200 | 
|---|---|---|
| committer | Paul Moore <paul@paul-moore.com> | 2019-06-11 18:35:51 -0400 | 
| commit | aff7ed4851680d0d28ad9f52cd2f99213e1371b2 (patch) | |
| tree | 7cbf055d91e90dadc8116ab0da46148adb8bd1b7 /scripts/gcc-plugins/latent_entropy_plugin.c | |
| parent | 05174c95b83f8aca0c47b87115abb7a6387aafa5 (diff) | |
selinux: log raw contexts as untrusted strings
These strings may come from untrusted sources (e.g. file xattrs) so they
need to be properly escaped.
Reproducer:
    # setenforce 0
    # touch /tmp/test
    # setfattr -n security.selinux -v 'kuřecí řízek' /tmp/test
    # runcon system_u:system_r:sshd_t:s0 cat /tmp/test
    (look at the generated AVCs)
Actual result:
    type=AVC [...] trawcon=kuřecí řízek
Expected result:
    type=AVC [...] trawcon=6B75C5996563C3AD20C599C3AD7A656B
Fixes: fede148324c3 ("selinux: log invalid contexts in AVCs")
Cc: stable@vger.kernel.org # v5.1+
Signed-off-by: Ondrej Mosnacek <omosnace@redhat.com>
Acked-by: Richard Guy Briggs <rgb@redhat.com>
Signed-off-by: Paul Moore <paul@paul-moore.com>
Diffstat (limited to 'scripts/gcc-plugins/latent_entropy_plugin.c')
0 files changed, 0 insertions, 0 deletions
