diff options
| author | Kees Cook <keescook@chromium.org> | 2023-08-17 13:22:17 -0700 | 
|---|---|---|
| committer | Paul Moore <paul@paul-moore.com> | 2023-09-12 16:58:40 -0400 | 
| commit | 34df25517a9bbec3436ab6f53074bcce9dc3eafc (patch) | |
| tree | e22c444e46fe5fb2b8694abf6e21126199677fbc /lib/net_utils.c | |
| parent | 0bb80ecc33a8fb5a682236443c1e740d5c917d1d (diff) | |
selinux: Annotate struct sidtab_str_cache with __counted_by
Prepare for the coming implementation by GCC and Clang of the __counted_by
attribute. Flexible array members annotated with __counted_by can have
their accesses bounds-checked at run-time checking via CONFIG_UBSAN_BOUNDS
(for array indexing) and CONFIG_FORTIFY_SOURCE (for strcpy/memcpy-family
functions).
As found with Coccinelle[1], add __counted_by for struct sidtab_str_cache.
[1] https://github.com/kees/kernel-tools/blob/trunk/coccinelle/examples/counted_by.cocci
Cc: Paul Moore <paul@paul-moore.com>
Cc: Stephen Smalley <stephen.smalley.work@gmail.com>
Cc: Eric Paris <eparis@parisplace.org>
Cc: Ondrej Mosnacek <omosnace@redhat.com>
Cc: selinux@vger.kernel.org
Signed-off-by: Kees Cook <keescook@chromium.org>
Reviewed-by: "Gustavo A. R. Silva" <gustavoars@kernel.org>
Signed-off-by: Paul Moore <paul@paul-moore.com>
Diffstat (limited to 'lib/net_utils.c')
0 files changed, 0 insertions, 0 deletions
