]> git.ipfire.org Git - thirdparty/kernel/linux.git/commitdiff
selinux: fix a type cast problem in cred_init_security()
authorPaul Moore <paul@paul-moore.com>
Thu, 27 Jan 2022 15:45:59 +0000 (10:45 -0500)
committerPaul Moore <paul@paul-moore.com>
Thu, 27 Jan 2022 17:52:43 +0000 (12:52 -0500)
In the process of removing an explicit type cast to preserve a cred
const qualifier in cred_init_security() we ran into a problem where
the task_struct::real_cred field is defined with the "__rcu"
attribute but the selinux_cred() function parameter is not, leading
to a sparse warning:

  security/selinux/hooks.c:216:36: sparse: sparse:
    incorrect type in argument 1 (different address spaces)
    @@     expected struct cred const *cred
    @@     got struct cred const [noderef] __rcu *real_cred

As we don't want to add the "__rcu" attribute to the selinux_cred()
parameter, we're going to add an explicit cast back to
cred_init_security().

Fixes: b084e189b01a ("selinux: simplify cred_init_security")
Reported-by: kernel test robot <lkp@intel.com>
Signed-off-by: Paul Moore <paul@paul-moore.com>
security/selinux/hooks.c

index eae7dbd62df1647e9b68677f7f49e99fea8b26a7..221e642025f536daf30417f1c336caf9c4053923 100644 (file)
@@ -213,7 +213,7 @@ static void cred_init_security(void)
 {
        struct task_security_struct *tsec;
 
-       tsec = selinux_cred(current->real_cred);
+       tsec = selinux_cred(unrcu_pointer(current->real_cred));
        tsec->osid = tsec->sid = SECINITSID_KERNEL;
 }