Re: [PATCH] LSM: Fix type of id parameter in kernel_post_load_data prototype

From: Kees Cook
Date: Wed Oct 07 2020 - 03:02:22 EST


On Tue, Oct 06, 2020 at 01:11:15PM -0700, Nathan Chancellor wrote:
> Clang warns:
>
> security/security.c:1716:59: warning: implicit conversion from
> enumeration type 'enum kernel_load_data_id' to different enumeration
> type 'enum kernel_read_file_id' [-Wenum-conversion]
> ret = call_int_hook(kernel_post_load_data, 0, buf, size, id,
> ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~^~~
> security/security.c:715:22: note: expanded from macro 'call_int_hook'
> RC = P->hook.FUNC(__VA_ARGS__); \
> ~ ^~~~~~~~~~~
> 1 warning generated.
>
> There is a mismatch between the id parameter type in
> security_kernel_post_load_data and the function pointer prototype that
> is created by the LSM_HOOK macro in the security_list_options union. Fix
> the type in the LSM_HOOK macro as 'enum kernel_load_data_id' is what is
> expected.
>
> Fixes: b64fcae74b6d ("LSM: Introduce kernel_post_load_data() hook")
> Link: https://github.com/ClangBuiltLinux/linux/issues/1172
> Signed-off-by: Nathan Chancellor <natechancellor@xxxxxxxxx>

Ah yes; thank you! Greg, can you add this to your tree?

Acked-by: Kees Cook <keescook@xxxxxxxxxxxx>

-Kees

> ---
> include/linux/lsm_hook_defs.h | 2 +-
> 1 file changed, 1 insertion(+), 1 deletion(-)
>
> diff --git a/include/linux/lsm_hook_defs.h b/include/linux/lsm_hook_defs.h
> index d67cb3502310..32a940117e7a 100644
> --- a/include/linux/lsm_hook_defs.h
> +++ b/include/linux/lsm_hook_defs.h
> @@ -186,7 +186,7 @@ LSM_HOOK(int, 0, kernel_create_files_as, struct cred *new, struct inode *inode)
> LSM_HOOK(int, 0, kernel_module_request, char *kmod_name)
> LSM_HOOK(int, 0, kernel_load_data, enum kernel_load_data_id id, bool contents)
> LSM_HOOK(int, 0, kernel_post_load_data, char *buf, loff_t size,
> - enum kernel_read_file_id id, char *description)
> + enum kernel_load_data_id id, char *description)
> LSM_HOOK(int, 0, kernel_read_file, struct file *file,
> enum kernel_read_file_id id, bool contents)
> LSM_HOOK(int, 0, kernel_post_read_file, struct file *file, char *buf,
>
> base-commit: dba8648dcab90564b8a11c952c06a9e1153506fb
> --
> 2.29.0.rc0
>

--
Kees Cook