Re: [PATCH v2 12/40] selinux: reject writable opens of policy file, drop mmap shared/write check

From: Paul Moore

Date: Mon Sep 14 2026 - 16:00:08 EST


On Mon, Sep 14, 2026 at 11:05 AM Lorenzo Stoakes (ARM) <ljs@xxxxxxxxxx> wrote:
>
> The policy file has no write method and is exposed read-only (S_IRUGO in
> selinux_files[]), yet sel_open_policy() performs no open mode check, so a
> CAP_DAC_OVERRIDE caller can open it O_RDWR. Reject FMODE_WRITE at open, as
> kernfs does.
>
> The file can then never be mapped with FMODE_WRITE, so do_mmap() always
> clears VM_MAYWRITE and VM_SHARED for MAP_SHARED mappings and the VM_SHARED
> check in sel_mmap_policy() cannot be reached. Remove it.
>
> This also stops sel_mmap_policy() clearing VM_MAYWRITE on a mapping that is
> neither a PFN map nor a mixed map, ahead of the core enforcing that only
> such mappings may do so.
>
> Acked-by: Stephen Smalley <stephen.smalley.work@xxxxxxxxx>
> Reviewed-by: Jann Horn <jannh@xxxxxxxxxx>
> Signed-off-by: Lorenzo Stoakes (ARM) <ljs@xxxxxxxxxx>
> ---
> security/selinux/selinuxfs.c | 11 +++--------
> 1 file changed, 3 insertions(+), 8 deletions(-)

Acked-by: Paul Moore <paul@xxxxxxxxxxxxxx>

--
paul-moore.com