[bug report] apparmor: add support loading per permission tagging
John Johansen
john.johansen at canonical.com
Wed Jun 10 23:12:49 UTC 2026
On 4/10/26 03:16, Dan Carpenter wrote:
> Hello John Johansen,
>
> Commit 3d28e2397af7 ("apparmor: add support loading per permission
> tagging") from Apr 1, 2025 (linux-next), leads to the following
> Smatch static checker warning:
>
> security/apparmor/policy_unpack.c:883 unpack_tags()
> warn: missing error code 'error'
>
Sorry for late reply, I am slowly working through the backlog
A managed to get a fix for this into 7.1
72971e6f745ad apparmor: fix unpack_tags to properly return error in failure cases
thanks
john
> security/apparmor/policy_unpack.c
> 852 static int unpack_tags(struct aa_ext *e, struct aa_tags_struct *tags,
> 853 const char **info)
> 854 {
> 855 int error = -EPROTO;
> 856 void *pos = e->pos;
> 857
> 858 AA_BUG(!tags);
> 859 /* policy tags are optional */
> 860 if (aa_unpack_nameX(e, AA_STRUCT, "tags")) {
> 861 u32 version;
> 862
> 863 if (!aa_unpack_u32(e, &version, "version") || version != 1) {
> 864 *info = "invalid tags version";
> 865 goto fail_reset;
> 866 }
> 867 error = unpack_strs_table(e, "strs", true, &tags->strs);
> 868 if (error) {
> 869 *info = "failed to unpack profile tag.strs";
> 870 goto fail;
> 871 }
> 872 error = unpack_tag_headers(e, tags);
> 873 if (error) {
> 874 *info = "failed to unpack profile tag.headers";
> 875 goto fail;
> 876 }
> 877 error = unpack_tagsets(e, tags);
> 878 if (error) {
> 879 *info = "failed to unpack profile tag.sets";
> 880 goto fail;
> 881 }
> 882 if (!aa_unpack_nameX(e, AA_STRUCTEND, NULL))
> --> 883 goto fail;
>
> set the error code here
>
> 884
> 885 if (!verify_tags(tags, info))
> 886 goto fail;
>
> and here
>
> 887 }
> 888
> 889 return 0;
> 890
> 891 fail:
> 892 aa_destroy_tags(tags);
> 893 fail_reset:
> 894 e->pos = pos;
> 895 return error;
> 896 }
>
> This email is a free service from the Smatch-CI project [smatch.sf.net].
>
> regards,
> dan carpenter
More information about the Linux-security-module-archive
mailing list