[PATCH 3/6] ipe: check parser token table sizes

Fan Wu wufan at kernel.org
Sat Oct 3 02:51:32 UTC 2026


The parser token tables contain one entry for each enum value followed
by a terminator. Add static assertions so adding an enum value without a
corresponding token fails the build.

Assisted-by: LLM
Signed-off-by: Fan Wu <wufan at kernel.org>
---
 security/ipe/policy_parser.c | 8 ++++++++
 1 file changed, 8 insertions(+)

diff --git a/security/ipe/policy_parser.c b/security/ipe/policy_parser.c
index f1c05e53667f..309a61594e1d 100644
--- a/security/ipe/policy_parser.c
+++ b/security/ipe/policy_parser.c
@@ -128,6 +128,8 @@ static const match_table_t header_tokens = {
 	{__IPE_HEADER_MAX,		NULL}
 };
 
+static_assert(ARRAY_SIZE(header_tokens) == __IPE_HEADER_MAX + 1);
+
 /**
  * parse_header() - Parse policy header information.
  * @line: Supplies header line to be parsed.
@@ -240,6 +242,8 @@ static const match_table_t operation_tokens = {
 	{IPE_OP_INVALID,		NULL}
 };
 
+static_assert(ARRAY_SIZE(operation_tokens) == __IPE_OP_MAX + 1);
+
 /**
  * parse_operation() - Parse the operation type given a token string.
  * @t: Supplies the token string to be parsed.
@@ -259,6 +263,8 @@ static const match_table_t action_tokens = {
 	{IPE_ACTION_INVALID,	NULL}
 };
 
+static_assert(ARRAY_SIZE(action_tokens) == __IPE_ACTION_MAX + 1);
+
 /**
  * parse_action() - Parse the action type given a token string.
  * @t: Supplies the token string to be parsed.
@@ -284,6 +290,8 @@ static const match_table_t property_tokens = {
 	{IPE_PROP_INVALID,		NULL}
 };
 
+static_assert(ARRAY_SIZE(property_tokens) == __IPE_PROP_MAX + 1);
+
 /**
  * parse_property() - Parse a rule property given a token string.
  * @t: Supplies the token string to be parsed.
-- 
2.55.0




More information about the Linux-security-module-archive mailing list