From patchwork Fri Jul 28 05:00:42 2023 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Kefeng Wang X-Patchwork-Id: 13331190 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from kanga.kvack.org (kanga.kvack.org [205.233.56.17]) by smtp.lore.kernel.org (Postfix) with ESMTP id E3A43C001DE for ; Fri, 28 Jul 2023 04:48:39 +0000 (UTC) Received: by kanga.kvack.org (Postfix) id 3AB946B007B; Fri, 28 Jul 2023 00:48:38 -0400 (EDT) Received: by kanga.kvack.org (Postfix, from userid 40) id 334B26B007D; Fri, 28 Jul 2023 00:48:38 -0400 (EDT) X-Delivered-To: int-list-linux-mm@kvack.org Received: by kanga.kvack.org (Postfix, from userid 63042) id 1D6C16B007E; Fri, 28 Jul 2023 00:48:38 -0400 (EDT) X-Delivered-To: linux-mm@kvack.org Received: from relay.hostedemail.com (smtprelay0011.hostedemail.com [216.40.44.11]) by kanga.kvack.org (Postfix) with ESMTP id 0B8186B007B for ; Fri, 28 Jul 2023 00:48:38 -0400 (EDT) Received: from smtpin30.hostedemail.com (a10.router.float.18 [10.200.18.1]) by unirelay05.hostedemail.com (Postfix) with ESMTP id C6910407CE for ; Fri, 28 Jul 2023 04:48:37 +0000 (UTC) X-FDA: 81059789874.30.D7288AB Received: from szxga08-in.huawei.com (szxga08-in.huawei.com [45.249.212.255]) by imf19.hostedemail.com (Postfix) with ESMTP id 180DE1A001C for ; Fri, 28 Jul 2023 04:48:34 +0000 (UTC) Authentication-Results: imf19.hostedemail.com; dkim=none; spf=pass (imf19.hostedemail.com: domain of wangkefeng.wang@huawei.com designates 45.249.212.255 as permitted sender) smtp.mailfrom=wangkefeng.wang@huawei.com; dmarc=pass (policy=quarantine) header.from=huawei.com ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=hostedemail.com; s=arc-20220608; t=1690519716; h=from:from:sender:reply-to:subject:subject:date:date: message-id:message-id:to:to:cc:cc:mime-version:mime-version: content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=VciDaF1eQZ1bIKh/QSRmkEMR+WzJ3A1u3Y3GbRGEwLc=; b=DNMdv7W+WdcknI6mARatBjIIk1J/Qtmc9/eZ4c9epUQ13iRzARzzhdUOMnh5BIAl4izmyn ngjyjG9ah1NTzZGa1ReZl3eDqg2cS8cYsOqjDxbEgFl+aR2JuytWPWOibg9sQminRMfJdT /yDURQtilR3kDsllCzsPVsW9bYXgx3o= ARC-Seal: i=1; s=arc-20220608; d=hostedemail.com; t=1690519716; a=rsa-sha256; cv=none; b=bEbrQhOF5zYyQ25fR37JeYf64dpKNsWUfYi2YwWyL318dMMKCdJ5BjeHvCcwiaNYPzs/9Q vEfRNUInRMYcbsmQd0bxqX1N1feKl+tHoBw+BzvwCiX2LEetvPFPMci6M5JIULfmtclJLs chrgCaeSpaZrygkuxSsJfQS5GNfQ3/U= ARC-Authentication-Results: i=1; imf19.hostedemail.com; dkim=none; spf=pass (imf19.hostedemail.com: domain of wangkefeng.wang@huawei.com designates 45.249.212.255 as permitted sender) smtp.mailfrom=wangkefeng.wang@huawei.com; dmarc=pass (policy=quarantine) header.from=huawei.com Received: from dggpemm100001.china.huawei.com (unknown [172.30.72.57]) by szxga08-in.huawei.com (SkyGuard) with ESMTP id 4RBw9J50qQz1GDKB; Fri, 28 Jul 2023 12:47:32 +0800 (CST) Received: from localhost.localdomain.localdomain (10.175.113.25) by dggpemm100001.china.huawei.com (7.185.36.93) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256) id 15.1.2507.27; Fri, 28 Jul 2023 12:48:26 +0800 From: Kefeng Wang To: Andrew Morton CC: , , , , , , , =?utf-8?q?Christian_G=C3=B6ttsche?= , David Hildenbrand , Felix Kuehling , Alex Deucher , , , , , , , , , , Kefeng Wang Subject: [PATCH v3 3/4] selinux: use vma_is_initial_stack() and vma_is_initial_heap() Date: Fri, 28 Jul 2023 13:00:42 +0800 Message-ID: <20230728050043.59880-4-wangkefeng.wang@huawei.com> X-Mailer: git-send-email 2.41.0 In-Reply-To: <20230728050043.59880-1-wangkefeng.wang@huawei.com> References: <20230728050043.59880-1-wangkefeng.wang@huawei.com> MIME-Version: 1.0 X-Originating-IP: [10.175.113.25] X-ClientProxiedBy: dggems706-chm.china.huawei.com (10.3.19.183) To dggpemm100001.china.huawei.com (7.185.36.93) X-CFilter-Loop: Reflected X-Rspamd-Queue-Id: 180DE1A001C X-Rspam-User: X-Rspamd-Server: rspam11 X-Stat-Signature: okkcykxaktgdjbi7d9kiw969arpkq1o9 X-HE-Tag: 1690519714-46504 X-HE-Meta: U2FsdGVkX1/Fbmmg1tubVsipS/BEa5vjqy1elMqsR2D1hWV4vlZlGDIfA6swQIlo3eNZ0S3WHR5N9P1I4dvJtHrR3hzhEHA80s2j9uJPLkzfxMhCp3DRdJE8zGL3WJvUYKRM7j9GYX+BOBCYNGovanBM5CnQGd/B1G+DYYNicaWTePDMsO+vjL3fWVBV40F+HFAXbse5NDKzSVGcqyhpvY2z7P50D04ZQFKUO3QfEvEWL3buYkDs3BpGBZQxwLItk/r72FOxEIsvpLnC2GOrnf7mcQK81Fm1tjHlXI5KIR2h/NVFZvcDAQ10cZeLUnoYHW2LykdpZuhzELoMpKWoVQzeyB5m+PbfIL3zJwbyaXsxo259pMU8nbZQp88bzpco3w2l++X8tDOXfUaztGRy0a9J9wvHhleoSzSfVnnLV/XNjK/DgeS/UFRiuQwmdzHEp8MR53tq/C0cP6Cpi6JHEhO625+1Kt9GqLFfsw07DE88+HU/EmpxgbrzUnVRbmY2NdzebFmi6zoI/+Ky381jN5gmj1wWtFp4f8BOxdGio1BsWgaUhJOC8QmeF5A0a1PRzS+5ERdi8xfNtdxCnysQtJeQb7wwkV785wef6dARrQUEn9L37NOZnBpdkukR+CNubOQW5ZtYbUuNfmhl1BbFcBZV2NFsn9nOfK49aagJ9v/M+5vksknUir0m/4epxBIdk8zmOyor92JT2ss3q0RE4pi9EZe7RphS5DmOiGgLLuz4aZeJKsr4Ik19p8jIql3i8/NkTxozACpujgYJZXfkk3GFPW6B5JJmHp0x4pRJQEZOrQjCB7zlTTtijHtQg4OAh/I5NpvQxcJhYDT3aV6r9RX/NqhgD/tsNsK3x5ZUcRurdsgNm54WTNih21+4TmVUyT7RUXABPPg9++yOeXEhvDAoEbkoOHK1Z95C/ldaqFgVtkTaRcu0BIQAv65zNjZbLt7IB9LZ9jWP8aTj0O4 sk2HtCMf 56osvoq6XmZg8mMIvnUJMvtPzflefPBObC5z//Hbgd+hixhIJ/K34v86Xx6JzCNxXNlCcFEU4EpGZdyQa6a/i+HyC7m0Qwm/gRAC9pc0Puzh8D4RTaE1LlgXQXE6Le6Avic5BOizMtuBzADwx07QEWT0+QX/48xmOwJu2P9wdRYM142gXjCbPGXJ2/YSvvXMbxpdLsSul7uOPeOOvBxSk6+iN9ra6qH24vaxVqCA4aKLHhYSmRRciuyvnHDpBtVaAA9KO/wBy+RAQIFQfrAP+9rPHVXzP8KkkwbDrhJGCqLmymeBrTdFMYbIfTwQfL3KY0YmtqiDC6BWsoMSrQ7ywVmHIse1HicyhwQRXoG0VOCaF9dYoy3TBjSmj5gTXC5ts6vA4jJKUftiO0ZYHVS0fGgMymezz35SokoTT+iP9gSoalOE= X-Bogosity: Ham, tests=bogofilter, spamicity=0.000000, version=1.2.4 Sender: owner-linux-mm@kvack.org Precedence: bulk X-Loop: owner-majordomo@kvack.org List-ID: Use the helpers to simplify code. Cc: Paul Moore Cc: Stephen Smalley Cc: Eric Paris Acked-by: Paul Moore Reviewed-by: David Hildenbrand Signed-off-by: Kefeng Wang --- security/selinux/hooks.c | 7 ++----- 1 file changed, 2 insertions(+), 5 deletions(-) diff --git a/security/selinux/hooks.c b/security/selinux/hooks.c index c87b79a29fad..ac582c046c51 100644 --- a/security/selinux/hooks.c +++ b/security/selinux/hooks.c @@ -3800,13 +3800,10 @@ static int selinux_file_mprotect(struct vm_area_struct *vma, if (default_noexec && (prot & PROT_EXEC) && !(vma->vm_flags & VM_EXEC)) { int rc = 0; - if (vma->vm_start >= vma->vm_mm->start_brk && - vma->vm_end <= vma->vm_mm->brk) { + if (vma_is_initial_heap(vma)) { rc = avc_has_perm(sid, sid, SECCLASS_PROCESS, PROCESS__EXECHEAP, NULL); - } else if (!vma->vm_file && - ((vma->vm_start <= vma->vm_mm->start_stack && - vma->vm_end >= vma->vm_mm->start_stack) || + } else if (!vma->vm_file && (vma_is_initial_stack(vma) || vma_is_stack_for_current(vma))) { rc = avc_has_perm(sid, sid, SECCLASS_PROCESS, PROCESS__EXECSTACK, NULL);