Patch "integrity: Use static_assert() to check struct sizes" has been added to the 6.11-stable tree

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



This is a note to let you know that I've just added the patch titled

    integrity: Use static_assert() to check struct sizes

to the 6.11-stable tree which can be found at:
    http://www.kernel.org/git/?p=linux/kernel/git/stable/stable-queue.git;a=summary

The filename of the patch is:
     integrity-use-static_assert-to-check-struct-sizes.patch
and it can be found in the queue-6.11 subdirectory.

If you, or anyone else, feels it should not be added to the stable tree,
please let <stable@xxxxxxxxxxxxxxx> know about it.



commit b834e782f2ef82fe57456805bb99798937e30fa7
Author: Gustavo A. R. Silva <gustavoars@xxxxxxxxxx>
Date:   Thu Aug 8 16:04:59 2024 -0600

    integrity: Use static_assert() to check struct sizes
    
    [ Upstream commit 08ae3e5f5fc8edb9bd0c7ef9696ff29ef18b26ef ]
    
    Commit 38aa3f5ac6d2 ("integrity: Avoid -Wflex-array-member-not-at-end
    warnings") introduced tagged `struct evm_ima_xattr_data_hdr` and
    `struct ima_digest_data_hdr`. We want to ensure that when new members
    need to be added to the flexible structures, they are always included
    within these tagged structs.
    
    So, we use `static_assert()` to ensure that the memory layout for
    both the flexible structure and the tagged struct is the same after
    any changes.
    
    Signed-off-by: Gustavo A. R. Silva <gustavoars@xxxxxxxxxx>
    Tested-by: Roberto Sassu <roberto.sassu@xxxxxxxxxx>
    Reviewed-by: Roberto Sassu <roberto.sassu@xxxxxxxxxx>
    Signed-off-by: Mimi Zohar <zohar@xxxxxxxxxxxxx>
    Signed-off-by: Sasha Levin <sashal@xxxxxxxxxx>

diff --git a/security/integrity/integrity.h b/security/integrity/integrity.h
index 660f76cb69d37..c2c2da6911233 100644
--- a/security/integrity/integrity.h
+++ b/security/integrity/integrity.h
@@ -37,6 +37,8 @@ struct evm_ima_xattr_data {
 	);
 	u8 data[];
 } __packed;
+static_assert(offsetof(struct evm_ima_xattr_data, data) == sizeof(struct evm_ima_xattr_data_hdr),
+	      "struct member likely outside of __struct_group()");
 
 /* Only used in the EVM HMAC code. */
 struct evm_xattr {
@@ -65,6 +67,8 @@ struct ima_digest_data {
 	);
 	u8 digest[];
 } __packed;
+static_assert(offsetof(struct ima_digest_data, digest) == sizeof(struct ima_digest_data_hdr),
+	      "struct member likely outside of __struct_group()");
 
 /*
  * Instead of wrapping the ima_digest_data struct inside a local structure




[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[Index of Archives]     [Linux USB Devel]     [Linux Audio Users]     [Yosemite News]     [Linux Kernel]     [Linux SCSI]

  Powered by Linux