Re: [PATCH] netlabel: calipso, x509: clean up ADDRSELECT on DOI removal and check AKID len

From: Paul Moore

Date: Sat Sep 19 2026 - 21:22:37 EST


On Sat, Sep 19, 2026 at 6:34 PM Hui Peng <benquike@xxxxxxxxx> wrote:
>
> Fix two issues in netlabel CALIPSO and X.509 key parsing:
>
> 1. In netlbl_calipso_remove_cb() (net/netlabel/netlabel_calipso.c), also
> inspect NETLBL_NLTYPE_ADDRSELECT entries so IPv6 address-selected
> mappings referencing a removed CALIPSO DOI are removed.
> 2. In crypto/asymmetric_keys/x509_public_key.c, guard against zero-
> length signature/AKID fields before key matching.
>
> Fixes: cb72d38211ea ("netlabel: Initial support for the CALIPSO netlink protocol.")
> Assisted-by: LLM
> Signed-off-by: Hui Peng <benquike@xxxxxxxxx>

Thank you for your patch, but as NetLabel and the kernel key code are
in two very different subsystems, please split this into two patches
so they can be properly reviewed and potentially merged.

> diff --git a/crypto/asymmetric_keys/x509_public_key.c b/crypto/asymmetric_keys/x509_public_key.c
> index 25cf8ac7f257..5c9165a83f91 100644
> --- a/crypto/asymmetric_keys/x509_public_key.c
> +++ b/crypto/asymmetric_keys/x509_public_key.c
> @@ -53,9 +53,11 @@ int x509_get_sig_params(struct x509_certificate *cert)
>
> if (sig->algo_takes_data) {
> /* The signature algorithm does whatever passes for hashing. */
> - sig->m = (u8 *)cert->tbs;
> + sig->m = kmemdup(cert->tbs, cert->tbs_size, GFP_KERNEL);
> + if (!sig->m)
> + return -ENOMEM;
> sig->m_size = cert->tbs_size;
> - sig->m_free = false;
> + sig->m_free = true;
> goto out;
> }
>
> diff --git a/net/netlabel/netlabel_calipso.c b/net/netlabel/netlabel_calipso.c
> index e1efd888b4a2..3756193b1c49 100644
> --- a/net/netlabel/netlabel_calipso.c
> +++ b/net/netlabel/netlabel_calipso.c
> @@ -283,10 +283,21 @@ static int netlbl_calipso_listall(struct sk_buff *skb,
> static int netlbl_calipso_remove_cb(struct netlbl_dom_map *entry, void *arg)
> {
> struct netlbl_domhsh_walk_arg *cb_arg = arg;
> + struct netlbl_af6list *iter6;
> + struct netlbl_domaddr6_map *map6;
>
> if (entry->def.type == NETLBL_NLTYPE_CALIPSO &&
> entry->def.calipso->doi == cb_arg->doi)
> return netlbl_domhsh_remove_entry(entry, cb_arg->audit_info);
> + else if (entry->def.type == NETLBL_NLTYPE_ADDRSELECT) {
> + netlbl_af6list_foreach_rcu(iter6, &entry->def.addrsel->list6) {
> + map6 = netlbl_domhsh_addr6_entry(iter6);
> + if (map6->def.type == NETLBL_NLTYPE_CALIPSO &&
> + map6->def.calipso->doi == cb_arg->doi)
> + return netlbl_domhsh_remove_entry(entry,
> + cb_arg->audit_info);
> + }
> + }
>
> return 0;
> }



--
paul-moore.com