policycoreutils/0050-sandbox-seunshare-drop-k-kill-support.patch
Petr Lautrbach 400e2f2208 policycoreutils-3.6-9
- Several sandbox and seunshare security improvements
- https://github.com/SELinuxProject/selinux/security/advisories/GHSA-h4m3-rc99-c7m5

Resolves: RHEL-212364
2026-08-04 17:21:22 +02:00

131 lines
3.0 KiB
Diff

From 6ee3f8a59640483ec04cc74e44c7b88f631c700e Mon Sep 17 00:00:00 2001
From: Stephen Smalley <stephen.smalley.work@gmail.com>
Date: Thu, 21 May 2026 11:54:44 -0400
Subject: [PATCH] sandbox/seunshare: drop -k/--kill support
Content-type: text/plain
Drop the -k/--kill support; it is fundamentally racy, redundant
with killall -Z, and seemingly unused by sandbox itself.
Provide an error message to the user telling them how to achieve
the same effect via killall.
Signed-off-by: Stephen Smalley <stephen.smalley.work@gmail.com>
---
sandbox/seunshare.c | 93 +--------------------------------------------
1 file changed, 1 insertion(+), 92 deletions(-)
diff --git a/sandbox/seunshare.c b/sandbox/seunshare.c
index ac749d4ca69c..814d003d310f 100644
--- a/sandbox/seunshare.c
+++ b/sandbox/seunshare.c
@@ -710,97 +710,6 @@ good:
return tmpdir;
}
-#define PROC_BASE "/proc"
-
-static int
-killall (const char *execcon)
-{
- DIR *dir;
- char *scon;
- struct dirent *de;
- pid_t *pid_table, pid, self;
- unsigned int i;
- unsigned int pids, max_pids;
- int running = 0;
- self = getpid();
- if (!(dir = opendir(PROC_BASE))) {
- return -1;
- }
- max_pids = 256;
- pid_table = malloc(max_pids * sizeof (pid_t));
- if (!pid_table) {
- (void)closedir(dir);
- return -1;
- }
- pids = 0;
- context_t con = context_new(execcon);
- if (!con) {
- free(pid_table);
- (void)closedir(dir);
- return -1;
- }
- const char *const mcs = context_range_get(con);
- const char *const type = context_type_get(con);
- if (!mcs || !type) {
- context_free(con);
- free(pid_table);
- (void)closedir(dir);
- return -1;
- }
- if (verbose)
- printf("mcs=%s type=%s\n", mcs, type);
- while ((de = readdir (dir)) != NULL) {
- if (!(pid = (pid_t)atoi(de->d_name)) || pid == self)
- continue;
-
- if (pids == max_pids) {
- max_pids *= 2;
- if (max_pids <= pids)
- {
- free(pid_table);
- (void)closedir(dir);
- return -1;
- }
- pid_t *new_pid_table = reallocarray(pid_table, max_pids, sizeof(pid_t));
- if (!new_pid_table) {
- free(pid_table);
- (void)closedir(dir);
- return -1;
- }
- pid_table = new_pid_table;
- }
- pid_table[pids++] = pid;
- }
-
- (void)closedir(dir);
-
- for (i = 0; i < pids; i++) {
- pid_t id = pid_table[i];
-
- if (getpidcon(id, &scon) == 0) {
-
- context_t pidcon = context_new(scon);
- if (pidcon) {
- const char *const pmcs = context_range_get(pidcon);
- const char *const ptype = context_type_get(pidcon);
-
- /* Attempt to kill remaining processes */
- if (pmcs && ptype && !strcmp(pmcs, mcs) &&
- !strcmp(ptype, type))
- kill(id, SIGKILL);
-
- context_free(pidcon);
- }
- freecon(scon);
- }
- running++;
- }
-
- context_free(con);
- free(pid_table);
- return running;
-}
-
int main(int argc, char **argv) {
int status = -1;
const char *execcon = NULL;
@@ -1253,7 +1162,7 @@ childerr:
kill(-child,SIGTERM);
if (execcon && kill_all)
- killall(execcon);
+ fprintf(stderr, "-k/--kill no longer supported; run killall -Z %s\n", execcon);
if (tmpdir_r) cleanup_tmpdir(tmpdir_r, tmpdir_s, pwd, 1);
--
2.55.0