git: 5d0b87669a91 - main - mac_bsdextended: reject negative rule indices in sysctl_rule()

From: Mark Johnston <markj_at_FreeBSD.org>
Date: Wed, 16 Sep 2026 15:35:09 UTC
The branch main has been updated by markj:

URL: https://cgit.FreeBSD.org/src/commit/?id=5d0b87669a91244e330a35fc973e6c60f92f6d1f

commit 5d0b87669a91244e330a35fc973e6c60f92f6d1f
Author:     Andrew Griffiths <andrew@calif.io>
AuthorDate: 2026-09-16 13:04:46 +0000
Commit:     Mark Johnston <markj@FreeBSD.org>
CommitDate: 2026-09-16 15:34:31 +0000

    mac_bsdextended: reject negative rule indices in sysctl_rule()
    
    The security.mac.bsdextended.rules.<N> node handler takes N as
    `index = name[0]` (a signed int) and only checks
    `index >= MAC_BSDEXTENDED_MAXRULES`.  A negative index is caught on
    the read branch, but the write-only add and delete
    branches proceed to `rules[index]` unconditionally.
    
    Reject `index < 0` alongside the existing upper-bound check.
    
    Submitted by calif.io for the OpenAI Patch The Planet program
    
    Signed-off-by: Andrew Griffiths <andrew@calif.io>
    
    Reviewed by:    markj
    MFC after:      2 weeks
---
 sys/security/mac_bsdextended/mac_bsdextended.c | 4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)

diff --git a/sys/security/mac_bsdextended/mac_bsdextended.c b/sys/security/mac_bsdextended/mac_bsdextended.c
index bf95c008e2f2..5047a723fe01 100644
--- a/sys/security/mac_bsdextended/mac_bsdextended.c
+++ b/sys/security/mac_bsdextended/mac_bsdextended.c
@@ -143,7 +143,7 @@ sysctl_rule(SYSCTL_HANDLER_ARGS)
 	if (namelen != 1)
 		return (EINVAL);
 	index = name[0];
-        if (index >= MAC_BSDEXTENDED_MAXRULES)
+	if (index < 0 || index >= MAC_BSDEXTENDED_MAXRULES)
 		return (ENOENT);
 
 	ruleptr = NULL;
@@ -157,7 +157,7 @@ sysctl_rule(SYSCTL_HANDLER_ARGS)
 
 	mtx_lock(&ugidfw_mtx);
 	if (req->oldptr) {
-		if (index < 0 || index > rule_slots + 1) {
+		if (index > rule_slots + 1) {
 			error = ENOENT;
 			goto out;
 		}