aboutsummaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorMimi Zohar <zohar@linux.vnet.ibm.com>2011-06-15 21:19:10 -0400
committerMimi Zohar <zohar@linux.vnet.ibm.com>2011-07-18 12:29:45 -0400
commit823eb1ccd0b310449e99c822412ea8208334d14c (patch)
tree649d04ab6042cf058f7849dd826ef74a2d556628
parentcb72318069d5e92eb74840118732c66eb38c812f (diff)
evm: call evm_inode_init_security from security_inode_init_security
Changelog v7: - moved the initialization call to security_inode_init_security, renaming evm_inode_post_init_security to evm_inode_init_security - increase size of xattr array for EVM xattr Signed-off-by: Mimi Zohar <zohar@us.ibm.com>
-rw-r--r--security/security.c18
1 files changed, 12 insertions, 6 deletions
diff --git a/security/security.c b/security/security.c
index 21a79b3d1e8e..181990ae90c1 100644
--- a/security/security.c
+++ b/security/security.c
@@ -20,7 +20,7 @@
20#include <linux/ima.h> 20#include <linux/ima.h>
21#include <linux/evm.h> 21#include <linux/evm.h>
22 22
23#define MAX_LSM_XATTR 1 23#define MAX_LSM_EVM_XATTR 2
24 24
25/* Boot-time LSM user choice */ 25/* Boot-time LSM user choice */
26static __initdata char chosen_lsm[SECURITY_NAME_MAX + 1] = 26static __initdata char chosen_lsm[SECURITY_NAME_MAX + 1] =
@@ -346,8 +346,8 @@ int security_inode_init_security(struct inode *inode, struct inode *dir,
346 const struct qstr *qstr, 346 const struct qstr *qstr,
347 const initxattrs initxattrs, void *fs_data) 347 const initxattrs initxattrs, void *fs_data)
348{ 348{
349 struct xattr new_xattrs[MAX_LSM_XATTR + 1]; 349 struct xattr new_xattrs[MAX_LSM_EVM_XATTR + 1];
350 struct xattr *lsm_xattr; 350 struct xattr *lsm_xattr, *evm_xattr, *xattr;
351 int ret; 351 int ret;
352 352
353 if (unlikely(IS_PRIVATE(inode))) 353 if (unlikely(IS_PRIVATE(inode)))
@@ -364,11 +364,17 @@ int security_inode_init_security(struct inode *inode, struct inode *dir,
364 &lsm_xattr->value_len); 364 &lsm_xattr->value_len);
365 if (ret) 365 if (ret)
366 goto out; 366 goto out;
367
368 evm_xattr = lsm_xattr + 1;
369 ret = evm_inode_init_security(inode, lsm_xattr, evm_xattr);
370 if (ret)
371 goto out;
367 ret = initxattrs(inode, new_xattrs, fs_data); 372 ret = initxattrs(inode, new_xattrs, fs_data);
368out: 373out:
369 kfree(lsm_xattr->name); 374 for (xattr = new_xattrs; xattr->name != NULL; xattr++) {
370 kfree(lsm_xattr->value); 375 kfree(xattr->name);
371 376 kfree(xattr->value);
377 }
372 return (ret == -EOPNOTSUPP) ? 0 : ret; 378 return (ret == -EOPNOTSUPP) ? 0 : ret;
373} 379}
374EXPORT_SYMBOL(security_inode_init_security); 380EXPORT_SYMBOL(security_inode_init_security);