diff options
| author | Linus Torvalds <torvalds@linux-foundation.org> | 2010-10-21 15:41:19 -0400 |
|---|---|---|
| committer | Linus Torvalds <torvalds@linux-foundation.org> | 2010-10-21 15:41:19 -0400 |
| commit | a8fe1500986c32b46b36118aa250f6badca11bfc (patch) | |
| tree | d5517e16e633fa0c54248f27b5921e8ac4e4a459 /security/selinux/ss/avtab.c | |
| parent | 94ebd235c493f43681f609b0e02733337053e8f0 (diff) | |
| parent | f0d3d9894e43fc68d47948e2c6f03e32da88b799 (diff) | |
Merge branch 'for-linus' of git://git.kernel.org/pub/scm/linux/kernel/git/jmorris/security-testing-2.6
* 'for-linus' of git://git.kernel.org/pub/scm/linux/kernel/git/jmorris/security-testing-2.6: (26 commits)
selinux: include vmalloc.h for vmalloc_user
secmark: fix config problem when CONFIG_NF_CONNTRACK_SECMARK is not set
selinux: implement mmap on /selinux/policy
SELinux: allow userspace to read policy back out of the kernel
SELinux: drop useless (and incorrect) AVTAB_MAX_SIZE
SELinux: deterministic ordering of range transition rules
kernel: roundup should only reference arguments once
kernel: rounddown helper function
secmark: export secctx, drop secmark in procfs
conntrack: export lsm context rather than internal secid via netlink
security: secid_to_secctx returns len when data is NULL
secmark: make secmark object handling generic
secmark: do not return early if there was no error
AppArmor: Ensure the size of the copy is < the buffer allocated to hold it
TOMOYO: Print URL information before panic().
security: remove unused parameter from security_task_setscheduler()
tpm: change 'tpm_suspend_pcr' to be module parameter
selinux: fix up style problem on /selinux/status
selinux: change to new flag variable
selinux: really fix dependency causing parallel compile failure.
...
Diffstat (limited to 'security/selinux/ss/avtab.c')
| -rw-r--r-- | security/selinux/ss/avtab.c | 46 |
1 files changed, 44 insertions, 2 deletions
diff --git a/security/selinux/ss/avtab.c b/security/selinux/ss/avtab.c index 929480c6c430..a3dd9faa19c0 100644 --- a/security/selinux/ss/avtab.c +++ b/security/selinux/ss/avtab.c | |||
| @@ -266,8 +266,8 @@ int avtab_alloc(struct avtab *h, u32 nrules) | |||
| 266 | if (shift > 2) | 266 | if (shift > 2) |
| 267 | shift = shift - 2; | 267 | shift = shift - 2; |
| 268 | nslot = 1 << shift; | 268 | nslot = 1 << shift; |
| 269 | if (nslot > MAX_AVTAB_SIZE) | 269 | if (nslot > MAX_AVTAB_HASH_BUCKETS) |
| 270 | nslot = MAX_AVTAB_SIZE; | 270 | nslot = MAX_AVTAB_HASH_BUCKETS; |
| 271 | mask = nslot - 1; | 271 | mask = nslot - 1; |
| 272 | 272 | ||
| 273 | h->htable = kcalloc(nslot, sizeof(*(h->htable)), GFP_KERNEL); | 273 | h->htable = kcalloc(nslot, sizeof(*(h->htable)), GFP_KERNEL); |
| @@ -501,6 +501,48 @@ bad: | |||
| 501 | goto out; | 501 | goto out; |
| 502 | } | 502 | } |
| 503 | 503 | ||
| 504 | int avtab_write_item(struct policydb *p, struct avtab_node *cur, void *fp) | ||
| 505 | { | ||
| 506 | __le16 buf16[4]; | ||
| 507 | __le32 buf32[1]; | ||
| 508 | int rc; | ||
| 509 | |||
| 510 | buf16[0] = cpu_to_le16(cur->key.source_type); | ||
| 511 | buf16[1] = cpu_to_le16(cur->key.target_type); | ||
| 512 | buf16[2] = cpu_to_le16(cur->key.target_class); | ||
| 513 | buf16[3] = cpu_to_le16(cur->key.specified); | ||
| 514 | rc = put_entry(buf16, sizeof(u16), 4, fp); | ||
| 515 | if (rc) | ||
| 516 | return rc; | ||
| 517 | buf32[0] = cpu_to_le32(cur->datum.data); | ||
| 518 | rc = put_entry(buf32, sizeof(u32), 1, fp); | ||
| 519 | if (rc) | ||
| 520 | return rc; | ||
| 521 | return 0; | ||
| 522 | } | ||
| 523 | |||
| 524 | int avtab_write(struct policydb *p, struct avtab *a, void *fp) | ||
| 525 | { | ||
| 526 | unsigned int i; | ||
| 527 | int rc = 0; | ||
| 528 | struct avtab_node *cur; | ||
| 529 | __le32 buf[1]; | ||
| 530 | |||
| 531 | buf[0] = cpu_to_le32(a->nel); | ||
| 532 | rc = put_entry(buf, sizeof(u32), 1, fp); | ||
| 533 | if (rc) | ||
| 534 | return rc; | ||
| 535 | |||
| 536 | for (i = 0; i < a->nslot; i++) { | ||
| 537 | for (cur = a->htable[i]; cur; cur = cur->next) { | ||
| 538 | rc = avtab_write_item(p, cur, fp); | ||
| 539 | if (rc) | ||
| 540 | return rc; | ||
| 541 | } | ||
| 542 | } | ||
| 543 | |||
| 544 | return rc; | ||
| 545 | } | ||
| 504 | void avtab_cache_init(void) | 546 | void avtab_cache_init(void) |
| 505 | { | 547 | { |
| 506 | avtab_node_cachep = kmem_cache_create("avtab_node", | 548 | avtab_node_cachep = kmem_cache_create("avtab_node", |
