diff options
author | Stephen Smalley <sds@tycho.nsa.gov> | 2018-12-12 10:10:56 -0500 |
---|---|---|
committer | Paul Moore <paul@paul-moore.com> | 2019-01-10 20:34:37 -0500 |
commit | e46e01eebbbcf2ff6d28ee7cae9f117e9d1572c8 (patch) | |
tree | 21fb06603d0a98d0146053922e1a93ba5ded5817 /security/selinux/include | |
parent | 3a28cff3bd4bf43f02be0c4e7933aebf3dc8197e (diff) | |
download | blackbird-op-linux-e46e01eebbbcf2ff6d28ee7cae9f117e9d1572c8.tar.gz blackbird-op-linux-e46e01eebbbcf2ff6d28ee7cae9f117e9d1572c8.zip |
selinux: stop passing MAY_NOT_BLOCK to the AVC upon follow_link
commit bda0be7ad9948 ("security: make inode_follow_link RCU-walk aware")
switched selinux_inode_follow_link() to use avc_has_perm_flags() and
pass down the MAY_NOT_BLOCK flag if called during RCU walk. However,
the only test of MAY_NOT_BLOCK occurs during slow_avc_audit()
and only if passing an inode as audit data (LSM_AUDIT_DATA_INODE). Since
selinux_inode_follow_link() passes a dentry directly, passing MAY_NOT_BLOCK
here serves no purpose. Switch selinux_inode_follow_link() to use
avc_has_perm() and drop avc_has_perm_flags() since there are no other
users.
Signed-off-by: Stephen Smalley <sds@tycho.nsa.gov>
Signed-off-by: Paul Moore <paul@paul-moore.com>
Diffstat (limited to 'security/selinux/include')
-rw-r--r-- | security/selinux/include/avc.h | 5 |
1 files changed, 0 insertions, 5 deletions
diff --git a/security/selinux/include/avc.h b/security/selinux/include/avc.h index 74ea50977c20..7be0e1e90e8b 100644 --- a/security/selinux/include/avc.h +++ b/security/selinux/include/avc.h @@ -153,11 +153,6 @@ int avc_has_perm(struct selinux_state *state, u32 ssid, u32 tsid, u16 tclass, u32 requested, struct common_audit_data *auditdata); -int avc_has_perm_flags(struct selinux_state *state, - u32 ssid, u32 tsid, - u16 tclass, u32 requested, - struct common_audit_data *auditdata, - int flags); int avc_has_extended_perms(struct selinux_state *state, u32 ssid, u32 tsid, u16 tclass, u32 requested, |