• E
    SELinux: reset the security_ops before flushing the avc cache · af8ff049
    Eric Paris 提交于
    This patch resets the security_ops to the secondary_ops before it flushes
    the avc.  It's still possible that a task on another processor could have
    already passed the security_ops dereference and be executing an selinux hook
    function which would add a new avc entry.  That entry would still not be
    freed.  This should however help to reduce the number of needless avcs the
    kernel has when selinux is disabled at run time.  There is no wasted
    memory if selinux is disabled on the command line or not compiled.
    Signed-off-by: NEric Paris <eparis@redhat.com>
    Signed-off-by: NJames Morris <jmorris@namei.org>
    af8ff049
hooks.c 140.9 KB