提交 065d78a0 编写于 作者: T Tetsuo Handa 提交者: James Morris

LSM: Fix security_module_enable() error.

We can set default LSM module to DAC (which means "enable no LSM module").
If default LSM module was set to DAC, security_module_enable() must return 0
unless overridden via boot time parameter.
Signed-off-by: NTetsuo Handa <penguin-kernel@I-love.SAKURA.ne.jp>
Acked-by: NSerge E. Hallyn <serge@hallyn.com>
Signed-off-by: NJames Morris <jmorris@namei.org>
上级 daa6d83a
...@@ -89,20 +89,12 @@ __setup("security=", choose_lsm); ...@@ -89,20 +89,12 @@ __setup("security=", choose_lsm);
* Return true if: * Return true if:
* -The passed LSM is the one chosen by user at boot time, * -The passed LSM is the one chosen by user at boot time,
* -or the passed LSM is configured as the default and the user did not * -or the passed LSM is configured as the default and the user did not
* choose an alternate LSM at boot time, * choose an alternate LSM at boot time.
* -or there is no default LSM set and the user didn't specify a
* specific LSM and we're the first to ask for registration permission,
* -or the passed LSM is currently loaded.
* Otherwise, return false. * Otherwise, return false.
*/ */
int __init security_module_enable(struct security_operations *ops) int __init security_module_enable(struct security_operations *ops)
{ {
if (!*chosen_lsm) return !strcmp(ops->name, chosen_lsm);
strncpy(chosen_lsm, ops->name, SECURITY_NAME_MAX);
else if (strncmp(ops->name, chosen_lsm, SECURITY_NAME_MAX))
return 0;
return 1;
} }
/** /**
......
Markdown is supported
0% .
You are about to add 0 people to the discussion. Proceed with caution.
先完成此消息的编辑!
想要评论请 注册