1. 15 8月, 2013 11 次提交
  2. 25 7月, 2013 1 次提交
  3. 29 6月, 2013 2 次提交
  4. 20 6月, 2013 2 次提交
  5. 09 6月, 2013 6 次提交
  6. 04 6月, 2013 1 次提交
  7. 01 6月, 2013 1 次提交
  8. 29 5月, 2013 5 次提交
  9. 24 5月, 2013 1 次提交
    • T
      device_cgroup: simplify cgroup tree walk in propagate_exception() · d591fb56
      Tejun Heo 提交于
      During a config change, propagate_exception() needs to traverse the
      subtree to update config on the subtree.  Because such config updates
      need to allocate memory, it couldn't directly use
      cgroup_for_each_descendant_pre() which required the whole iteration to
      be contained in a single RCU read critical section.  To work around
      the limitation, propagate_exception() built a linked list of
      descendant cgroups while read-locking RCU and then walked the list
      afterwards, which is safe as the whole iteration is protected by
      devcgroup_mutex.  This works but is cumbersome.
      
      With the recent updates, cgroup iterators now allow dropping RCU read
      lock while iteration is in progress making this workaround no longer
      necessary.  This patch replaces dev_cgroup->propagate_pending list and
      get_online_devcg() with direct cgroup_for_each_descendant_pre() walk.
      Signed-off-by: NTejun Heo <tj@kernel.org>
      Cc: Aristeu Rozanski <aris@redhat.com>
      Acked-by: NSerge E. Hallyn <serge.hallyn@ubuntu.com>
      Reviewed-by: NMichal Hocko <mhocko@suse.cz>
      d591fb56
  10. 13 5月, 2013 1 次提交
    • J
      security: cap_inode_getsecctx returning garbage · 0d422afb
      J. Bruce Fields 提交于
      We shouldn't be returning success from this function without also
      filling in the return values ctx and ctxlen.
      
      Note currently this doesn't appear to cause bugs since the only
      inode_getsecctx caller I can find is fs/sysfs/inode.c, which only calls
      this if security_inode_setsecurity succeeds.  Assuming
      security_inode_setsecurity is set to cap_inode_setsecurity whenever
      inode_getsecctx is set to cap_inode_getsecctx, this function can never
      actually called.
      
      So I noticed this only because the server labeled NFS patches add a real
      caller.
      Acked-by: NSerge E. Hallyn <serge.hallyn@ubuntu.com>
      Signed-off-by: NJ. Bruce Fields <bfields@redhat.com>
      0d422afb
  11. 12 5月, 2013 1 次提交
  12. 08 5月, 2013 1 次提交
  13. 01 5月, 2013 1 次提交
  14. 30 4月, 2013 1 次提交
  15. 28 4月, 2013 5 次提交