* Re: [patch 1/2] security: add const to security_task_setscheduler() [not found] ` <alpine.LRH.2.00.1010050929340.28702@tundra.namei.org> @ 2010-10-05 1:55 ` KOSAKI Motohiro 2010-10-06 23:41 ` James Morris 0 siblings, 1 reply; 3+ messages in thread From: KOSAKI Motohiro @ 2010-10-05 1:55 UTC (permalink / raw) To: James Morris Cc: kosaki.motohiro, akpm, Ingo Molnar, rostedt, linux-security-module, LKML > On Fri, 1 Oct 2010, akpm@linux-foundation.org wrote: > > > From: KOSAKI Motohiro <kosaki.motohiro@jp.fujitsu.com> > > > > All security modules shouldn't change sched_param parameter of > > security_task_setscheduler(). This is not only meaningless, but also make > > harmful result if caller pass static variable. > > Nobody's using this parameter, so probably best to just get rid of it in > the LSM API. To be honest, I don't like completely remove this parameter because security_task_setscheduler(struct task_struct *p) seems not so useful. But, you are maintainer. OK, I've reworked this as you requested :-) Thanks. >From 10bfd5279260f650d489a85c3cca7d35f0529dbb Mon Sep 17 00:00:00 2001 From: KOSAKI Motohiro <kosaki.motohiro@jp.fujitsu.com> Date: Fri, 15 Oct 2010 04:21:18 +0900 Subject: [PATCH] security: remove unused parameter from security_task_setscheduler() All security modules shouldn't change sched_param parameter of security_task_setscheduler(). This is not only meaningless, but also make a harmful result if caller pass a static variable. This patch remove policy and sched_param parameter from security_task_setscheduler() becuase none of security module is using it. Cc: James Morris <jmorris@namei.org> Signed-off-by: KOSAKI Motohiro <kosaki.motohiro@jp.fujitsu.com> --- arch/mips/kernel/mips-mt-fpaff.c | 2 +- include/linux/security.h | 14 +++++--------- kernel/cpuset.c | 4 ++-- kernel/sched.c | 4 ++-- security/commoncap.c | 5 +---- security/security.c | 5 ++--- security/selinux/hooks.c | 4 ++-- security/smack/smack_lsm.c | 5 ++--- 8 files changed, 17 insertions(+), 26 deletions(-) diff --git a/arch/mips/kernel/mips-mt-fpaff.c b/arch/mips/kernel/mips-mt-fpaff.c index 2340f11..9a526ba 100644 --- a/arch/mips/kernel/mips-mt-fpaff.c +++ b/arch/mips/kernel/mips-mt-fpaff.c @@ -103,7 +103,7 @@ asmlinkage long mipsmt_sys_sched_setaffinity(pid_t pid, unsigned int len, if (!check_same_owner(p) && !capable(CAP_SYS_NICE)) goto out_unlock; - retval = security_task_setscheduler(p, 0, NULL); + retval = security_task_setscheduler(p) if (retval) goto out_unlock; diff --git a/include/linux/security.h b/include/linux/security.h index a22219a..294a0b2 100644 --- a/include/linux/security.h +++ b/include/linux/security.h @@ -74,7 +74,7 @@ extern int cap_file_mmap(struct file *file, unsigned long reqprot, extern int cap_task_fix_setuid(struct cred *new, const struct cred *old, int flags); extern int cap_task_prctl(int option, unsigned long arg2, unsigned long arg3, unsigned long arg4, unsigned long arg5); -extern int cap_task_setscheduler(struct task_struct *p, int policy, struct sched_param *lp); +extern int cap_task_setscheduler(struct task_struct *p); extern int cap_task_setioprio(struct task_struct *p, int ioprio); extern int cap_task_setnice(struct task_struct *p, int nice); extern int cap_syslog(int type, bool from_file); @@ -1501,8 +1501,7 @@ struct security_operations { int (*task_getioprio) (struct task_struct *p); int (*task_setrlimit) (struct task_struct *p, unsigned int resource, struct rlimit *new_rlim); - int (*task_setscheduler) (struct task_struct *p, int policy, - struct sched_param *lp); + int (*task_setscheduler) (struct task_struct *p); int (*task_getscheduler) (struct task_struct *p); int (*task_movememory) (struct task_struct *p); int (*task_kill) (struct task_struct *p, @@ -1752,8 +1751,7 @@ int security_task_setioprio(struct task_struct *p, int ioprio); int security_task_getioprio(struct task_struct *p); int security_task_setrlimit(struct task_struct *p, unsigned int resource, struct rlimit *new_rlim); -int security_task_setscheduler(struct task_struct *p, - int policy, struct sched_param *lp); +int security_task_setscheduler(struct task_struct *p); int security_task_getscheduler(struct task_struct *p); int security_task_movememory(struct task_struct *p); int security_task_kill(struct task_struct *p, struct siginfo *info, @@ -2320,11 +2318,9 @@ static inline int security_task_setrlimit(struct task_struct *p, return 0; } -static inline int security_task_setscheduler(struct task_struct *p, - int policy, - struct sched_param *lp) +static inline int security_task_setscheduler(struct task_struct *p) { - return cap_task_setscheduler(p, policy, lp); + return cap_task_setscheduler(p); } static inline int security_task_getscheduler(struct task_struct *p) diff --git a/kernel/cpuset.c b/kernel/cpuset.c index b23c097..51b143e 100644 --- a/kernel/cpuset.c +++ b/kernel/cpuset.c @@ -1397,7 +1397,7 @@ static int cpuset_can_attach(struct cgroup_subsys *ss, struct cgroup *cont, if (tsk->flags & PF_THREAD_BOUND) return -EINVAL; - ret = security_task_setscheduler(tsk, 0, NULL); + ret = security_task_setscheduler(tsk); if (ret) return ret; if (threadgroup) { @@ -1405,7 +1405,7 @@ static int cpuset_can_attach(struct cgroup_subsys *ss, struct cgroup *cont, rcu_read_lock(); list_for_each_entry_rcu(c, &tsk->thread_group, thread_group) { - ret = security_task_setscheduler(c, 0, NULL); + ret = security_task_setscheduler(c); if (ret) { rcu_read_unlock(); return ret; diff --git a/kernel/sched.c b/kernel/sched.c index dc85ceb..df6579d 100644 --- a/kernel/sched.c +++ b/kernel/sched.c @@ -4645,7 +4645,7 @@ recheck: } if (user) { - retval = security_task_setscheduler(p, policy, param); + retval = security_task_setscheduler(p); if (retval) return retval; } @@ -4887,7 +4887,7 @@ long sched_setaffinity(pid_t pid, const struct cpumask *in_mask) if (!check_same_owner(p) && !capable(CAP_SYS_NICE)) goto out_unlock; - retval = security_task_setscheduler(p, 0, NULL); + retval = security_task_setscheduler(p); if (retval) goto out_unlock; diff --git a/security/commoncap.c b/security/commoncap.c index 9d172e6..5e632b4 100644 --- a/security/commoncap.c +++ b/security/commoncap.c @@ -719,14 +719,11 @@ static int cap_safe_nice(struct task_struct *p) /** * cap_task_setscheduler - Detemine if scheduler policy change is permitted * @p: The task to affect - * @policy: The policy to effect - * @lp: The parameters to the scheduling policy * * Detemine if the requested scheduler policy change is permitted for the * specified task, returning 0 if permission is granted, -ve if denied. */ -int cap_task_setscheduler(struct task_struct *p, int policy, - struct sched_param *lp) +int cap_task_setscheduler(struct task_struct *p) { return cap_safe_nice(p); } diff --git a/security/security.c b/security/security.c index c53949f..34a3f2c 100644 --- a/security/security.c +++ b/security/security.c @@ -786,10 +786,9 @@ int security_task_setrlimit(struct task_struct *p, unsigned int resource, return security_ops->task_setrlimit(p, resource, new_rlim); } -int security_task_setscheduler(struct task_struct *p, - int policy, struct sched_param *lp) +int security_task_setscheduler(struct task_struct *p) { - return security_ops->task_setscheduler(p, policy, lp); + return security_ops->task_setscheduler(p); } int security_task_getscheduler(struct task_struct *p) diff --git a/security/selinux/hooks.c b/security/selinux/hooks.c index 4796ddd..db2b331 100644 --- a/security/selinux/hooks.c +++ b/security/selinux/hooks.c @@ -3354,11 +3354,11 @@ static int selinux_task_setrlimit(struct task_struct *p, unsigned int resource, return 0; } -static int selinux_task_setscheduler(struct task_struct *p, int policy, struct sched_param *lp) +static int selinux_task_setscheduler(struct task_struct *p) { int rc; - rc = cap_task_setscheduler(p, policy, lp); + rc = cap_task_setscheduler(p); if (rc) return rc; diff --git a/security/smack/smack_lsm.c b/security/smack/smack_lsm.c index c448d57..174aec4 100644 --- a/security/smack/smack_lsm.c +++ b/security/smack/smack_lsm.c @@ -1281,12 +1281,11 @@ static int smack_task_getioprio(struct task_struct *p) * * Return 0 if read access is permitted */ -static int smack_task_setscheduler(struct task_struct *p, int policy, - struct sched_param *lp) +static int smack_task_setscheduler(struct task_struct *p) { int rc; - rc = cap_task_setscheduler(p, policy, lp); + rc = cap_task_setscheduler(p); if (rc == 0) rc = smk_curacc_on_task(p, MAY_WRITE); return rc; -- 1.6.5.2 ^ permalink raw reply [flat|nested] 3+ messages in thread
* Re: [patch 1/2] security: add const to security_task_setscheduler() 2010-10-05 1:55 ` [patch 1/2] security: add const to security_task_setscheduler() KOSAKI Motohiro @ 2010-10-06 23:41 ` James Morris 0 siblings, 0 replies; 3+ messages in thread From: James Morris @ 2010-10-06 23:41 UTC (permalink / raw) To: KOSAKI Motohiro; +Cc: akpm, Ingo Molnar, rostedt, linux-security-module, LKML On Tue, 5 Oct 2010, KOSAKI Motohiro wrote: > From: KOSAKI Motohiro <kosaki.motohiro@jp.fujitsu.com> > Date: Fri, 15 Oct 2010 04:21:18 +0900 > Subject: [PATCH] security: remove unused parameter from security_task_setscheduler() > > All security modules shouldn't change sched_param parameter of > security_task_setscheduler(). This is not only meaningless, but also > make a harmful result if caller pass a static variable. > > This patch remove policy and sched_param parameter from > security_task_setscheduler() becuase none of security module is > using it. > > Cc: James Morris <jmorris@namei.org> > Signed-off-by: KOSAKI Motohiro <kosaki.motohiro@jp.fujitsu.com> Thanks. Applied to git://git.kernel.org/pub/scm/linux/kernel/git/jmorris/security-testing-2.6#next -- James Morris <jmorris@namei.org> ^ permalink raw reply [flat|nested] 3+ messages in thread
* Re: [PATCH 10/11] oom: give the dying task a higher priority
@ 2010-07-02 21:49 Andrew Morton
2010-07-06 0:49 ` KOSAKI Motohiro
0 siblings, 1 reply; 3+ messages in thread
From: Andrew Morton @ 2010-07-02 21:49 UTC (permalink / raw)
To: KOSAKI Motohiro
Cc: LKML, linux-mm, Minchan Kim, David Rientjes, KAMEZAWA Hiroyuki,
Ingo Molnar, Peter Zijlstra
On Wed, 30 Jun 2010 18:33:23 +0900 (JST)
KOSAKI Motohiro <kosaki.motohiro@jp.fujitsu.com> wrote:
> +static void boost_dying_task_prio(struct task_struct *p,
> + struct mem_cgroup *mem)
> +{
> + struct sched_param param = { .sched_priority = 1 };
> +
> + if (mem)
> + return;
> +
> + if (!rt_task(p))
> + sched_setscheduler_nocheck(p, SCHED_FIFO, ¶m);
> +}
We can actually make `param' static here. That saves a teeny bit of
code and a little bit of stack. The oom-killer can be called when
we're using a lot of stack.
But if we make that change we really should make the param arg to
sched_setscheduler_nocheck() be const. I did that (and was able to
convert lots of callers to use a static `param') but to complete the
job we'd need to chase through all the security goop, fixing up
security_task_setscheduler() and callees, and I got bored.
include/linux/sched.h | 2 +-
kernel/kthread.c | 2 +-
kernel/sched.c | 4 ++--
kernel/softirq.c | 4 +++-
kernel/stop_machine.c | 2 +-
kernel/workqueue.c | 2 +-
6 files changed, 9 insertions(+), 7 deletions(-)
diff -puN kernel/kthread.c~a kernel/kthread.c
--- a/kernel/kthread.c~a
+++ a/kernel/kthread.c
@@ -131,7 +131,7 @@ struct task_struct *kthread_create(int (
wait_for_completion(&create.done);
if (!IS_ERR(create.result)) {
- struct sched_param param = { .sched_priority = 0 };
+ static struct sched_param param = { .sched_priority = 0 };
va_list args;
va_start(args, namefmt);
diff -puN kernel/workqueue.c~a kernel/workqueue.c
--- a/kernel/workqueue.c~a
+++ a/kernel/workqueue.c
@@ -962,7 +962,7 @@ init_cpu_workqueue(struct workqueue_stru
static int create_workqueue_thread(struct cpu_workqueue_struct *cwq, int cpu)
{
- struct sched_param param = { .sched_priority = MAX_RT_PRIO-1 };
+ static struct sched_param param = { .sched_priority = MAX_RT_PRIO-1 };
struct workqueue_struct *wq = cwq->wq;
const char *fmt = is_wq_single_threaded(wq) ? "%s" : "%s/%d";
struct task_struct *p;
diff -puN kernel/stop_machine.c~a kernel/stop_machine.c
--- a/kernel/stop_machine.c~a
+++ a/kernel/stop_machine.c
@@ -291,7 +291,7 @@ repeat:
static int __cpuinit cpu_stop_cpu_callback(struct notifier_block *nfb,
unsigned long action, void *hcpu)
{
- struct sched_param param = { .sched_priority = MAX_RT_PRIO - 1 };
+ static struct sched_param param = { .sched_priority = MAX_RT_PRIO - 1 };
unsigned int cpu = (unsigned long)hcpu;
struct cpu_stopper *stopper = &per_cpu(cpu_stopper, cpu);
struct task_struct *p;
diff -puN kernel/sched.c~a kernel/sched.c
--- a/kernel/sched.c~a
+++ a/kernel/sched.c
@@ -4570,7 +4570,7 @@ static bool check_same_owner(struct task
}
static int __sched_setscheduler(struct task_struct *p, int policy,
- struct sched_param *param, bool user)
+ const struct sched_param *param, bool user)
{
int retval, oldprio, oldpolicy = -1, on_rq, running;
unsigned long flags;
@@ -4734,7 +4734,7 @@ EXPORT_SYMBOL_GPL(sched_setscheduler);
* but our caller might not have that capability.
*/
int sched_setscheduler_nocheck(struct task_struct *p, int policy,
- struct sched_param *param)
+ const struct sched_param *param)
{
return __sched_setscheduler(p, policy, param, false);
}
diff -puN kernel/softirq.c~a kernel/softirq.c
--- a/kernel/softirq.c~a
+++ a/kernel/softirq.c
@@ -827,7 +827,9 @@ static int __cpuinit cpu_callback(struct
cpumask_any(cpu_online_mask));
case CPU_DEAD:
case CPU_DEAD_FROZEN: {
- struct sched_param param = { .sched_priority = MAX_RT_PRIO-1 };
+ static struct sched_param param = {
+ .sched_priority = MAX_RT_PRIO-1,
+ };
p = per_cpu(ksoftirqd, hotcpu);
per_cpu(ksoftirqd, hotcpu) = NULL;
diff -puN include/linux/sched.h~a include/linux/sched.h
--- a/include/linux/sched.h~a
+++ a/include/linux/sched.h
@@ -1924,7 +1924,7 @@ extern int task_curr(const struct task_s
extern int idle_cpu(int cpu);
extern int sched_setscheduler(struct task_struct *, int, struct sched_param *);
extern int sched_setscheduler_nocheck(struct task_struct *, int,
- struct sched_param *);
+ const struct sched_param *);
extern struct task_struct *idle_task(int cpu);
extern struct task_struct *curr_task(int cpu);
extern void set_curr_task(int cpu, struct task_struct *p);
_
^ permalink raw reply [flat|nested] 3+ messages in thread* Re: [PATCH 10/11] oom: give the dying task a higher priority 2010-07-02 21:49 [PATCH 10/11] oom: give the dying task a higher priority Andrew Morton @ 2010-07-06 0:49 ` KOSAKI Motohiro 2010-07-06 0:50 ` [PATCH 1/2] security: add const to security_task_setscheduler() KOSAKI Motohiro 0 siblings, 1 reply; 3+ messages in thread From: KOSAKI Motohiro @ 2010-07-06 0:49 UTC (permalink / raw) To: Andrew Morton Cc: kosaki.motohiro, LKML, linux-mm, Minchan Kim, David Rientjes, KAMEZAWA Hiroyuki, Ingo Molnar, Peter Zijlstra, James Morris (cc to James) > On Wed, 30 Jun 2010 18:33:23 +0900 (JST) > KOSAKI Motohiro <kosaki.motohiro@jp.fujitsu.com> wrote: > > > +static void boost_dying_task_prio(struct task_struct *p, > > + struct mem_cgroup *mem) > > +{ > > + struct sched_param param = { .sched_priority = 1 }; > > + > > + if (mem) > > + return; > > + > > + if (!rt_task(p)) > > + sched_setscheduler_nocheck(p, SCHED_FIFO, ¶m); > > +} > > We can actually make `param' static here. That saves a teeny bit of > code and a little bit of stack. The oom-killer can be called when > we're using a lot of stack. > > But if we make that change we really should make the param arg to > sched_setscheduler_nocheck() be const. I did that (and was able to > convert lots of callers to use a static `param') but to complete the > job we'd need to chase through all the security goop, fixing up > security_task_setscheduler() and callees, and I got bored. ok, I've finished this works. I made two patches, for-security-tree and for-core. diffstat is below. I'll post the patches as reply of this mail. KOSAKI Motohiro (2): security: add const to security_task_setscheduler() sched: make sched_param arugment static variables in some sched_setscheduler() caller include/linux/sched.h | 5 +++-- include/linux/security.h | 9 +++++---- kernel/irq/manage.c | 4 +++- kernel/kthread.c | 2 +- kernel/sched.c | 6 +++--- kernel/softirq.c | 4 +++- kernel/stop_machine.c | 2 +- kernel/trace/trace_selftest.c | 2 +- kernel/watchdog.c | 2 +- kernel/workqueue.c | 2 +- security/commoncap.c | 2 +- security/security.c | 4 ++-- security/selinux/hooks.c | 3 ++- security/smack/smack_lsm.c | 2 +- 14 files changed, 28 insertions(+), 21 deletions(-) - kosaki > > > include/linux/sched.h | 2 +- > kernel/kthread.c | 2 +- > kernel/sched.c | 4 ++-- > kernel/softirq.c | 4 +++- > kernel/stop_machine.c | 2 +- > kernel/workqueue.c | 2 +- > 6 files changed, 9 insertions(+), 7 deletions(-) > > diff -puN kernel/kthread.c~a kernel/kthread.c > --- a/kernel/kthread.c~a > +++ a/kernel/kthread.c > @@ -131,7 +131,7 @@ struct task_struct *kthread_create(int ( > wait_for_completion(&create.done); > > if (!IS_ERR(create.result)) { > - struct sched_param param = { .sched_priority = 0 }; > + static struct sched_param param = { .sched_priority = 0 }; > va_list args; > > va_start(args, namefmt); > diff -puN kernel/workqueue.c~a kernel/workqueue.c > --- a/kernel/workqueue.c~a > +++ a/kernel/workqueue.c > @@ -962,7 +962,7 @@ init_cpu_workqueue(struct workqueue_stru > > static int create_workqueue_thread(struct cpu_workqueue_struct *cwq, int cpu) > { > - struct sched_param param = { .sched_priority = MAX_RT_PRIO-1 }; > + static struct sched_param param = { .sched_priority = MAX_RT_PRIO-1 }; > struct workqueue_struct *wq = cwq->wq; > const char *fmt = is_wq_single_threaded(wq) ? "%s" : "%s/%d"; > struct task_struct *p; > diff -puN kernel/stop_machine.c~a kernel/stop_machine.c > --- a/kernel/stop_machine.c~a > +++ a/kernel/stop_machine.c > @@ -291,7 +291,7 @@ repeat: > static int __cpuinit cpu_stop_cpu_callback(struct notifier_block *nfb, > unsigned long action, void *hcpu) > { > - struct sched_param param = { .sched_priority = MAX_RT_PRIO - 1 }; > + static struct sched_param param = { .sched_priority = MAX_RT_PRIO - 1 }; > unsigned int cpu = (unsigned long)hcpu; > struct cpu_stopper *stopper = &per_cpu(cpu_stopper, cpu); > struct task_struct *p; > diff -puN kernel/sched.c~a kernel/sched.c > --- a/kernel/sched.c~a > +++ a/kernel/sched.c > @@ -4570,7 +4570,7 @@ static bool check_same_owner(struct task > } > > static int __sched_setscheduler(struct task_struct *p, int policy, > - struct sched_param *param, bool user) > + const struct sched_param *param, bool user) > { > int retval, oldprio, oldpolicy = -1, on_rq, running; > unsigned long flags; > @@ -4734,7 +4734,7 @@ EXPORT_SYMBOL_GPL(sched_setscheduler); > * but our caller might not have that capability. > */ > int sched_setscheduler_nocheck(struct task_struct *p, int policy, > - struct sched_param *param) > + const struct sched_param *param) > { > return __sched_setscheduler(p, policy, param, false); > } > diff -puN kernel/softirq.c~a kernel/softirq.c > --- a/kernel/softirq.c~a > +++ a/kernel/softirq.c > @@ -827,7 +827,9 @@ static int __cpuinit cpu_callback(struct > cpumask_any(cpu_online_mask)); > case CPU_DEAD: > case CPU_DEAD_FROZEN: { > - struct sched_param param = { .sched_priority = MAX_RT_PRIO-1 }; > + static struct sched_param param = { > + .sched_priority = MAX_RT_PRIO-1, > + }; > > p = per_cpu(ksoftirqd, hotcpu); > per_cpu(ksoftirqd, hotcpu) = NULL; > diff -puN include/linux/sched.h~a include/linux/sched.h > --- a/include/linux/sched.h~a > +++ a/include/linux/sched.h > @@ -1924,7 +1924,7 @@ extern int task_curr(const struct task_s > extern int idle_cpu(int cpu); > extern int sched_setscheduler(struct task_struct *, int, struct sched_param *); > extern int sched_setscheduler_nocheck(struct task_struct *, int, > - struct sched_param *); > + const struct sched_param *); > extern struct task_struct *idle_task(int cpu); > extern struct task_struct *curr_task(int cpu); > extern void set_curr_task(int cpu, struct task_struct *p); > _ > ^ permalink raw reply [flat|nested] 3+ messages in thread
* [PATCH 1/2] security: add const to security_task_setscheduler() 2010-07-06 0:49 ` KOSAKI Motohiro @ 2010-07-06 0:50 ` KOSAKI Motohiro 0 siblings, 0 replies; 3+ messages in thread From: KOSAKI Motohiro @ 2010-07-06 0:50 UTC (permalink / raw) To: James Morris Cc: kosaki.motohiro, Andrew Morton, LKML, linux-mm, Minchan Kim, David Rientjes, KAMEZAWA Hiroyuki, Ingo Molnar, Peter Zijlstra All security modules shouldn't change sched_param parameter of security_task_setscheduler(). This is not only meaningless, but also make harmful result if caller pass static variable. This patch add const to it. Signed-off-by: KOSAKI Motohiro <kosaki.motohiro@jp.fujitsu.com> --- include/linux/security.h | 9 +++++---- security/commoncap.c | 2 +- security/security.c | 4 ++-- security/selinux/hooks.c | 3 ++- security/smack/smack_lsm.c | 2 +- 5 files changed, 11 insertions(+), 9 deletions(-) diff --git a/include/linux/security.h b/include/linux/security.h index 5bcb395..07e94e5 100644 --- a/include/linux/security.h +++ b/include/linux/security.h @@ -74,7 +74,8 @@ extern int cap_file_mmap(struct file *file, unsigned long reqprot, extern int cap_task_fix_setuid(struct cred *new, const struct cred *old, int flags); extern int cap_task_prctl(int option, unsigned long arg2, unsigned long arg3, unsigned long arg4, unsigned long arg5); -extern int cap_task_setscheduler(struct task_struct *p, int policy, struct sched_param *lp); +extern int cap_task_setscheduler(struct task_struct *p, int policy, + const struct sched_param *lp); extern int cap_task_setioprio(struct task_struct *p, int ioprio); extern int cap_task_setnice(struct task_struct *p, int nice); extern int cap_syslog(int type, bool from_file); @@ -1501,7 +1502,7 @@ struct security_operations { int (*task_getioprio) (struct task_struct *p); int (*task_setrlimit) (unsigned int resource, struct rlimit *new_rlim); int (*task_setscheduler) (struct task_struct *p, int policy, - struct sched_param *lp); + const struct sched_param *lp); int (*task_getscheduler) (struct task_struct *p); int (*task_movememory) (struct task_struct *p); int (*task_kill) (struct task_struct *p, @@ -1750,8 +1751,8 @@ int security_task_setnice(struct task_struct *p, int nice); int security_task_setioprio(struct task_struct *p, int ioprio); int security_task_getioprio(struct task_struct *p); int security_task_setrlimit(unsigned int resource, struct rlimit *new_rlim); -int security_task_setscheduler(struct task_struct *p, - int policy, struct sched_param *lp); +int security_task_setscheduler(struct task_struct *p, int policy, + const struct sched_param *lp); int security_task_getscheduler(struct task_struct *p); int security_task_movememory(struct task_struct *p); int security_task_kill(struct task_struct *p, struct siginfo *info, diff --git a/security/commoncap.c b/security/commoncap.c index 4e01599..b74d460 100644 --- a/security/commoncap.c +++ b/security/commoncap.c @@ -726,7 +726,7 @@ static int cap_safe_nice(struct task_struct *p) * specified task, returning 0 if permission is granted, -ve if denied. */ int cap_task_setscheduler(struct task_struct *p, int policy, - struct sched_param *lp) + const struct sched_param *lp) { return cap_safe_nice(p); } diff --git a/security/security.c b/security/security.c index 7461b1b..6151322 100644 --- a/security/security.c +++ b/security/security.c @@ -785,8 +785,8 @@ int security_task_setrlimit(unsigned int resource, struct rlimit *new_rlim) return security_ops->task_setrlimit(resource, new_rlim); } -int security_task_setscheduler(struct task_struct *p, - int policy, struct sched_param *lp) +int security_task_setscheduler(struct task_struct *p, int policy, + const struct sched_param *lp) { return security_ops->task_setscheduler(p, policy, lp); } diff --git a/security/selinux/hooks.c b/security/selinux/hooks.c index 5c9f25b..dd136bd 100644 --- a/security/selinux/hooks.c +++ b/security/selinux/hooks.c @@ -3385,7 +3385,8 @@ static int selinux_task_setrlimit(unsigned int resource, struct rlimit *new_rlim return 0; } -static int selinux_task_setscheduler(struct task_struct *p, int policy, struct sched_param *lp) +static int selinux_task_setscheduler(struct task_struct *p, int policy, + const struct sched_param *lp) { int rc; diff --git a/security/smack/smack_lsm.c b/security/smack/smack_lsm.c index 07abc9c..c3336f1 100644 --- a/security/smack/smack_lsm.c +++ b/security/smack/smack_lsm.c @@ -1280,7 +1280,7 @@ static int smack_task_getioprio(struct task_struct *p) * Return 0 if read access is permitted */ static int smack_task_setscheduler(struct task_struct *p, int policy, - struct sched_param *lp) + const struct sched_param *lp) { int rc; -- 1.6.5.2 ^ permalink raw reply [flat|nested] 3+ messages in thread
end of thread, other threads:[~2010-10-06 23:41 UTC | newest]
Thread overview: 3+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
[not found] <201010012119.o91LJMwQ021365@imap1.linux-foundation.org>
[not found] ` <alpine.LRH.2.00.1010050929340.28702@tundra.namei.org>
2010-10-05 1:55 ` [patch 1/2] security: add const to security_task_setscheduler() KOSAKI Motohiro
2010-10-06 23:41 ` James Morris
2010-07-02 21:49 [PATCH 10/11] oom: give the dying task a higher priority Andrew Morton
2010-07-06 0:49 ` KOSAKI Motohiro
2010-07-06 0:50 ` [PATCH 1/2] security: add const to security_task_setscheduler() KOSAKI Motohiro
This is a public inbox, see mirroring instructions for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®