mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* [PATCH 1/2] keys: Fix unreachable code
@ 2012-12-17 13:15 David Howells
  2012-12-17 13:15 ` [PATCH 2/2] KEYS: Use keyring_alloc() to create module signing keyring David Howells
  0 siblings, 1 reply; 2+ messages in thread
From: David Howells @ 2012-12-17 13:15 UTC (permalink / raw)
  To: torvalds; +Cc: linux-security-module, Alan Cox, jmorris, linux-kernel

From: Alan Cox <alan@linux.intel.com>

We set ret to NULL then test it. Remove the bogus test

Signed-off-by: Alan Cox <alan@linux.intel.com>
Signed-off-by: David Howells <dhowells@redhat.com>
---

 security/keys/process_keys.c |    2 --
 1 file changed, 2 deletions(-)

diff --git a/security/keys/process_keys.c b/security/keys/process_keys.c
index 58dfe08..20e4bf5 100644
--- a/security/keys/process_keys.c
+++ b/security/keys/process_keys.c
@@ -367,8 +367,6 @@ key_ref_t search_my_process_keyrings(struct key_type *type,
 
 		switch (PTR_ERR(key_ref)) {
 		case -EAGAIN: /* no key */
-			if (ret)
-				break;
 		case -ENOKEY: /* negative key */
 			ret = key_ref;
 			break;


^ permalink raw reply	[flat|nested] 2+ messages in thread

* [PATCH 2/2] KEYS: Use keyring_alloc() to create module signing keyring
  2012-12-17 13:15 [PATCH 1/2] keys: Fix unreachable code David Howells
@ 2012-12-17 13:15 ` David Howells
  0 siblings, 0 replies; 2+ messages in thread
From: David Howells @ 2012-12-17 13:15 UTC (permalink / raw)
  To: torvalds; +Cc: linux-security-module, Rusty Russell, jmorris, linux-kernel

Use keyring_alloc() to create special keyrings now that it has a permissions
parameter rather than using key_alloc() + key_instantiate_and_link().

Signed-off-by: David Howells <dhowells@redhat.com>
cc: Rusty Russell <rusty@rustcorp.com.au>
---

 kernel/modsign_pubkey.c |   15 ++++++---------
 1 file changed, 6 insertions(+), 9 deletions(-)

diff --git a/kernel/modsign_pubkey.c b/kernel/modsign_pubkey.c
index 767e559..524a56f 100644
--- a/kernel/modsign_pubkey.c
+++ b/kernel/modsign_pubkey.c
@@ -40,18 +40,15 @@ static __init int module_verify_init(void)
 {
 	pr_notice("Initialise module verification\n");
 
-	modsign_keyring = key_alloc(&key_type_keyring, ".module_sign",
-				    KUIDT_INIT(0), KGIDT_INIT(0),
-				    current_cred(),
-				    (KEY_POS_ALL & ~KEY_POS_SETATTR) |
-				    KEY_USR_VIEW | KEY_USR_READ,
-				    KEY_ALLOC_NOT_IN_QUOTA);
+	modsign_keyring = keyring_alloc(".module_sign",
+					KUIDT_INIT(0), KGIDT_INIT(0),
+					current_cred(),
+					((KEY_POS_ALL & ~KEY_POS_SETATTR) |
+					 KEY_USR_VIEW | KEY_USR_READ),
+					KEY_ALLOC_NOT_IN_QUOTA, NULL);
 	if (IS_ERR(modsign_keyring))
 		panic("Can't allocate module signing keyring\n");
 
-	if (key_instantiate_and_link(modsign_keyring, NULL, 0, NULL, NULL) < 0)
-		panic("Can't instantiate module signing keyring\n");
-
 	return 0;
 }
 


^ permalink raw reply	[flat|nested] 2+ messages in thread

end of thread, other threads:[~2012-12-17 13:52 UTC | newest]

Thread overview: 2+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2012-12-17 13:15 [PATCH 1/2] keys: Fix unreachable code David Howells
2012-12-17 13:15 ` [PATCH 2/2] KEYS: Use keyring_alloc() to create module signing keyring David Howells

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®