* [PATCH 1/2] keys: Fix unreachable code
@ 2012-12-17 13:15 David Howells
2012-12-17 13:15 ` [PATCH 2/2] KEYS: Use keyring_alloc() to create module signing keyring David Howells
0 siblings, 1 reply; 2+ messages in thread
From: David Howells @ 2012-12-17 13:15 UTC (permalink / raw)
To: torvalds; +Cc: linux-security-module, Alan Cox, jmorris, linux-kernel
From: Alan Cox <alan@linux.intel.com>
We set ret to NULL then test it. Remove the bogus test
Signed-off-by: Alan Cox <alan@linux.intel.com>
Signed-off-by: David Howells <dhowells@redhat.com>
---
security/keys/process_keys.c | 2 --
1 file changed, 2 deletions(-)
diff --git a/security/keys/process_keys.c b/security/keys/process_keys.c
index 58dfe08..20e4bf5 100644
--- a/security/keys/process_keys.c
+++ b/security/keys/process_keys.c
@@ -367,8 +367,6 @@ key_ref_t search_my_process_keyrings(struct key_type *type,
switch (PTR_ERR(key_ref)) {
case -EAGAIN: /* no key */
- if (ret)
- break;
case -ENOKEY: /* negative key */
ret = key_ref;
break;
^ permalink raw reply [flat|nested] 2+ messages in thread
* [PATCH 2/2] KEYS: Use keyring_alloc() to create module signing keyring
2012-12-17 13:15 [PATCH 1/2] keys: Fix unreachable code David Howells
@ 2012-12-17 13:15 ` David Howells
0 siblings, 0 replies; 2+ messages in thread
From: David Howells @ 2012-12-17 13:15 UTC (permalink / raw)
To: torvalds; +Cc: linux-security-module, Rusty Russell, jmorris, linux-kernel
Use keyring_alloc() to create special keyrings now that it has a permissions
parameter rather than using key_alloc() + key_instantiate_and_link().
Signed-off-by: David Howells <dhowells@redhat.com>
cc: Rusty Russell <rusty@rustcorp.com.au>
---
kernel/modsign_pubkey.c | 15 ++++++---------
1 file changed, 6 insertions(+), 9 deletions(-)
diff --git a/kernel/modsign_pubkey.c b/kernel/modsign_pubkey.c
index 767e559..524a56f 100644
--- a/kernel/modsign_pubkey.c
+++ b/kernel/modsign_pubkey.c
@@ -40,18 +40,15 @@ static __init int module_verify_init(void)
{
pr_notice("Initialise module verification\n");
- modsign_keyring = key_alloc(&key_type_keyring, ".module_sign",
- KUIDT_INIT(0), KGIDT_INIT(0),
- current_cred(),
- (KEY_POS_ALL & ~KEY_POS_SETATTR) |
- KEY_USR_VIEW | KEY_USR_READ,
- KEY_ALLOC_NOT_IN_QUOTA);
+ modsign_keyring = keyring_alloc(".module_sign",
+ KUIDT_INIT(0), KGIDT_INIT(0),
+ current_cred(),
+ ((KEY_POS_ALL & ~KEY_POS_SETATTR) |
+ KEY_USR_VIEW | KEY_USR_READ),
+ KEY_ALLOC_NOT_IN_QUOTA, NULL);
if (IS_ERR(modsign_keyring))
panic("Can't allocate module signing keyring\n");
- if (key_instantiate_and_link(modsign_keyring, NULL, 0, NULL, NULL) < 0)
- panic("Can't instantiate module signing keyring\n");
-
return 0;
}
^ permalink raw reply [flat|nested] 2+ messages in thread
end of thread, other threads:[~2012-12-17 13:52 UTC | newest]
Thread overview: 2+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2012-12-17 13:15 [PATCH 1/2] keys: Fix unreachable code David Howells
2012-12-17 13:15 ` [PATCH 2/2] KEYS: Use keyring_alloc() to create module signing keyring David Howells
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®