mirror of
https://github.com/Fishwaldo/Star64_linux.git
synced 2025-07-18 21:02:04 +00:00
LSM: Infrastructure management of the task security
Move management of the task_struct->security blob out of the individual security modules and into the security infrastructure. Instead of allocating the blobs from within the modules the modules tell the infrastructure how much space is required, and the space is allocated there. The only user of this blob is AppArmor. The AppArmor use is abstracted to avoid future conflict. Signed-off-by: Casey Schaufler <casey@schaufler-ca.com> Reviewed-by: Kees Cook <keescook@chromium.org> [kees: adjusted for ordered init series] Signed-off-by: Kees Cook <keescook@chromium.org>
This commit is contained in:
parent
afb1cbe374
commit
f4ad8f2c40
4 changed files with 62 additions and 27 deletions
|
@ -2034,6 +2034,7 @@ struct lsm_blob_sizes {
|
|||
int lbs_cred;
|
||||
int lbs_file;
|
||||
int lbs_inode;
|
||||
int lbs_task;
|
||||
};
|
||||
|
||||
/*
|
||||
|
@ -2109,6 +2110,7 @@ extern int lsm_inode_alloc(struct inode *inode);
|
|||
|
||||
#ifdef CONFIG_SECURITY
|
||||
void __init lsm_early_cred(struct cred *cred);
|
||||
void __init lsm_early_task(struct task_struct *task);
|
||||
#endif
|
||||
|
||||
#endif /* ! __LINUX_LSM_HOOKS_H */
|
||||
|
|
Loading…
Add table
Add a link
Reference in a new issue