From: Mimi Zohar <zohar@linux•vnet.ibm.com>
To: Randy Dunlap <rdunlap@infradead•org>,
David Rientjes <rientjes@google•com>
Cc: James Morris <jmorris@namei•org>,
linux-security-module <linux-security-module@vger•kernel.org>,
linux-kernel <linux-kernel@vger•kernel.org>,
linux-next <linux-next@vger•kernel.org>,
Dmitry Kasatkin <dmitry.kasatkin@intel•com>
Subject: [PATCH] ima: fix part_pack_uuid() build error
Date: Fri, 22 Feb 2013 14:46:53 -0500 [thread overview]
Message-ID: <1361562413.2908.22.camel@falcor1.watson.ibm.com> (raw)
Fix a build error when CONFIG_BLOCK is not enabled by defining
a wrapper called ima_part_pack_uuid(). The wrapper returns
-EINVAL, when CONFIG_BLOCK is not defined.
security/integrity/ima/ima_policy.c:538:4: error: implicit declaration
of function 'part_pack_uuid' [-Werror=implicit-function-declaration]
Changelog v0:
- fix UUID scripts/Lindent msgs
Reported-by: Randy Dunlap <rdunlap@infradead•org>
Reported-by: David Rientjes <rientjes@google•com>
Signed-off-by: Mimi Zohar <zohar@linux•vnet.ibm.com>
---
security/integrity/ima/ima.h | 13 +++++++++++++
security/integrity/ima/ima_policy.c | 11 ++++++-----
2 files changed, 19 insertions(+), 5 deletions(-)
diff --git a/security/integrity/ima/ima.h b/security/integrity/ima/ima.h
index a41c9c1..902c356 100644
--- a/security/integrity/ima/ima.h
+++ b/security/integrity/ima/ima.h
@@ -21,6 +21,7 @@
#include <linux/crypto.h>
#include <linux/security.h>
#include <linux/hash.h>
+#include <linux/genhd.h>
#include <linux/tpm.h>
#include <linux/audit.h>
@@ -199,4 +200,16 @@ static inline int security_filter_rule_match(u32 secid, u32 field, u32 op,
return -EINVAL;
}
#endif /* CONFIG_IMA_LSM_RULES */
+
+/* UUID policy option requires CONFIG_BLOCK */
+#ifdef CONFIG_BLOCK
+static inline int ima_part_pack_uuid(const u8 *uuid_str, u8 *to) {
+ part_pack_uuid(uuid_str, to);
+ return 0;
+}
+#else
+static inline int ima_part_pack_uuid(const u8 *uuid_str, u8 *to) {
+ return -EINVAL;
+}
+#endif
#endif
diff --git a/security/integrity/ima/ima_policy.c b/security/integrity/ima/ima_policy.c
index b27535a..41b7f48 100644
--- a/security/integrity/ima/ima_policy.c
+++ b/security/integrity/ima/ima_policy.c
@@ -176,7 +176,7 @@ static bool ima_match_rules(struct ima_rule_entry *rule,
&& rule->fsmagic != inode->i_sb->s_magic)
return false;
if ((rule->flags & IMA_FSUUID) &&
- memcmp(rule->fsuuid, inode->i_sb->s_uuid, sizeof(rule->fsuuid)))
+ memcmp(rule->fsuuid, inode->i_sb->s_uuid, sizeof(rule->fsuuid)))
return false;
if ((rule->flags & IMA_UID) && !uid_eq(rule->uid, cred->uid))
return false;
@@ -530,14 +530,15 @@ static int ima_parse_rule(char *rule, struct ima_rule_entry *entry)
ima_log_string(ab, "fsuuid", args[0].from);
if (memchr_inv(entry->fsuuid, 0x00,
- sizeof(entry->fsuuid))) {
+ sizeof(entry->fsuuid))) {
result = -EINVAL;
break;
}
- part_pack_uuid(args[0].from, entry->fsuuid);
- entry->flags |= IMA_FSUUID;
- result = 0;
+ result = ima_part_pack_uuid(args[0].from,
+ entry->fsuuid);
+ if (!result)
+ entry->flags |= IMA_FSUUID;
break;
case Opt_uid:
ima_log_string(ab, "uid", args[0].from);
--
1.8.1.rc3
next reply other threads:[~2013-02-22 19:47 UTC|newest]
Thread overview: 4+ messages / expand[flat|nested] mbox.gz Atom feed top
2013-02-22 19:46 Mimi Zohar [this message]
2013-02-22 20:35 ` [PATCH] ima: fix part_pack_uuid() build error David Rientjes
2013-02-22 21:20 ` Randy Dunlap
2013-02-24 15:15 ` Mimi Zohar
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=1361562413.2908.22.camel@falcor1.watson.ibm.com \
--to=zohar@linux$(echo .)vnet.ibm.com \
--cc=dmitry.kasatkin@intel$(echo .)com \
--cc=jmorris@namei$(echo .)org \
--cc=linux-kernel@vger$(echo .)kernel.org \
--cc=linux-next@vger$(echo .)kernel.org \
--cc=linux-security-module@vger$(echo .)kernel.org \
--cc=rdunlap@infradead$(echo .)org \
--cc=rientjes@google$(echo .)com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox