On 02/10/14 16:03, Mimi Zohar wrote: >> Ok, thanks. >> > >> > Acked-by: Roberto Sassu <roberto.sa...@polito.it> >> > >> > Roberto Sassu > Thanks, Dmitry, Roberto. The patch and update description looks good. > Please post the updated patch inline here on the mailing list. > > thanks, > > Mimi > >
Mimi, patch is the same what I posted 9:21 GMT and what Roberto acked. Patch description updated based on Roberto's and Your comments ima: check ima_policy_flag in the ima_file_free() hook This patch completes the switching to the 'ima_policy_flag' variable in the checks at the beginning of IMA functions, starting with the commit a756024e. Checking 'iint_initialized' is completely unnecessary, because S_IMA flag is unset if iint was not allocated. At the same time the integrity cache is allocated with SLAB_PANIC and the kernel will panic if the allocation fails during kernel initialization. So on a running system iint_initialized is always true and can be removed. Changes in v3: * not limiting test to IMA_APPRAISE (spotted by Roberto Sassu) Changes in v2: * 'iint_initialized' removal patch merged to this patch (requested by Mimi) Signed-off-by: Dmitry Kasatkin <d.kasat...@samsung.com> Acked-by: Roberto Sassu <roberto.sa...@polito.it> -- To unsubscribe from this list: send the line "unsubscribe linux-kernel" in the body of a message to majord...@vger.kernel.org More majordomo info at http://vger.kernel.org/majordomo-info.html Please read the FAQ at http://www.tux.org/lkml/