Browse Source

selinux: fix error codes in cond_policydb_init()

It's better to propagate the error code from avtab_init() instead of
returning -1 (-EPERM).  It turns out that avtab_init() never fails so
this patch doesn't change how the code runs but it's still a clean up.

Signed-off-by: Dan Carpenter <error27@gmail.com>
Acked-by:  Stephen D. Smalley <sds@tycho.nsa.gov>
Signed-off-by: James Morris <jmorris@namei.org>
Dan Carpenter 15 years ago
parent
commit
38184c5222
1 changed files with 6 additions and 2 deletions
  1. 6 2
      security/selinux/ss/conditional.c

+ 6 - 2
security/selinux/ss/conditional.c

@@ -117,10 +117,14 @@ int evaluate_cond_node(struct policydb *p, struct cond_node *node)
 
 
 int cond_policydb_init(struct policydb *p)
 int cond_policydb_init(struct policydb *p)
 {
 {
+	int rc;
+
 	p->bool_val_to_struct = NULL;
 	p->bool_val_to_struct = NULL;
 	p->cond_list = NULL;
 	p->cond_list = NULL;
-	if (avtab_init(&p->te_cond_avtab))
-		return -1;
+
+	rc = avtab_init(&p->te_cond_avtab);
+	if (rc)
+		return rc;
 
 
 	return 0;
 	return 0;
 }
 }