浏览代码

IMA: set entry->action to UNKNOWN rather than hard coding

ima_parse_rule currently sets entry->action = -1 and then later tests
if (entry->action == UNKNOWN).  It is true that UNKNOWN == -1 but actually
setting it to UNKNOWN makes a lot more sense in case things change in the
future.

Signed-off-by: Eric Paris <eparis@redhat.com>
Acked-by: Mimi Zohar <zohar@us.ibm.com>
Signed-off-by: James Morris <jmorris@namei.org>
Eric Paris 15 年之前
父节点
当前提交
b9035b1fd7
共有 1 个文件被更改,包括 1 次插入1 次删除
  1. 1 1
      security/integrity/ima/ima_policy.c

+ 1 - 1
security/integrity/ima/ima_policy.c

@@ -264,7 +264,7 @@ static int ima_parse_rule(char *rule, struct ima_measure_rule_entry *entry)
 	ab = audit_log_start(NULL, GFP_KERNEL, AUDIT_INTEGRITY_RULE);
 
 	entry->uid = -1;
-	entry->action = -1;
+	entry->action = UNKNOWN;
 	while ((p = strsep(&rule, " ")) != NULL) {
 		substring_t args[MAX_OPT_ARGS];
 		int token;