|
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index] [Xen-devel] [PATCH 3/4] flask: check permissions first thing in flask_security_set_bool()
Nothing else should be done if the caller isn't permitted to set
boolean values.
Signed-off-by: Jan Beulich <jbeulich@xxxxxxxx>
--- a/xen/xsm/flask/flask_op.c
+++ b/xen/xsm/flask/flask_op.c
@@ -326,11 +326,11 @@ static int flask_security_set_bool(struc
{
int rv;
- rv = flask_security_resolve_bool(arg);
+ rv = domain_has_security(current->domain, SECURITY__SETBOOL);
if ( rv )
return rv;
- rv = domain_has_security(current->domain, SECURITY__SETBOOL);
+ rv = flask_security_resolve_bool(arg);
if ( rv )
return rv;
Attachment:
flask-set-bool-perm-first.patch _______________________________________________ Xen-devel mailing list Xen-devel@xxxxxxxxxxxxx http://lists.xen.org/xen-devel
|
![]() |
Lists.xenproject.org is hosted with RackSpace, monitoring our |