Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.kernel > #1559248 > unrolled thread
| Started by | SF Markus Elfring <elfring@users.sourceforge.net> |
|---|---|
| First post | 2017-01-15 16:00 +0100 |
| Last post | 2017-01-16 19:40 +0100 |
| Articles | 20 on this page of 50 — 3 participants |
Back to article view | Back to linux.kernel
[PATCH 00/46] SELinux: Fine-tuning for several function implementations SF Markus Elfring <elfring@users.sourceforge.net> - 2017-01-15 16:00 +0100
[PATCH 02/46] selinux: Delete an unnecessary return statement in cond_compute_av() SF Markus Elfring <elfring@users.sourceforge.net> - 2017-01-15 16:00 +0100
[PATCH 01/46] selinux: Use kmalloc_array() in cond_init_bool_indexes() SF Markus Elfring <elfring@users.sourceforge.net> - 2017-01-15 16:00 +0100
[PATCH 04/46] selinux: Use kmalloc_array() in hashtab_create() SF Markus Elfring <elfring@users.sourceforge.net> - 2017-01-15 16:10 +0100
[PATCH 05/46] selinux: Adjust four checks for null pointers SF Markus Elfring <elfring@users.sourceforge.net> - 2017-01-15 16:10 +0100
[PATCH 07/46] selinux: Delete unnecessary variable assignments in policydb_index() SF Markus Elfring <elfring@users.sourceforge.net> - 2017-01-15 16:10 +0100
[PATCH 09/46] selinux: Delete an error message for a failed memory allocation in policydb_read() SF Markus Elfring <elfring@users.sourceforge.net> - 2017-01-15 16:10 +0100
[PATCH 08/46] selinux: Delete an unnecessary return statement in policydb_destroy() SF Markus Elfring <elfring@users.sourceforge.net> - 2017-01-15 16:10 +0100
[PATCH 03/46] selinux: Improve size determinations in four functions SF Markus Elfring <elfring@users.sourceforge.net> - 2017-01-15 16:10 +0100
[PATCH 06/46] selinux: Use kcalloc() in policydb_index() SF Markus Elfring <elfring@users.sourceforge.net> - 2017-01-15 16:10 +0100
[PATCH 18/46] selinux: One function call less in filename_trans_read() after error detection SF Markus Elfring <elfring@users.sourceforge.net> - 2017-01-15 16:20 +0100
[PATCH 17/46] selinux: Delete an unnecessary variable assignment in filename_trans_read() SF Markus Elfring <elfring@users.sourceforge.net> - 2017-01-15 16:20 +0100
[PATCH 11/46] selinux: Return directly after a failed next_entry() in genfs_read() SF Markus Elfring <elfring@users.sourceforge.net> - 2017-01-15 16:20 +0100
[PATCH 15/46] selinux: One check and function call less in genfs_read() after error detection SF Markus Elfring <elfring@users.sourceforge.net> - 2017-01-15 16:20 +0100
[PATCH 16/46] selinux: Move two assignments for the variable "rc" in filename_trans_read() SF Markus Elfring <elfring@users.sourceforge.net> - 2017-01-15 16:20 +0100
[PATCH 13/46] selinux: Move four assignments for the variable "rc" in genfs_read() SF Markus Elfring <elfring@users.sourceforge.net> - 2017-01-15 16:20 +0100
[PATCH 14/46] selinux: One function call less in genfs_read() after null pointer detection SF Markus Elfring <elfring@users.sourceforge.net> - 2017-01-15 16:20 +0100
[PATCH 19/46] selinux: Return directly after a failed next_entry() in range_read() SF Markus Elfring <elfring@users.sourceforge.net> - 2017-01-15 16:20 +0100
[PATCH 10/46] selinux: Move some assignments for the variable "rc" in policydb_read() SF Markus Elfring <elfring@users.sourceforge.net> - 2017-01-15 16:20 +0100
[PATCH 12/46] selinux: Move assignments for two pointers in genfs_read() SF Markus Elfring <elfring@users.sourceforge.net> - 2017-01-15 16:20 +0100
[PATCH 28/46] selinux: Return directly after a failed kzalloc() in user_read() SF Markus Elfring <elfring@users.sourceforge.net> - 2017-01-15 16:30 +0100
[PATCH 20/46] selinux: Move four assignments for the variable "rc" in range_read() SF Markus Elfring <elfring@users.sourceforge.net> - 2017-01-15 16:30 +0100
[PATCH 24/46] selinux: Return directly after a failed kzalloc() in cat_read() SF Markus Elfring <elfring@users.sourceforge.net> - 2017-01-15 16:30 +0100
[PATCH 21/46] selinux: Two function calls less in range_read() after error detection SF Markus Elfring <elfring@users.sourceforge.net> - 2017-01-15 16:30 +0100
[PATCH 23/46] selinux: Move an assignment for a pointer in range_read() SF Markus Elfring <elfring@users.sourceforge.net> - 2017-01-15 16:30 +0100
[PATCH 29/46] selinux: Return directly after a failed kzalloc() in type_read() SF Markus Elfring <elfring@users.sourceforge.net> - 2017-01-15 16:30 +0100
[PATCH 25/46] selinux: Return directly after a failed kzalloc() in sens_read() SF Markus Elfring <elfring@users.sourceforge.net> - 2017-01-15 16:30 +0100
[PATCH 26/46] selinux: Improve another size determination in sens_read() SF Markus Elfring <elfring@users.sourceforge.net> - 2017-01-15 16:30 +0100
[PATCH 27/46] selinux: Move an assignment for the variable "rc" in sens_read() SF Markus Elfring <elfring@users.sourceforge.net> - 2017-01-15 16:30 +0100
[PATCH 22/46] selinux: Delete an unnecessary variable initialisation in range_read() SF Markus Elfring <elfring@users.sourceforge.net> - 2017-01-15 16:30 +0100
[PATCH 35/46] selinux: Return directly after a failed kzalloc() in perm_read() SF Markus Elfring <elfring@users.sourceforge.net> - 2017-01-15 16:40 +0100
[PATCH 32/46] selinux: Return directly after a failed kzalloc() in class_read() SF Markus Elfring <elfring@users.sourceforge.net> - 2017-01-15 16:40 +0100
[PATCH 39/46] selinux: Move two assignments for the variable "rc" in ocontext_read() SF Markus Elfring <elfring@users.sourceforge.net> - 2017-01-15 16:40 +0100
[PATCH 33/46] selinux: Move an assignment for the variable "rc" in class_read() SF Markus Elfring <elfring@users.sourceforge.net> - 2017-01-15 16:40 +0100
[PATCH 37/46] selinux: Move an assignment for the variable "rc" in policydb_load_isids() SF Markus Elfring <elfring@users.sourceforge.net> - 2017-01-15 16:40 +0100
[PATCH 38/46] selinux: One function call less in five functions after null pointer detection SF Markus Elfring <elfring@users.sourceforge.net> - 2017-01-15 16:40 +0100
[PATCH 30/46] selinux: Return directly after a failed kzalloc() in role_read() SF Markus Elfring <elfring@users.sourceforge.net> - 2017-01-15 16:40 +0100
[PATCH 31/46] selinux: Move an assignment for the variable "rc" in role_read() SF Markus Elfring <elfring@users.sourceforge.net> - 2017-01-15 16:40 +0100
[PATCH 36/46] selinux: Move an assignment for the variable "rc" in mls_read_range_helper() SF Markus Elfring <elfring@users.sourceforge.net> - 2017-01-15 16:40 +0100
[PATCH 34/46] selinux: Return directly after a failed kzalloc() in common_read() SF Markus Elfring <elfring@users.sourceforge.net> - 2017-01-15 16:40 +0100
[PATCH 45/46] selinux: Use common error handling code in sidtab_insert() SF Markus Elfring <elfring@users.sourceforge.net> - 2017-01-15 16:50 +0100
[PATCH 44/46] selinux: Adjust two checks for null pointers SF Markus Elfring <elfring@users.sourceforge.net> - 2017-01-15 16:50 +0100
[PATCH 40/46] selinux: Return directly after a failed kzalloc() in roles_init() SF Markus Elfring <elfring@users.sourceforge.net> - 2017-01-15 16:50 +0100
[PATCH 46/46] selinuxfs: Use seq_puts() in sel_avc_stats_seq_show() SF Markus Elfring <elfring@users.sourceforge.net> - 2017-01-15 16:50 +0100
[PATCH 43/46] selinux: Use kmalloc_array() in sidtab_init() SF Markus Elfring <elfring@users.sourceforge.net> - 2017-01-15 16:50 +0100
[PATCH 42/46] selinux: One function call less in roles_init() after error detection SF Markus Elfring <elfring@users.sourceforge.net> - 2017-01-15 16:50 +0100
[PATCH 41/46] selinux: Move two assignments for the variable "rc" in roles_init() SF Markus Elfring <elfring@users.sourceforge.net> - 2017-01-15 16:50 +0100
Re: [PATCH 00/46] SELinux: Fine-tuning for several function implementations Eric Paris <eparis@redhat.com> - 2017-01-16 16:30 +0100
Re: [PATCH 00/46] SELinux: Fine-tuning for several function implementations Paul Moore <paul@paul-moore.com> - 2017-01-16 17:50 +0100
Re: SELinux: Checking source code positions for the setting of error codes SF Markus Elfring <elfring@users.sourceforge.net> - 2017-01-16 19:40 +0100
Page 2 of 3 — ← Prev page 1 [2] 3 Next page →
| From | SF Markus Elfring <elfring@users.sourceforge.net> |
|---|---|
| Date | 2017-01-15 16:30 +0100 |
| Subject | [PATCH 28/46] selinux: Return directly after a failed kzalloc() in user_read() |
| Message-ID | <sZUUN-47Q-7@gated-at.bofh.it> |
| In reply to | #1559248 |
From: Markus Elfring <elfring@users.sourceforge.net> Date: Sat, 14 Jan 2017 22:08:22 +0100 Return directly after a call of the function "kzalloc" failed at the beginning. Signed-off-by: Markus Elfring <elfring@users.sourceforge.net> --- security/selinux/ss/policydb.c | 3 +-- 1 file changed, 1 insertion(+), 2 deletions(-) diff --git a/security/selinux/ss/policydb.c b/security/selinux/ss/policydb.c index 3e43556e67b8..1c046d39e2a7 100644 --- a/security/selinux/ss/policydb.c +++ b/security/selinux/ss/policydb.c @@ -1542,10 +1542,9 @@ static int user_read(struct policydb *p, struct hashtab *h, void *fp) __le32 buf[3]; u32 len; - rc = -ENOMEM; usrdatum = kzalloc(sizeof(*usrdatum), GFP_KERNEL); if (!usrdatum) - goto bad; + return -ENOMEM; if (p->policyvers >= POLICYDB_VERSION_BOUNDARY) to_read = 3; -- 2.11.0
[toc] | [prev] | [next] | [standalone]
| From | SF Markus Elfring <elfring@users.sourceforge.net> |
|---|---|
| Date | 2017-01-15 16:30 +0100 |
| Subject | [PATCH 20/46] selinux: Move four assignments for the variable "rc" in range_read() |
| Message-ID | <sZUUN-47Q-1@gated-at.bofh.it> |
| In reply to | #1559248 |
From: Markus Elfring <elfring@users.sourceforge.net>
Date: Sat, 14 Jan 2017 19:55:00 +0100
One local variable was set to an error code in four cases before
a concrete error situation was detected. Thus move the corresponding
assignments into if branches to indicate a software failure there.
Signed-off-by: Markus Elfring <elfring@users.sourceforge.net>
---
security/selinux/ss/policydb.c | 17 ++++++++++-------
1 file changed, 10 insertions(+), 7 deletions(-)
diff --git a/security/selinux/ss/policydb.c b/security/selinux/ss/policydb.c
index a696876fc327..4cd96ce51322 100644
--- a/security/selinux/ss/policydb.c
+++ b/security/selinux/ss/policydb.c
@@ -1854,10 +1854,11 @@ static int range_read(struct policydb *p, void *fp)
nel = le32_to_cpu(buf[0]);
for (i = 0; i < nel; i++) {
- rc = -ENOMEM;
rt = kzalloc(sizeof(*rt), GFP_KERNEL);
- if (!rt)
+ if (!rt) {
+ rc = -ENOMEM;
goto out;
+ }
rc = next_entry(buf, fp, (sizeof(u32) * 2));
if (rc)
@@ -1873,24 +1874,26 @@ static int range_read(struct policydb *p, void *fp)
} else
rt->target_class = p->process_class;
- rc = -EINVAL;
if (!policydb_type_isvalid(p, rt->source_type) ||
!policydb_type_isvalid(p, rt->target_type) ||
- !policydb_class_isvalid(p, rt->target_class))
+ !policydb_class_isvalid(p, rt->target_class)) {
+ rc = -EINVAL;
goto out;
+ }
- rc = -ENOMEM;
r = kzalloc(sizeof(*r), GFP_KERNEL);
- if (!r)
+ if (!r) {
+ rc = -ENOMEM;
goto out;
+ }
rc = mls_read_range_helper(r, fp);
if (rc)
goto out;
- rc = -EINVAL;
if (!mls_range_isvalid(p, r)) {
printk(KERN_WARNING "SELinux: rangetrans: invalid range\n");
+ rc = -EINVAL;
goto out;
}
--
2.11.0
[toc] | [prev] | [next] | [standalone]
| From | SF Markus Elfring <elfring@users.sourceforge.net> |
|---|---|
| Date | 2017-01-15 16:30 +0100 |
| Subject | [PATCH 24/46] selinux: Return directly after a failed kzalloc() in cat_read() |
| Message-ID | <sZUUN-47Q-3@gated-at.bofh.it> |
| In reply to | #1559248 |
From: Markus Elfring <elfring@users.sourceforge.net> Date: Sat, 14 Jan 2017 21:20:43 +0100 Return directly after a call of the function "kzalloc" failed at the beginning. Signed-off-by: Markus Elfring <elfring@users.sourceforge.net> --- security/selinux/ss/policydb.c | 3 +-- 1 file changed, 1 insertion(+), 2 deletions(-) diff --git a/security/selinux/ss/policydb.c b/security/selinux/ss/policydb.c index 5101592ae172..eb898dcbe502 100644 --- a/security/selinux/ss/policydb.c +++ b/security/selinux/ss/policydb.c @@ -1635,10 +1635,9 @@ static int cat_read(struct policydb *p, struct hashtab *h, void *fp) __le32 buf[3]; u32 len; - rc = -ENOMEM; catdatum = kzalloc(sizeof(*catdatum), GFP_ATOMIC); if (!catdatum) - goto bad; + return -ENOMEM; rc = next_entry(buf, fp, sizeof buf); if (rc) -- 2.11.0
[toc] | [prev] | [next] | [standalone]
| From | SF Markus Elfring <elfring@users.sourceforge.net> |
|---|---|
| Date | 2017-01-15 16:30 +0100 |
| Subject | [PATCH 21/46] selinux: Two function calls less in range_read() after error detection |
| Message-ID | <sZUUO-47Q-9@gated-at.bofh.it> |
| In reply to | #1559248 |
From: Markus Elfring <elfring@users.sourceforge.net>
Date: Sat, 14 Jan 2017 20:20:15 +0100
Adjust a jump target to avoid two calls of the function "kfree" at the end
after a memory allocation failed for the local variable "rt".
Signed-off-by: Markus Elfring <elfring@users.sourceforge.net>
---
security/selinux/ss/policydb.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/security/selinux/ss/policydb.c b/security/selinux/ss/policydb.c
index 4cd96ce51322..0d2f64558c0a 100644
--- a/security/selinux/ss/policydb.c
+++ b/security/selinux/ss/policydb.c
@@ -1857,7 +1857,7 @@ static int range_read(struct policydb *p, void *fp)
rt = kzalloc(sizeof(*rt), GFP_KERNEL);
if (!rt) {
rc = -ENOMEM;
- goto out;
+ goto exit;
}
rc = next_entry(buf, fp, (sizeof(u32) * 2));
@@ -1909,6 +1909,7 @@ static int range_read(struct policydb *p, void *fp)
out:
kfree(rt);
kfree(r);
+exit:
return rc;
}
--
2.11.0
[toc] | [prev] | [next] | [standalone]
| From | SF Markus Elfring <elfring@users.sourceforge.net> |
|---|---|
| Date | 2017-01-15 16:30 +0100 |
| Subject | [PATCH 23/46] selinux: Move an assignment for a pointer in range_read() |
| Message-ID | <sZUUO-47Q-13@gated-at.bofh.it> |
| In reply to | #1559248 |
From: Markus Elfring <elfring@users.sourceforge.net>
Date: Sat, 14 Jan 2017 21:00:45 +0100
Move the assignment for the local variable "r" behind a call of the
function "next_entry" at the beginning so that it will only be set
after a successful call.
Signed-off-by: Markus Elfring <elfring@users.sourceforge.net>
---
security/selinux/ss/policydb.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/security/selinux/ss/policydb.c b/security/selinux/ss/policydb.c
index 6121a26ada64..5101592ae172 100644
--- a/security/selinux/ss/policydb.c
+++ b/security/selinux/ss/policydb.c
@@ -1840,7 +1840,7 @@ u32 string_to_av_perm(struct policydb *p, u16 tclass, const char *name)
static int range_read(struct policydb *p, void *fp)
{
struct range_trans *rt;
- struct mls_range *r = NULL;
+ struct mls_range *r;
int i, rc;
__le32 buf[2];
u32 nel;
@@ -1852,6 +1852,7 @@ static int range_read(struct policydb *p, void *fp)
if (rc)
return rc;
+ r = NULL;
nel = le32_to_cpu(buf[0]);
for (i = 0; i < nel; i++) {
rt = kzalloc(sizeof(*rt), GFP_KERNEL);
--
2.11.0
[toc] | [prev] | [next] | [standalone]
| From | SF Markus Elfring <elfring@users.sourceforge.net> |
|---|---|
| Date | 2017-01-15 16:30 +0100 |
| Subject | [PATCH 29/46] selinux: Return directly after a failed kzalloc() in type_read() |
| Message-ID | <sZUUO-47Q-11@gated-at.bofh.it> |
| In reply to | #1559248 |
From: Markus Elfring <elfring@users.sourceforge.net> Date: Sat, 14 Jan 2017 22:15:54 +0100 Return directly after a call of the function "kzalloc" failed at the beginning. Signed-off-by: Markus Elfring <elfring@users.sourceforge.net> --- security/selinux/ss/policydb.c | 3 +-- 1 file changed, 1 insertion(+), 2 deletions(-) diff --git a/security/selinux/ss/policydb.c b/security/selinux/ss/policydb.c index 1c046d39e2a7..662139365449 100644 --- a/security/selinux/ss/policydb.c +++ b/security/selinux/ss/policydb.c @@ -1467,10 +1467,9 @@ static int type_read(struct policydb *p, struct hashtab *h, void *fp) __le32 buf[4]; u32 len; - rc = -ENOMEM; typdatum = kzalloc(sizeof(*typdatum), GFP_KERNEL); if (!typdatum) - goto bad; + return -ENOMEM; if (p->policyvers >= POLICYDB_VERSION_BOUNDARY) to_read = 4; -- 2.11.0
[toc] | [prev] | [next] | [standalone]
| From | SF Markus Elfring <elfring@users.sourceforge.net> |
|---|---|
| Date | 2017-01-15 16:30 +0100 |
| Subject | [PATCH 25/46] selinux: Return directly after a failed kzalloc() in sens_read() |
| Message-ID | <sZUUO-47Q-15@gated-at.bofh.it> |
| In reply to | #1559248 |
From: Markus Elfring <elfring@users.sourceforge.net> Date: Sat, 14 Jan 2017 21:42:02 +0100 Return directly after a call of the function "kzalloc" failed at the beginning. Signed-off-by: Markus Elfring <elfring@users.sourceforge.net> --- security/selinux/ss/policydb.c | 3 +-- 1 file changed, 1 insertion(+), 2 deletions(-) diff --git a/security/selinux/ss/policydb.c b/security/selinux/ss/policydb.c index eb898dcbe502..5caa1fa5ea80 100644 --- a/security/selinux/ss/policydb.c +++ b/security/selinux/ss/policydb.c @@ -1593,10 +1593,9 @@ static int sens_read(struct policydb *p, struct hashtab *h, void *fp) __le32 buf[2]; u32 len; - rc = -ENOMEM; levdatum = kzalloc(sizeof(*levdatum), GFP_ATOMIC); if (!levdatum) - goto bad; + return -ENOMEM; rc = next_entry(buf, fp, sizeof buf); if (rc) -- 2.11.0
[toc] | [prev] | [next] | [standalone]
| From | SF Markus Elfring <elfring@users.sourceforge.net> |
|---|---|
| Date | 2017-01-15 16:30 +0100 |
| Subject | [PATCH 26/46] selinux: Improve another size determination in sens_read() |
| Message-ID | <sZUUO-47Q-17@gated-at.bofh.it> |
| In reply to | #1559248 |
From: Markus Elfring <elfring@users.sourceforge.net> Date: Sat, 14 Jan 2017 21:52:55 +0100 Replace the specification of a data type by a pointer dereference as the parameter for the operator "sizeof" to make the corresponding size determination a bit safer according to the Linux coding style convention. Signed-off-by: Markus Elfring <elfring@users.sourceforge.net> --- security/selinux/ss/policydb.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/security/selinux/ss/policydb.c b/security/selinux/ss/policydb.c index 5caa1fa5ea80..edfcfd3bbc60 100644 --- a/security/selinux/ss/policydb.c +++ b/security/selinux/ss/policydb.c @@ -1609,7 +1609,7 @@ static int sens_read(struct policydb *p, struct hashtab *h, void *fp) goto bad; rc = -ENOMEM; - levdatum->level = kmalloc(sizeof(struct mls_level), GFP_ATOMIC); + levdatum->level = kmalloc(sizeof(*levdatum->level), GFP_ATOMIC); if (!levdatum->level) goto bad; -- 2.11.0
[toc] | [prev] | [next] | [standalone]
| From | SF Markus Elfring <elfring@users.sourceforge.net> |
|---|---|
| Date | 2017-01-15 16:30 +0100 |
| Subject | [PATCH 27/46] selinux: Move an assignment for the variable "rc" in sens_read() |
| Message-ID | <sZUUO-47Q-19@gated-at.bofh.it> |
| In reply to | #1559248 |
From: Markus Elfring <elfring@users.sourceforge.net>
Date: Sat, 14 Jan 2017 22:02:14 +0100
A local variable was set to an error code in one case before a concrete
error situation was detected. Thus move the corresponding assignment into
an if branch to indicate a software failure there.
Signed-off-by: Markus Elfring <elfring@users.sourceforge.net>
---
security/selinux/ss/policydb.c | 5 +++--
1 file changed, 3 insertions(+), 2 deletions(-)
diff --git a/security/selinux/ss/policydb.c b/security/selinux/ss/policydb.c
index edfcfd3bbc60..3e43556e67b8 100644
--- a/security/selinux/ss/policydb.c
+++ b/security/selinux/ss/policydb.c
@@ -1608,10 +1608,11 @@ static int sens_read(struct policydb *p, struct hashtab *h, void *fp)
if (rc)
goto bad;
- rc = -ENOMEM;
levdatum->level = kmalloc(sizeof(*levdatum->level), GFP_ATOMIC);
- if (!levdatum->level)
+ if (!levdatum->level) {
+ rc = -ENOMEM;
goto bad;
+ }
rc = mls_read_level(levdatum->level, fp);
if (rc)
--
2.11.0
[toc] | [prev] | [next] | [standalone]
| From | SF Markus Elfring <elfring@users.sourceforge.net> |
|---|---|
| Date | 2017-01-15 16:30 +0100 |
| Subject | [PATCH 22/46] selinux: Delete an unnecessary variable initialisation in range_read() |
| Message-ID | <sZUUO-47Q-25@gated-at.bofh.it> |
| In reply to | #1559248 |
From: Markus Elfring <elfring@users.sourceforge.net>
Date: Sat, 14 Jan 2017 20:40:12 +0100
The local variable "rt" will be set to an appropriate pointer a bit later.
Thus omit the explicit initialisation at the beginning which became
unnecessary with a previous update step.
Signed-off-by: Markus Elfring <elfring@users.sourceforge.net>
---
security/selinux/ss/policydb.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/security/selinux/ss/policydb.c b/security/selinux/ss/policydb.c
index 0d2f64558c0a..6121a26ada64 100644
--- a/security/selinux/ss/policydb.c
+++ b/security/selinux/ss/policydb.c
@@ -1839,7 +1839,7 @@ u32 string_to_av_perm(struct policydb *p, u16 tclass, const char *name)
static int range_read(struct policydb *p, void *fp)
{
- struct range_trans *rt = NULL;
+ struct range_trans *rt;
struct mls_range *r = NULL;
int i, rc;
__le32 buf[2];
--
2.11.0
[toc] | [prev] | [next] | [standalone]
| From | SF Markus Elfring <elfring@users.sourceforge.net> |
|---|---|
| Date | 2017-01-15 16:40 +0100 |
| Subject | [PATCH 35/46] selinux: Return directly after a failed kzalloc() in perm_read() |
| Message-ID | <sZV4t-4aR-1@gated-at.bofh.it> |
| In reply to | #1559248 |
From: Markus Elfring <elfring@users.sourceforge.net> Date: Sun, 15 Jan 2017 11:20:13 +0100 Return directly after a call of the function "kzalloc" failed at the beginning. Signed-off-by: Markus Elfring <elfring@users.sourceforge.net> --- security/selinux/ss/policydb.c | 3 +-- 1 file changed, 1 insertion(+), 2 deletions(-) diff --git a/security/selinux/ss/policydb.c b/security/selinux/ss/policydb.c index 551685283399..9b595f2e0d9f 100644 --- a/security/selinux/ss/policydb.c +++ b/security/selinux/ss/policydb.c @@ -1116,10 +1116,9 @@ static int perm_read(struct policydb *p, struct hashtab *h, void *fp) __le32 buf[2]; u32 len; - rc = -ENOMEM; perdatum = kzalloc(sizeof(*perdatum), GFP_KERNEL); if (!perdatum) - goto bad; + return -ENOMEM; rc = next_entry(buf, fp, sizeof buf); if (rc) -- 2.11.0
[toc] | [prev] | [next] | [standalone]
| From | SF Markus Elfring <elfring@users.sourceforge.net> |
|---|---|
| Date | 2017-01-15 16:40 +0100 |
| Subject | [PATCH 32/46] selinux: Return directly after a failed kzalloc() in class_read() |
| Message-ID | <sZV4t-4aR-5@gated-at.bofh.it> |
| In reply to | #1559248 |
From: Markus Elfring <elfring@users.sourceforge.net> Date: Sat, 14 Jan 2017 22:30:51 +0100 Return directly after a call of the function "kzalloc" failed at the beginning. Signed-off-by: Markus Elfring <elfring@users.sourceforge.net> --- security/selinux/ss/policydb.c | 3 +-- 1 file changed, 1 insertion(+), 2 deletions(-) diff --git a/security/selinux/ss/policydb.c b/security/selinux/ss/policydb.c index 49fc5d8990e9..3af2b0849495 100644 --- a/security/selinux/ss/policydb.c +++ b/security/selinux/ss/policydb.c @@ -1316,10 +1316,9 @@ static int class_read(struct policydb *p, struct hashtab *h, void *fp) u32 len, len2, ncons, nel; int i, rc; - rc = -ENOMEM; cladatum = kzalloc(sizeof(*cladatum), GFP_KERNEL); if (!cladatum) - goto bad; + return -ENOMEM; rc = next_entry(buf, fp, sizeof(u32)*6); if (rc) -- 2.11.0
[toc] | [prev] | [next] | [standalone]
| From | SF Markus Elfring <elfring@users.sourceforge.net> |
|---|---|
| Date | 2017-01-15 16:40 +0100 |
| Subject | [PATCH 39/46] selinux: Move two assignments for the variable "rc" in ocontext_read() |
| Message-ID | <sZV4t-4aR-11@gated-at.bofh.it> |
| In reply to | #1559248 |
From: Markus Elfring <elfring@users.sourceforge.net>
Date: Sun, 15 Jan 2017 11:30:12 +0100
One local variable was set to an error code in two cases before
a concrete error situation was detected. Thus move the corresponding
assignments into if branches to indicate a software failure there.
Signed-off-by: Markus Elfring <elfring@users.sourceforge.net>
---
security/selinux/ss/policydb.c | 13 +++++++------
1 file changed, 7 insertions(+), 6 deletions(-)
diff --git a/security/selinux/ss/policydb.c b/security/selinux/ss/policydb.c
index 88730b372277..8b9ed3f1b132 100644
--- a/security/selinux/ss/policydb.c
+++ b/security/selinux/ss/policydb.c
@@ -2121,10 +2121,11 @@ static int ocontext_read(struct policydb *p, struct policydb_compat_info *info,
l = NULL;
for (j = 0; j < nel; j++) {
- rc = -ENOMEM;
c = kzalloc(sizeof(*c), GFP_KERNEL);
- if (!c)
+ if (!c) {
+ rc = -ENOMEM;
goto out;
+ }
if (l)
l->next = c;
else
@@ -2186,13 +2187,13 @@ static int ocontext_read(struct policydb *p, struct policydb_compat_info *info,
if (rc)
goto out;
- rc = -EINVAL;
c->v.behavior = le32_to_cpu(buf[0]);
/* Determined at runtime, not in policy DB. */
- if (c->v.behavior == SECURITY_FS_USE_MNTPOINT)
- goto out;
- if (c->v.behavior > SECURITY_FS_USE_MAX)
+ if (c->v.behavior == SECURITY_FS_USE_MNTPOINT ||
+ c->v.behavior > SECURITY_FS_USE_MAX) {
+ rc = -EINVAL;
goto out;
+ }
len = le32_to_cpu(buf[1]);
rc = str_read(&c->u.name, GFP_KERNEL, fp, len);
--
2.11.0
[toc] | [prev] | [next] | [standalone]
| From | SF Markus Elfring <elfring@users.sourceforge.net> |
|---|---|
| Date | 2017-01-15 16:40 +0100 |
| Subject | [PATCH 33/46] selinux: Move an assignment for the variable "rc" in class_read() |
| Message-ID | <sZV4u-4aR-17@gated-at.bofh.it> |
| In reply to | #1559248 |
From: Markus Elfring <elfring@users.sourceforge.net>
Date: Sun, 15 Jan 2017 11:10:39 +0100
A local variable was set to an error code in one case before a concrete
error situation was detected. Thus move the corresponding assignment into
an if branch to indicate a software failure there.
Signed-off-by: Markus Elfring <elfring@users.sourceforge.net>
---
security/selinux/ss/policydb.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/security/selinux/ss/policydb.c b/security/selinux/ss/policydb.c
index 3af2b0849495..9035e5329ceb 100644
--- a/security/selinux/ss/policydb.c
+++ b/security/selinux/ss/policydb.c
@@ -1345,10 +1345,10 @@ static int class_read(struct policydb *p, struct hashtab *h, void *fp)
if (rc)
goto bad;
- rc = -EINVAL;
cladatum->comdatum = hashtab_search(p->p_commons.table, cladatum->comkey);
if (!cladatum->comdatum) {
printk(KERN_ERR "SELinux: unknown common %s\n", cladatum->comkey);
+ rc = -EINVAL;
goto bad;
}
}
--
2.11.0
[toc] | [prev] | [next] | [standalone]
| From | SF Markus Elfring <elfring@users.sourceforge.net> |
|---|---|
| Date | 2017-01-15 16:40 +0100 |
| Subject | [PATCH 37/46] selinux: Move an assignment for the variable "rc" in policydb_load_isids() |
| Message-ID | <sZV4u-4aR-19@gated-at.bofh.it> |
| In reply to | #1559248 |
From: Markus Elfring <elfring@users.sourceforge.net>
Date: Sun, 15 Jan 2017 11:24:51 +0100
A local variable was set to an error code in one case before a concrete
error situation was detected. Thus move the corresponding assignment into
an if branch to indicate a software failure there.
Signed-off-by: Markus Elfring <elfring@users.sourceforge.net>
---
security/selinux/ss/policydb.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/security/selinux/ss/policydb.c b/security/selinux/ss/policydb.c
index 7cf635c650dc..faa6ecc2450d 100644
--- a/security/selinux/ss/policydb.c
+++ b/security/selinux/ss/policydb.c
@@ -897,10 +897,10 @@ int policydb_load_isids(struct policydb *p, struct sidtab *s)
head = p->ocontexts[OCON_ISID];
for (c = head; c; c = c->next) {
- rc = -EINVAL;
if (!c->context[0].user) {
printk(KERN_ERR "SELinux: SID %s was never defined.\n",
c->u.name);
+ rc = -EINVAL;
goto out;
}
--
2.11.0
[toc] | [prev] | [next] | [standalone]
| From | SF Markus Elfring <elfring@users.sourceforge.net> |
|---|---|
| Date | 2017-01-15 16:40 +0100 |
| Subject | [PATCH 38/46] selinux: One function call less in five functions after null pointer detection |
| Message-ID | <sZV4u-4aR-15@gated-at.bofh.it> |
| In reply to | #1559248 |
From: Markus Elfring <elfring@users.sourceforge.net> Date: Sun, 15 Jan 2017 11:28:02 +0100 Call the function "kfree" at the end only after it was determined that the passed parameter contained a non-null pointer. Signed-off-by: Markus Elfring <elfring@users.sourceforge.net> --- security/selinux/ss/policydb.c | 10 +++++----- 1 file changed, 5 insertions(+), 5 deletions(-) diff --git a/security/selinux/ss/policydb.c b/security/selinux/ss/policydb.c index faa6ecc2450d..88730b372277 100644 --- a/security/selinux/ss/policydb.c +++ b/security/selinux/ss/policydb.c @@ -620,8 +620,8 @@ static int common_destroy(void *key, void *datum, void *p) comdatum = datum; hashtab_map(comdatum->permissions.table, perm_destroy, NULL); hashtab_destroy(comdatum->permissions.table); + kfree(datum); } - kfree(datum); return 0; } @@ -675,8 +675,8 @@ static int cls_destroy(void *key, void *datum, void *p) kfree(ctemp); } kfree(cladatum->comkey); + kfree(datum); } - kfree(datum); return 0; } @@ -689,8 +689,8 @@ static int role_destroy(void *key, void *datum, void *p) role = datum; ebitmap_destroy(&role->dominates); ebitmap_destroy(&role->types); + kfree(datum); } - kfree(datum); return 0; } @@ -712,8 +712,8 @@ static int user_destroy(void *key, void *datum, void *p) ebitmap_destroy(&usrdatum->range.level[0].cat); ebitmap_destroy(&usrdatum->range.level[1].cat); ebitmap_destroy(&usrdatum->dfltlevel.cat); + kfree(datum); } - kfree(datum); return 0; } @@ -726,8 +726,8 @@ static int sens_destroy(void *key, void *datum, void *p) levdatum = datum; ebitmap_destroy(&levdatum->level->cat); kfree(levdatum->level); + kfree(datum); } - kfree(datum); return 0; } -- 2.11.0
[toc] | [prev] | [next] | [standalone]
| From | SF Markus Elfring <elfring@users.sourceforge.net> |
|---|---|
| Date | 2017-01-15 16:40 +0100 |
| Subject | [PATCH 30/46] selinux: Return directly after a failed kzalloc() in role_read() |
| Message-ID | <sZV4u-4aR-23@gated-at.bofh.it> |
| In reply to | #1559248 |
From: Markus Elfring <elfring@users.sourceforge.net> Date: Sat, 14 Jan 2017 22:20:25 +0100 Return directly after a call of the function "kzalloc" failed at the beginning. Signed-off-by: Markus Elfring <elfring@users.sourceforge.net> --- security/selinux/ss/policydb.c | 3 +-- 1 file changed, 1 insertion(+), 2 deletions(-) diff --git a/security/selinux/ss/policydb.c b/security/selinux/ss/policydb.c index 662139365449..34b670227c4d 100644 --- a/security/selinux/ss/policydb.c +++ b/security/selinux/ss/policydb.c @@ -1410,10 +1410,9 @@ static int role_read(struct policydb *p, struct hashtab *h, void *fp) __le32 buf[3]; u32 len; - rc = -ENOMEM; role = kzalloc(sizeof(*role), GFP_KERNEL); if (!role) - goto bad; + return -ENOMEM; if (p->policyvers >= POLICYDB_VERSION_BOUNDARY) to_read = 3; -- 2.11.0
[toc] | [prev] | [next] | [standalone]
| From | SF Markus Elfring <elfring@users.sourceforge.net> |
|---|---|
| Date | 2017-01-15 16:40 +0100 |
| Subject | [PATCH 31/46] selinux: Move an assignment for the variable "rc" in role_read() |
| Message-ID | <sZV4u-4aR-31@gated-at.bofh.it> |
| In reply to | #1559248 |
From: Markus Elfring <elfring@users.sourceforge.net>
Date: Sat, 14 Jan 2017 22:25:20 +0100
A local variable was set to an error code in one case before a concrete
error situation was detected. Thus move the corresponding assignment into
an if branch to indicate a software failure there.
Signed-off-by: Markus Elfring <elfring@users.sourceforge.net>
---
security/selinux/ss/policydb.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/security/selinux/ss/policydb.c b/security/selinux/ss/policydb.c
index 34b670227c4d..49fc5d8990e9 100644
--- a/security/selinux/ss/policydb.c
+++ b/security/selinux/ss/policydb.c
@@ -1439,10 +1439,10 @@ static int role_read(struct policydb *p, struct hashtab *h, void *fp)
goto bad;
if (strcmp(key, OBJECT_R) == 0) {
- rc = -EINVAL;
if (role->value != OBJECT_R_VAL) {
printk(KERN_ERR "SELinux: Role %s has wrong value %d\n",
OBJECT_R, role->value);
+ rc = -EINVAL;
goto bad;
}
rc = 0;
--
2.11.0
[toc] | [prev] | [next] | [standalone]
| From | SF Markus Elfring <elfring@users.sourceforge.net> |
|---|---|
| Date | 2017-01-15 16:40 +0100 |
| Subject | [PATCH 36/46] selinux: Move an assignment for the variable "rc" in mls_read_range_helper() |
| Message-ID | <sZV4u-4aR-21@gated-at.bofh.it> |
| In reply to | #1559248 |
From: Markus Elfring <elfring@users.sourceforge.net>
Date: Sun, 15 Jan 2017 11:22:23 +0100
A local variable was set to an error code in one case before a concrete
error situation was detected. Thus move the corresponding assignment into
an if branch to indicate a software failure there.
Signed-off-by: Markus Elfring <elfring@users.sourceforge.net>
---
security/selinux/ss/policydb.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/security/selinux/ss/policydb.c b/security/selinux/ss/policydb.c
index 9b595f2e0d9f..7cf635c650dc 100644
--- a/security/selinux/ss/policydb.c
+++ b/security/selinux/ss/policydb.c
@@ -996,10 +996,10 @@ static int mls_read_range_helper(struct mls_range *r, void *fp)
if (rc)
goto out;
- rc = -EINVAL;
items = le32_to_cpu(buf[0]);
if (items > ARRAY_SIZE(buf)) {
printk(KERN_ERR "SELinux: mls: range overflow\n");
+ rc = -EINVAL;
goto out;
}
--
2.11.0
[toc] | [prev] | [next] | [standalone]
| From | SF Markus Elfring <elfring@users.sourceforge.net> |
|---|---|
| Date | 2017-01-15 16:40 +0100 |
| Subject | [PATCH 34/46] selinux: Return directly after a failed kzalloc() in common_read() |
| Message-ID | <sZV4u-4aR-25@gated-at.bofh.it> |
| In reply to | #1559248 |
From: Markus Elfring <elfring@users.sourceforge.net> Date: Sun, 15 Jan 2017 11:15:19 +0100 Return directly after a call of the function "kzalloc" failed at the beginning. Signed-off-by: Markus Elfring <elfring@users.sourceforge.net> --- security/selinux/ss/policydb.c | 3 +-- 1 file changed, 1 insertion(+), 2 deletions(-) diff --git a/security/selinux/ss/policydb.c b/security/selinux/ss/policydb.c index 9035e5329ceb..551685283399 100644 --- a/security/selinux/ss/policydb.c +++ b/security/selinux/ss/policydb.c @@ -1150,10 +1150,9 @@ static int common_read(struct policydb *p, struct hashtab *h, void *fp) u32 len, nel; int i, rc; - rc = -ENOMEM; comdatum = kzalloc(sizeof(*comdatum), GFP_KERNEL); if (!comdatum) - goto bad; + return -ENOMEM; rc = next_entry(buf, fp, sizeof buf); if (rc) -- 2.11.0
[toc] | [prev] | [next] | [standalone]
Page 2 of 3 — ← Prev page 1 [2] 3 Next page →
Back to top | Article view | linux.kernel
csiph-web