Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1559248 > unrolled thread

[PATCH 00/46] SELinux: Fine-tuning for several function implementations

Started bySF Markus Elfring <elfring@users.sourceforge.net>
First post2017-01-15 16:00 +0100
Last post2017-01-16 19:40 +0100
Articles 20 on this page of 50 — 3 participants

Back to article view | Back to linux.kernel


Contents

  [PATCH 00/46] SELinux: Fine-tuning for several function  implementations SF Markus Elfring <elfring@users.sourceforge.net> - 2017-01-15 16:00 +0100
    [PATCH 02/46] selinux: Delete an unnecessary return statement in  cond_compute_av() SF Markus Elfring <elfring@users.sourceforge.net> - 2017-01-15 16:00 +0100
    [PATCH 01/46] selinux: Use kmalloc_array() in  cond_init_bool_indexes() SF Markus Elfring <elfring@users.sourceforge.net> - 2017-01-15 16:00 +0100
    [PATCH 04/46] selinux: Use kmalloc_array() in hashtab_create() SF Markus Elfring <elfring@users.sourceforge.net> - 2017-01-15 16:10 +0100
    [PATCH 05/46] selinux: Adjust four checks for null pointers SF Markus Elfring <elfring@users.sourceforge.net> - 2017-01-15 16:10 +0100
    [PATCH 07/46] selinux: Delete unnecessary variable assignments in  policydb_index() SF Markus Elfring <elfring@users.sourceforge.net> - 2017-01-15 16:10 +0100
    [PATCH 09/46] selinux: Delete an error message for a failed memory  allocation in policydb_read() SF Markus Elfring <elfring@users.sourceforge.net> - 2017-01-15 16:10 +0100
    [PATCH 08/46] selinux: Delete an unnecessary return statement in  policydb_destroy() SF Markus Elfring <elfring@users.sourceforge.net> - 2017-01-15 16:10 +0100
    [PATCH 03/46] selinux: Improve size determinations in four functions SF Markus Elfring <elfring@users.sourceforge.net> - 2017-01-15 16:10 +0100
    [PATCH 06/46] selinux: Use kcalloc() in policydb_index() SF Markus Elfring <elfring@users.sourceforge.net> - 2017-01-15 16:10 +0100
    [PATCH 18/46] selinux: One function call less in  filename_trans_read() after error detection SF Markus Elfring <elfring@users.sourceforge.net> - 2017-01-15 16:20 +0100
    [PATCH 17/46] selinux: Delete an unnecessary variable assignment in  filename_trans_read() SF Markus Elfring <elfring@users.sourceforge.net> - 2017-01-15 16:20 +0100
    [PATCH 11/46] selinux: Return directly after a failed next_entry() in  genfs_read() SF Markus Elfring <elfring@users.sourceforge.net> - 2017-01-15 16:20 +0100
    [PATCH 15/46] selinux: One check and function call less in  genfs_read() after error detection SF Markus Elfring <elfring@users.sourceforge.net> - 2017-01-15 16:20 +0100
    [PATCH 16/46] selinux: Move two assignments for the variable "rc" in  filename_trans_read() SF Markus Elfring <elfring@users.sourceforge.net> - 2017-01-15 16:20 +0100
    [PATCH 13/46] selinux: Move four assignments for the variable "rc" in  genfs_read() SF Markus Elfring <elfring@users.sourceforge.net> - 2017-01-15 16:20 +0100
    [PATCH 14/46] selinux: One function call less in genfs_read() after  null pointer detection SF Markus Elfring <elfring@users.sourceforge.net> - 2017-01-15 16:20 +0100
    [PATCH 19/46] selinux: Return directly after a failed next_entry() in  range_read() SF Markus Elfring <elfring@users.sourceforge.net> - 2017-01-15 16:20 +0100
    [PATCH 10/46] selinux: Move some assignments for the variable "rc" in  policydb_read() SF Markus Elfring <elfring@users.sourceforge.net> - 2017-01-15 16:20 +0100
    [PATCH 12/46] selinux: Move assignments for two pointers in  genfs_read() SF Markus Elfring <elfring@users.sourceforge.net> - 2017-01-15 16:20 +0100
    [PATCH 28/46] selinux: Return directly after a failed kzalloc() in  user_read() SF Markus Elfring <elfring@users.sourceforge.net> - 2017-01-15 16:30 +0100
    [PATCH 20/46] selinux: Move four assignments for the variable "rc" in  range_read() SF Markus Elfring <elfring@users.sourceforge.net> - 2017-01-15 16:30 +0100
    [PATCH 24/46] selinux: Return directly after a failed kzalloc() in  cat_read() SF Markus Elfring <elfring@users.sourceforge.net> - 2017-01-15 16:30 +0100
    [PATCH 21/46] selinux: Two function calls less in range_read() after  error detection SF Markus Elfring <elfring@users.sourceforge.net> - 2017-01-15 16:30 +0100
    [PATCH 23/46] selinux: Move an assignment for a pointer in  range_read() SF Markus Elfring <elfring@users.sourceforge.net> - 2017-01-15 16:30 +0100
    [PATCH 29/46] selinux: Return directly after a failed kzalloc() in  type_read() SF Markus Elfring <elfring@users.sourceforge.net> - 2017-01-15 16:30 +0100
    [PATCH 25/46] selinux: Return directly after a failed kzalloc() in  sens_read() SF Markus Elfring <elfring@users.sourceforge.net> - 2017-01-15 16:30 +0100
    [PATCH 26/46] selinux: Improve another size determination in  sens_read() SF Markus Elfring <elfring@users.sourceforge.net> - 2017-01-15 16:30 +0100
    [PATCH 27/46] selinux: Move an assignment for the variable "rc" in  sens_read() SF Markus Elfring <elfring@users.sourceforge.net> - 2017-01-15 16:30 +0100
    [PATCH 22/46] selinux: Delete an unnecessary variable initialisation  in range_read() SF Markus Elfring <elfring@users.sourceforge.net> - 2017-01-15 16:30 +0100
    [PATCH 35/46] selinux: Return directly after a failed kzalloc() in  perm_read() SF Markus Elfring <elfring@users.sourceforge.net> - 2017-01-15 16:40 +0100
    [PATCH 32/46] selinux: Return directly after a failed kzalloc() in  class_read() SF Markus Elfring <elfring@users.sourceforge.net> - 2017-01-15 16:40 +0100
    [PATCH 39/46] selinux: Move two assignments for the variable "rc" in  ocontext_read() SF Markus Elfring <elfring@users.sourceforge.net> - 2017-01-15 16:40 +0100
    [PATCH 33/46] selinux: Move an assignment for the variable "rc" in  class_read() SF Markus Elfring <elfring@users.sourceforge.net> - 2017-01-15 16:40 +0100
    [PATCH 37/46] selinux: Move an assignment for the variable "rc" in  policydb_load_isids() SF Markus Elfring <elfring@users.sourceforge.net> - 2017-01-15 16:40 +0100
    [PATCH 38/46] selinux: One function call less in five functions after  null pointer detection SF Markus Elfring <elfring@users.sourceforge.net> - 2017-01-15 16:40 +0100
    [PATCH 30/46] selinux: Return directly after a failed kzalloc() in  role_read() SF Markus Elfring <elfring@users.sourceforge.net> - 2017-01-15 16:40 +0100
    [PATCH 31/46] selinux: Move an assignment for the variable "rc" in  role_read() SF Markus Elfring <elfring@users.sourceforge.net> - 2017-01-15 16:40 +0100
    [PATCH 36/46] selinux: Move an assignment for the variable "rc" in  mls_read_range_helper() SF Markus Elfring <elfring@users.sourceforge.net> - 2017-01-15 16:40 +0100
    [PATCH 34/46] selinux: Return directly after a failed kzalloc() in  common_read() SF Markus Elfring <elfring@users.sourceforge.net> - 2017-01-15 16:40 +0100
    [PATCH 45/46] selinux: Use common error handling code in  sidtab_insert() SF Markus Elfring <elfring@users.sourceforge.net> - 2017-01-15 16:50 +0100
    [PATCH 44/46] selinux: Adjust two checks for null pointers SF Markus Elfring <elfring@users.sourceforge.net> - 2017-01-15 16:50 +0100
    [PATCH 40/46] selinux: Return directly after a failed kzalloc() in  roles_init() SF Markus Elfring <elfring@users.sourceforge.net> - 2017-01-15 16:50 +0100
    [PATCH 46/46] selinuxfs: Use seq_puts() in sel_avc_stats_seq_show() SF Markus Elfring <elfring@users.sourceforge.net> - 2017-01-15 16:50 +0100
    [PATCH 43/46] selinux: Use kmalloc_array() in sidtab_init() SF Markus Elfring <elfring@users.sourceforge.net> - 2017-01-15 16:50 +0100
    [PATCH 42/46] selinux: One function call less in roles_init() after  error detection SF Markus Elfring <elfring@users.sourceforge.net> - 2017-01-15 16:50 +0100
    [PATCH 41/46] selinux: Move two assignments for the variable "rc" in  roles_init() SF Markus Elfring <elfring@users.sourceforge.net> - 2017-01-15 16:50 +0100
    Re: [PATCH 00/46] SELinux: Fine-tuning for several function  implementations Eric Paris <eparis@redhat.com> - 2017-01-16 16:30 +0100
      Re: [PATCH 00/46] SELinux: Fine-tuning for several function implementations Paul Moore <paul@paul-moore.com> - 2017-01-16 17:50 +0100
      Re: SELinux: Checking source code positions for the setting of error  codes SF Markus Elfring <elfring@users.sourceforge.net> - 2017-01-16 19:40 +0100

Page 2 of 3 — ← Prev page 1 [2] 3  Next page →


#1559270 — [PATCH 28/46] selinux: Return directly after a failed kzalloc() in user_read()

FromSF Markus Elfring <elfring@users.sourceforge.net>
Date2017-01-15 16:30 +0100
Subject[PATCH 28/46] selinux: Return directly after a failed kzalloc() in user_read()
Message-ID<sZUUN-47Q-7@gated-at.bofh.it>
In reply to#1559248
From: Markus Elfring <elfring@users.sourceforge.net>
Date: Sat, 14 Jan 2017 22:08:22 +0100

Return directly after a call of the function "kzalloc" failed
at the beginning.

Signed-off-by: Markus Elfring <elfring@users.sourceforge.net>
---
 security/selinux/ss/policydb.c | 3 +--
 1 file changed, 1 insertion(+), 2 deletions(-)

diff --git a/security/selinux/ss/policydb.c b/security/selinux/ss/policydb.c
index 3e43556e67b8..1c046d39e2a7 100644
--- a/security/selinux/ss/policydb.c
+++ b/security/selinux/ss/policydb.c
@@ -1542,10 +1542,9 @@ static int user_read(struct policydb *p, struct hashtab *h, void *fp)
 	__le32 buf[3];
 	u32 len;
 
-	rc = -ENOMEM;
 	usrdatum = kzalloc(sizeof(*usrdatum), GFP_KERNEL);
 	if (!usrdatum)
-		goto bad;
+		return -ENOMEM;
 
 	if (p->policyvers >= POLICYDB_VERSION_BOUNDARY)
 		to_read = 3;
-- 
2.11.0

[toc] | [prev] | [next] | [standalone]


#1559271 — [PATCH 20/46] selinux: Move four assignments for the variable "rc" in range_read()

FromSF Markus Elfring <elfring@users.sourceforge.net>
Date2017-01-15 16:30 +0100
Subject[PATCH 20/46] selinux: Move four assignments for the variable "rc" in range_read()
Message-ID<sZUUN-47Q-1@gated-at.bofh.it>
In reply to#1559248
From: Markus Elfring <elfring@users.sourceforge.net>
Date: Sat, 14 Jan 2017 19:55:00 +0100

One local variable was set to an error code in four cases before
a concrete error situation was detected. Thus move the corresponding
assignments into if branches to indicate a software failure there.

Signed-off-by: Markus Elfring <elfring@users.sourceforge.net>
---
 security/selinux/ss/policydb.c | 17 ++++++++++-------
 1 file changed, 10 insertions(+), 7 deletions(-)

diff --git a/security/selinux/ss/policydb.c b/security/selinux/ss/policydb.c
index a696876fc327..4cd96ce51322 100644
--- a/security/selinux/ss/policydb.c
+++ b/security/selinux/ss/policydb.c
@@ -1854,10 +1854,11 @@ static int range_read(struct policydb *p, void *fp)
 
 	nel = le32_to_cpu(buf[0]);
 	for (i = 0; i < nel; i++) {
-		rc = -ENOMEM;
 		rt = kzalloc(sizeof(*rt), GFP_KERNEL);
-		if (!rt)
+		if (!rt) {
+			rc = -ENOMEM;
 			goto out;
+		}
 
 		rc = next_entry(buf, fp, (sizeof(u32) * 2));
 		if (rc)
@@ -1873,24 +1874,26 @@ static int range_read(struct policydb *p, void *fp)
 		} else
 			rt->target_class = p->process_class;
 
-		rc = -EINVAL;
 		if (!policydb_type_isvalid(p, rt->source_type) ||
 		    !policydb_type_isvalid(p, rt->target_type) ||
-		    !policydb_class_isvalid(p, rt->target_class))
+		    !policydb_class_isvalid(p, rt->target_class)) {
+			rc = -EINVAL;
 			goto out;
+		}
 
-		rc = -ENOMEM;
 		r = kzalloc(sizeof(*r), GFP_KERNEL);
-		if (!r)
+		if (!r) {
+			rc = -ENOMEM;
 			goto out;
+		}
 
 		rc = mls_read_range_helper(r, fp);
 		if (rc)
 			goto out;
 
-		rc = -EINVAL;
 		if (!mls_range_isvalid(p, r)) {
 			printk(KERN_WARNING "SELinux:  rangetrans:  invalid range\n");
+			rc = -EINVAL;
 			goto out;
 		}
 
-- 
2.11.0

[toc] | [prev] | [next] | [standalone]


#1559272 — [PATCH 24/46] selinux: Return directly after a failed kzalloc() in cat_read()

FromSF Markus Elfring <elfring@users.sourceforge.net>
Date2017-01-15 16:30 +0100
Subject[PATCH 24/46] selinux: Return directly after a failed kzalloc() in cat_read()
Message-ID<sZUUN-47Q-3@gated-at.bofh.it>
In reply to#1559248
From: Markus Elfring <elfring@users.sourceforge.net>
Date: Sat, 14 Jan 2017 21:20:43 +0100

Return directly after a call of the function "kzalloc" failed
at the beginning.

Signed-off-by: Markus Elfring <elfring@users.sourceforge.net>
---
 security/selinux/ss/policydb.c | 3 +--
 1 file changed, 1 insertion(+), 2 deletions(-)

diff --git a/security/selinux/ss/policydb.c b/security/selinux/ss/policydb.c
index 5101592ae172..eb898dcbe502 100644
--- a/security/selinux/ss/policydb.c
+++ b/security/selinux/ss/policydb.c
@@ -1635,10 +1635,9 @@ static int cat_read(struct policydb *p, struct hashtab *h, void *fp)
 	__le32 buf[3];
 	u32 len;
 
-	rc = -ENOMEM;
 	catdatum = kzalloc(sizeof(*catdatum), GFP_ATOMIC);
 	if (!catdatum)
-		goto bad;
+		return -ENOMEM;
 
 	rc = next_entry(buf, fp, sizeof buf);
 	if (rc)
-- 
2.11.0

[toc] | [prev] | [next] | [standalone]


#1559274 — [PATCH 21/46] selinux: Two function calls less in range_read() after error detection

FromSF Markus Elfring <elfring@users.sourceforge.net>
Date2017-01-15 16:30 +0100
Subject[PATCH 21/46] selinux: Two function calls less in range_read() after error detection
Message-ID<sZUUO-47Q-9@gated-at.bofh.it>
In reply to#1559248
From: Markus Elfring <elfring@users.sourceforge.net>
Date: Sat, 14 Jan 2017 20:20:15 +0100

Adjust a jump target to avoid two calls of the function "kfree" at the end
after a memory allocation failed for the local variable "rt".

Signed-off-by: Markus Elfring <elfring@users.sourceforge.net>
---
 security/selinux/ss/policydb.c | 3 ++-
 1 file changed, 2 insertions(+), 1 deletion(-)

diff --git a/security/selinux/ss/policydb.c b/security/selinux/ss/policydb.c
index 4cd96ce51322..0d2f64558c0a 100644
--- a/security/selinux/ss/policydb.c
+++ b/security/selinux/ss/policydb.c
@@ -1857,7 +1857,7 @@ static int range_read(struct policydb *p, void *fp)
 		rt = kzalloc(sizeof(*rt), GFP_KERNEL);
 		if (!rt) {
 			rc = -ENOMEM;
-			goto out;
+			goto exit;
 		}
 
 		rc = next_entry(buf, fp, (sizeof(u32) * 2));
@@ -1909,6 +1909,7 @@ static int range_read(struct policydb *p, void *fp)
 out:
 	kfree(rt);
 	kfree(r);
+exit:
 	return rc;
 }
 
-- 
2.11.0

[toc] | [prev] | [next] | [standalone]


#1559275 — [PATCH 23/46] selinux: Move an assignment for a pointer in range_read()

FromSF Markus Elfring <elfring@users.sourceforge.net>
Date2017-01-15 16:30 +0100
Subject[PATCH 23/46] selinux: Move an assignment for a pointer in range_read()
Message-ID<sZUUO-47Q-13@gated-at.bofh.it>
In reply to#1559248
From: Markus Elfring <elfring@users.sourceforge.net>
Date: Sat, 14 Jan 2017 21:00:45 +0100

Move the assignment for the local variable "r" behind a call of the
function "next_entry" at the beginning so that it will only be set
after a successful call.

Signed-off-by: Markus Elfring <elfring@users.sourceforge.net>
---
 security/selinux/ss/policydb.c | 3 ++-
 1 file changed, 2 insertions(+), 1 deletion(-)

diff --git a/security/selinux/ss/policydb.c b/security/selinux/ss/policydb.c
index 6121a26ada64..5101592ae172 100644
--- a/security/selinux/ss/policydb.c
+++ b/security/selinux/ss/policydb.c
@@ -1840,7 +1840,7 @@ u32 string_to_av_perm(struct policydb *p, u16 tclass, const char *name)
 static int range_read(struct policydb *p, void *fp)
 {
 	struct range_trans *rt;
-	struct mls_range *r = NULL;
+	struct mls_range *r;
 	int i, rc;
 	__le32 buf[2];
 	u32 nel;
@@ -1852,6 +1852,7 @@ static int range_read(struct policydb *p, void *fp)
 	if (rc)
 		return rc;
 
+	r = NULL;
 	nel = le32_to_cpu(buf[0]);
 	for (i = 0; i < nel; i++) {
 		rt = kzalloc(sizeof(*rt), GFP_KERNEL);
-- 
2.11.0

[toc] | [prev] | [next] | [standalone]


#1559276 — [PATCH 29/46] selinux: Return directly after a failed kzalloc() in type_read()

FromSF Markus Elfring <elfring@users.sourceforge.net>
Date2017-01-15 16:30 +0100
Subject[PATCH 29/46] selinux: Return directly after a failed kzalloc() in type_read()
Message-ID<sZUUO-47Q-11@gated-at.bofh.it>
In reply to#1559248
From: Markus Elfring <elfring@users.sourceforge.net>
Date: Sat, 14 Jan 2017 22:15:54 +0100

Return directly after a call of the function "kzalloc" failed
at the beginning.

Signed-off-by: Markus Elfring <elfring@users.sourceforge.net>
---
 security/selinux/ss/policydb.c | 3 +--
 1 file changed, 1 insertion(+), 2 deletions(-)

diff --git a/security/selinux/ss/policydb.c b/security/selinux/ss/policydb.c
index 1c046d39e2a7..662139365449 100644
--- a/security/selinux/ss/policydb.c
+++ b/security/selinux/ss/policydb.c
@@ -1467,10 +1467,9 @@ static int type_read(struct policydb *p, struct hashtab *h, void *fp)
 	__le32 buf[4];
 	u32 len;
 
-	rc = -ENOMEM;
 	typdatum = kzalloc(sizeof(*typdatum), GFP_KERNEL);
 	if (!typdatum)
-		goto bad;
+		return -ENOMEM;
 
 	if (p->policyvers >= POLICYDB_VERSION_BOUNDARY)
 		to_read = 4;
-- 
2.11.0

[toc] | [prev] | [next] | [standalone]


#1559277 — [PATCH 25/46] selinux: Return directly after a failed kzalloc() in sens_read()

FromSF Markus Elfring <elfring@users.sourceforge.net>
Date2017-01-15 16:30 +0100
Subject[PATCH 25/46] selinux: Return directly after a failed kzalloc() in sens_read()
Message-ID<sZUUO-47Q-15@gated-at.bofh.it>
In reply to#1559248
From: Markus Elfring <elfring@users.sourceforge.net>
Date: Sat, 14 Jan 2017 21:42:02 +0100

Return directly after a call of the function "kzalloc" failed
at the beginning.

Signed-off-by: Markus Elfring <elfring@users.sourceforge.net>
---
 security/selinux/ss/policydb.c | 3 +--
 1 file changed, 1 insertion(+), 2 deletions(-)

diff --git a/security/selinux/ss/policydb.c b/security/selinux/ss/policydb.c
index eb898dcbe502..5caa1fa5ea80 100644
--- a/security/selinux/ss/policydb.c
+++ b/security/selinux/ss/policydb.c
@@ -1593,10 +1593,9 @@ static int sens_read(struct policydb *p, struct hashtab *h, void *fp)
 	__le32 buf[2];
 	u32 len;
 
-	rc = -ENOMEM;
 	levdatum = kzalloc(sizeof(*levdatum), GFP_ATOMIC);
 	if (!levdatum)
-		goto bad;
+		return -ENOMEM;
 
 	rc = next_entry(buf, fp, sizeof buf);
 	if (rc)
-- 
2.11.0

[toc] | [prev] | [next] | [standalone]


#1559278 — [PATCH 26/46] selinux: Improve another size determination in sens_read()

FromSF Markus Elfring <elfring@users.sourceforge.net>
Date2017-01-15 16:30 +0100
Subject[PATCH 26/46] selinux: Improve another size determination in sens_read()
Message-ID<sZUUO-47Q-17@gated-at.bofh.it>
In reply to#1559248
From: Markus Elfring <elfring@users.sourceforge.net>
Date: Sat, 14 Jan 2017 21:52:55 +0100

Replace the specification of a data type by a pointer dereference
as the parameter for the operator "sizeof" to make the corresponding size
determination a bit safer according to the Linux coding style convention.

Signed-off-by: Markus Elfring <elfring@users.sourceforge.net>
---
 security/selinux/ss/policydb.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/security/selinux/ss/policydb.c b/security/selinux/ss/policydb.c
index 5caa1fa5ea80..edfcfd3bbc60 100644
--- a/security/selinux/ss/policydb.c
+++ b/security/selinux/ss/policydb.c
@@ -1609,7 +1609,7 @@ static int sens_read(struct policydb *p, struct hashtab *h, void *fp)
 		goto bad;
 
 	rc = -ENOMEM;
-	levdatum->level = kmalloc(sizeof(struct mls_level), GFP_ATOMIC);
+	levdatum->level = kmalloc(sizeof(*levdatum->level), GFP_ATOMIC);
 	if (!levdatum->level)
 		goto bad;
 
-- 
2.11.0

[toc] | [prev] | [next] | [standalone]


#1559279 — [PATCH 27/46] selinux: Move an assignment for the variable "rc" in sens_read()

FromSF Markus Elfring <elfring@users.sourceforge.net>
Date2017-01-15 16:30 +0100
Subject[PATCH 27/46] selinux: Move an assignment for the variable "rc" in sens_read()
Message-ID<sZUUO-47Q-19@gated-at.bofh.it>
In reply to#1559248
From: Markus Elfring <elfring@users.sourceforge.net>
Date: Sat, 14 Jan 2017 22:02:14 +0100

A local variable was set to an error code in one case before a concrete
error situation was detected. Thus move the corresponding assignment into
an if branch to indicate a software failure there.

Signed-off-by: Markus Elfring <elfring@users.sourceforge.net>
---
 security/selinux/ss/policydb.c | 5 +++--
 1 file changed, 3 insertions(+), 2 deletions(-)

diff --git a/security/selinux/ss/policydb.c b/security/selinux/ss/policydb.c
index edfcfd3bbc60..3e43556e67b8 100644
--- a/security/selinux/ss/policydb.c
+++ b/security/selinux/ss/policydb.c
@@ -1608,10 +1608,11 @@ static int sens_read(struct policydb *p, struct hashtab *h, void *fp)
 	if (rc)
 		goto bad;
 
-	rc = -ENOMEM;
 	levdatum->level = kmalloc(sizeof(*levdatum->level), GFP_ATOMIC);
-	if (!levdatum->level)
+	if (!levdatum->level) {
+		rc = -ENOMEM;
 		goto bad;
+	}
 
 	rc = mls_read_level(levdatum->level, fp);
 	if (rc)
-- 
2.11.0

[toc] | [prev] | [next] | [standalone]


#1559280 — [PATCH 22/46] selinux: Delete an unnecessary variable initialisation in range_read()

FromSF Markus Elfring <elfring@users.sourceforge.net>
Date2017-01-15 16:30 +0100
Subject[PATCH 22/46] selinux: Delete an unnecessary variable initialisation in range_read()
Message-ID<sZUUO-47Q-25@gated-at.bofh.it>
In reply to#1559248
From: Markus Elfring <elfring@users.sourceforge.net>
Date: Sat, 14 Jan 2017 20:40:12 +0100

The local variable "rt" will be set to an appropriate pointer a bit later.
Thus omit the explicit initialisation at the beginning which became
unnecessary with a previous update step.

Signed-off-by: Markus Elfring <elfring@users.sourceforge.net>
---
 security/selinux/ss/policydb.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/security/selinux/ss/policydb.c b/security/selinux/ss/policydb.c
index 0d2f64558c0a..6121a26ada64 100644
--- a/security/selinux/ss/policydb.c
+++ b/security/selinux/ss/policydb.c
@@ -1839,7 +1839,7 @@ u32 string_to_av_perm(struct policydb *p, u16 tclass, const char *name)
 
 static int range_read(struct policydb *p, void *fp)
 {
-	struct range_trans *rt = NULL;
+	struct range_trans *rt;
 	struct mls_range *r = NULL;
 	int i, rc;
 	__le32 buf[2];
-- 
2.11.0

[toc] | [prev] | [next] | [standalone]


#1559281 — [PATCH 35/46] selinux: Return directly after a failed kzalloc() in perm_read()

FromSF Markus Elfring <elfring@users.sourceforge.net>
Date2017-01-15 16:40 +0100
Subject[PATCH 35/46] selinux: Return directly after a failed kzalloc() in perm_read()
Message-ID<sZV4t-4aR-1@gated-at.bofh.it>
In reply to#1559248
From: Markus Elfring <elfring@users.sourceforge.net>
Date: Sun, 15 Jan 2017 11:20:13 +0100

Return directly after a call of the function "kzalloc" failed
at the beginning.

Signed-off-by: Markus Elfring <elfring@users.sourceforge.net>
---
 security/selinux/ss/policydb.c | 3 +--
 1 file changed, 1 insertion(+), 2 deletions(-)

diff --git a/security/selinux/ss/policydb.c b/security/selinux/ss/policydb.c
index 551685283399..9b595f2e0d9f 100644
--- a/security/selinux/ss/policydb.c
+++ b/security/selinux/ss/policydb.c
@@ -1116,10 +1116,9 @@ static int perm_read(struct policydb *p, struct hashtab *h, void *fp)
 	__le32 buf[2];
 	u32 len;
 
-	rc = -ENOMEM;
 	perdatum = kzalloc(sizeof(*perdatum), GFP_KERNEL);
 	if (!perdatum)
-		goto bad;
+		return -ENOMEM;
 
 	rc = next_entry(buf, fp, sizeof buf);
 	if (rc)
-- 
2.11.0

[toc] | [prev] | [next] | [standalone]


#1559282 — [PATCH 32/46] selinux: Return directly after a failed kzalloc() in class_read()

FromSF Markus Elfring <elfring@users.sourceforge.net>
Date2017-01-15 16:40 +0100
Subject[PATCH 32/46] selinux: Return directly after a failed kzalloc() in class_read()
Message-ID<sZV4t-4aR-5@gated-at.bofh.it>
In reply to#1559248
From: Markus Elfring <elfring@users.sourceforge.net>
Date: Sat, 14 Jan 2017 22:30:51 +0100

Return directly after a call of the function "kzalloc" failed
at the beginning.

Signed-off-by: Markus Elfring <elfring@users.sourceforge.net>
---
 security/selinux/ss/policydb.c | 3 +--
 1 file changed, 1 insertion(+), 2 deletions(-)

diff --git a/security/selinux/ss/policydb.c b/security/selinux/ss/policydb.c
index 49fc5d8990e9..3af2b0849495 100644
--- a/security/selinux/ss/policydb.c
+++ b/security/selinux/ss/policydb.c
@@ -1316,10 +1316,9 @@ static int class_read(struct policydb *p, struct hashtab *h, void *fp)
 	u32 len, len2, ncons, nel;
 	int i, rc;
 
-	rc = -ENOMEM;
 	cladatum = kzalloc(sizeof(*cladatum), GFP_KERNEL);
 	if (!cladatum)
-		goto bad;
+		return -ENOMEM;
 
 	rc = next_entry(buf, fp, sizeof(u32)*6);
 	if (rc)
-- 
2.11.0

[toc] | [prev] | [next] | [standalone]


#1559283 — [PATCH 39/46] selinux: Move two assignments for the variable "rc" in ocontext_read()

FromSF Markus Elfring <elfring@users.sourceforge.net>
Date2017-01-15 16:40 +0100
Subject[PATCH 39/46] selinux: Move two assignments for the variable "rc" in ocontext_read()
Message-ID<sZV4t-4aR-11@gated-at.bofh.it>
In reply to#1559248
From: Markus Elfring <elfring@users.sourceforge.net>
Date: Sun, 15 Jan 2017 11:30:12 +0100

One local variable was set to an error code in two cases before
a concrete error situation was detected. Thus move the corresponding
assignments into if branches to indicate a software failure there.

Signed-off-by: Markus Elfring <elfring@users.sourceforge.net>
---
 security/selinux/ss/policydb.c | 13 +++++++------
 1 file changed, 7 insertions(+), 6 deletions(-)

diff --git a/security/selinux/ss/policydb.c b/security/selinux/ss/policydb.c
index 88730b372277..8b9ed3f1b132 100644
--- a/security/selinux/ss/policydb.c
+++ b/security/selinux/ss/policydb.c
@@ -2121,10 +2121,11 @@ static int ocontext_read(struct policydb *p, struct policydb_compat_info *info,
 
 		l = NULL;
 		for (j = 0; j < nel; j++) {
-			rc = -ENOMEM;
 			c = kzalloc(sizeof(*c), GFP_KERNEL);
-			if (!c)
+			if (!c) {
+				rc = -ENOMEM;
 				goto out;
+			}
 			if (l)
 				l->next = c;
 			else
@@ -2186,13 +2187,13 @@ static int ocontext_read(struct policydb *p, struct policydb_compat_info *info,
 				if (rc)
 					goto out;
 
-				rc = -EINVAL;
 				c->v.behavior = le32_to_cpu(buf[0]);
 				/* Determined at runtime, not in policy DB. */
-				if (c->v.behavior == SECURITY_FS_USE_MNTPOINT)
-					goto out;
-				if (c->v.behavior > SECURITY_FS_USE_MAX)
+				if (c->v.behavior == SECURITY_FS_USE_MNTPOINT ||
+				    c->v.behavior > SECURITY_FS_USE_MAX) {
+					rc = -EINVAL;
 					goto out;
+				}
 
 				len = le32_to_cpu(buf[1]);
 				rc = str_read(&c->u.name, GFP_KERNEL, fp, len);
-- 
2.11.0

[toc] | [prev] | [next] | [standalone]


#1559284 — [PATCH 33/46] selinux: Move an assignment for the variable "rc" in class_read()

FromSF Markus Elfring <elfring@users.sourceforge.net>
Date2017-01-15 16:40 +0100
Subject[PATCH 33/46] selinux: Move an assignment for the variable "rc" in class_read()
Message-ID<sZV4u-4aR-17@gated-at.bofh.it>
In reply to#1559248
From: Markus Elfring <elfring@users.sourceforge.net>
Date: Sun, 15 Jan 2017 11:10:39 +0100

A local variable was set to an error code in one case before a concrete
error situation was detected. Thus move the corresponding assignment into
an if branch to indicate a software failure there.

Signed-off-by: Markus Elfring <elfring@users.sourceforge.net>
---
 security/selinux/ss/policydb.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/security/selinux/ss/policydb.c b/security/selinux/ss/policydb.c
index 3af2b0849495..9035e5329ceb 100644
--- a/security/selinux/ss/policydb.c
+++ b/security/selinux/ss/policydb.c
@@ -1345,10 +1345,10 @@ static int class_read(struct policydb *p, struct hashtab *h, void *fp)
 		if (rc)
 			goto bad;
 
-		rc = -EINVAL;
 		cladatum->comdatum = hashtab_search(p->p_commons.table, cladatum->comkey);
 		if (!cladatum->comdatum) {
 			printk(KERN_ERR "SELinux:  unknown common %s\n", cladatum->comkey);
+			rc = -EINVAL;
 			goto bad;
 		}
 	}
-- 
2.11.0

[toc] | [prev] | [next] | [standalone]


#1559285 — [PATCH 37/46] selinux: Move an assignment for the variable "rc" in policydb_load_isids()

FromSF Markus Elfring <elfring@users.sourceforge.net>
Date2017-01-15 16:40 +0100
Subject[PATCH 37/46] selinux: Move an assignment for the variable "rc" in policydb_load_isids()
Message-ID<sZV4u-4aR-19@gated-at.bofh.it>
In reply to#1559248
From: Markus Elfring <elfring@users.sourceforge.net>
Date: Sun, 15 Jan 2017 11:24:51 +0100

A local variable was set to an error code in one case before a concrete
error situation was detected. Thus move the corresponding assignment into
an if branch to indicate a software failure there.

Signed-off-by: Markus Elfring <elfring@users.sourceforge.net>
---
 security/selinux/ss/policydb.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/security/selinux/ss/policydb.c b/security/selinux/ss/policydb.c
index 7cf635c650dc..faa6ecc2450d 100644
--- a/security/selinux/ss/policydb.c
+++ b/security/selinux/ss/policydb.c
@@ -897,10 +897,10 @@ int policydb_load_isids(struct policydb *p, struct sidtab *s)
 
 	head = p->ocontexts[OCON_ISID];
 	for (c = head; c; c = c->next) {
-		rc = -EINVAL;
 		if (!c->context[0].user) {
 			printk(KERN_ERR "SELinux:  SID %s was never defined.\n",
 				c->u.name);
+			rc = -EINVAL;
 			goto out;
 		}
 
-- 
2.11.0

[toc] | [prev] | [next] | [standalone]


#1559286 — [PATCH 38/46] selinux: One function call less in five functions after null pointer detection

FromSF Markus Elfring <elfring@users.sourceforge.net>
Date2017-01-15 16:40 +0100
Subject[PATCH 38/46] selinux: One function call less in five functions after null pointer detection
Message-ID<sZV4u-4aR-15@gated-at.bofh.it>
In reply to#1559248
From: Markus Elfring <elfring@users.sourceforge.net>
Date: Sun, 15 Jan 2017 11:28:02 +0100

Call the function "kfree" at the end only after it was determined
that the passed parameter contained a non-null pointer.

Signed-off-by: Markus Elfring <elfring@users.sourceforge.net>
---
 security/selinux/ss/policydb.c | 10 +++++-----
 1 file changed, 5 insertions(+), 5 deletions(-)

diff --git a/security/selinux/ss/policydb.c b/security/selinux/ss/policydb.c
index faa6ecc2450d..88730b372277 100644
--- a/security/selinux/ss/policydb.c
+++ b/security/selinux/ss/policydb.c
@@ -620,8 +620,8 @@ static int common_destroy(void *key, void *datum, void *p)
 		comdatum = datum;
 		hashtab_map(comdatum->permissions.table, perm_destroy, NULL);
 		hashtab_destroy(comdatum->permissions.table);
+		kfree(datum);
 	}
-	kfree(datum);
 	return 0;
 }
 
@@ -675,8 +675,8 @@ static int cls_destroy(void *key, void *datum, void *p)
 			kfree(ctemp);
 		}
 		kfree(cladatum->comkey);
+		kfree(datum);
 	}
-	kfree(datum);
 	return 0;
 }
 
@@ -689,8 +689,8 @@ static int role_destroy(void *key, void *datum, void *p)
 		role = datum;
 		ebitmap_destroy(&role->dominates);
 		ebitmap_destroy(&role->types);
+		kfree(datum);
 	}
-	kfree(datum);
 	return 0;
 }
 
@@ -712,8 +712,8 @@ static int user_destroy(void *key, void *datum, void *p)
 		ebitmap_destroy(&usrdatum->range.level[0].cat);
 		ebitmap_destroy(&usrdatum->range.level[1].cat);
 		ebitmap_destroy(&usrdatum->dfltlevel.cat);
+		kfree(datum);
 	}
-	kfree(datum);
 	return 0;
 }
 
@@ -726,8 +726,8 @@ static int sens_destroy(void *key, void *datum, void *p)
 		levdatum = datum;
 		ebitmap_destroy(&levdatum->level->cat);
 		kfree(levdatum->level);
+		kfree(datum);
 	}
-	kfree(datum);
 	return 0;
 }
 
-- 
2.11.0

[toc] | [prev] | [next] | [standalone]


#1559287 — [PATCH 30/46] selinux: Return directly after a failed kzalloc() in role_read()

FromSF Markus Elfring <elfring@users.sourceforge.net>
Date2017-01-15 16:40 +0100
Subject[PATCH 30/46] selinux: Return directly after a failed kzalloc() in role_read()
Message-ID<sZV4u-4aR-23@gated-at.bofh.it>
In reply to#1559248
From: Markus Elfring <elfring@users.sourceforge.net>
Date: Sat, 14 Jan 2017 22:20:25 +0100

Return directly after a call of the function "kzalloc" failed
at the beginning.

Signed-off-by: Markus Elfring <elfring@users.sourceforge.net>
---
 security/selinux/ss/policydb.c | 3 +--
 1 file changed, 1 insertion(+), 2 deletions(-)

diff --git a/security/selinux/ss/policydb.c b/security/selinux/ss/policydb.c
index 662139365449..34b670227c4d 100644
--- a/security/selinux/ss/policydb.c
+++ b/security/selinux/ss/policydb.c
@@ -1410,10 +1410,9 @@ static int role_read(struct policydb *p, struct hashtab *h, void *fp)
 	__le32 buf[3];
 	u32 len;
 
-	rc = -ENOMEM;
 	role = kzalloc(sizeof(*role), GFP_KERNEL);
 	if (!role)
-		goto bad;
+		return -ENOMEM;
 
 	if (p->policyvers >= POLICYDB_VERSION_BOUNDARY)
 		to_read = 3;
-- 
2.11.0

[toc] | [prev] | [next] | [standalone]


#1559288 — [PATCH 31/46] selinux: Move an assignment for the variable "rc" in role_read()

FromSF Markus Elfring <elfring@users.sourceforge.net>
Date2017-01-15 16:40 +0100
Subject[PATCH 31/46] selinux: Move an assignment for the variable "rc" in role_read()
Message-ID<sZV4u-4aR-31@gated-at.bofh.it>
In reply to#1559248
From: Markus Elfring <elfring@users.sourceforge.net>
Date: Sat, 14 Jan 2017 22:25:20 +0100

A local variable was set to an error code in one case before a concrete
error situation was detected. Thus move the corresponding assignment into
an if branch to indicate a software failure there.

Signed-off-by: Markus Elfring <elfring@users.sourceforge.net>
---
 security/selinux/ss/policydb.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/security/selinux/ss/policydb.c b/security/selinux/ss/policydb.c
index 34b670227c4d..49fc5d8990e9 100644
--- a/security/selinux/ss/policydb.c
+++ b/security/selinux/ss/policydb.c
@@ -1439,10 +1439,10 @@ static int role_read(struct policydb *p, struct hashtab *h, void *fp)
 		goto bad;
 
 	if (strcmp(key, OBJECT_R) == 0) {
-		rc = -EINVAL;
 		if (role->value != OBJECT_R_VAL) {
 			printk(KERN_ERR "SELinux: Role %s has wrong value %d\n",
 			       OBJECT_R, role->value);
+			rc = -EINVAL;
 			goto bad;
 		}
 		rc = 0;
-- 
2.11.0

[toc] | [prev] | [next] | [standalone]


#1559289 — [PATCH 36/46] selinux: Move an assignment for the variable "rc" in mls_read_range_helper()

FromSF Markus Elfring <elfring@users.sourceforge.net>
Date2017-01-15 16:40 +0100
Subject[PATCH 36/46] selinux: Move an assignment for the variable "rc" in mls_read_range_helper()
Message-ID<sZV4u-4aR-21@gated-at.bofh.it>
In reply to#1559248
From: Markus Elfring <elfring@users.sourceforge.net>
Date: Sun, 15 Jan 2017 11:22:23 +0100

A local variable was set to an error code in one case before a concrete
error situation was detected. Thus move the corresponding assignment into
an if branch to indicate a software failure there.

Signed-off-by: Markus Elfring <elfring@users.sourceforge.net>
---
 security/selinux/ss/policydb.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/security/selinux/ss/policydb.c b/security/selinux/ss/policydb.c
index 9b595f2e0d9f..7cf635c650dc 100644
--- a/security/selinux/ss/policydb.c
+++ b/security/selinux/ss/policydb.c
@@ -996,10 +996,10 @@ static int mls_read_range_helper(struct mls_range *r, void *fp)
 	if (rc)
 		goto out;
 
-	rc = -EINVAL;
 	items = le32_to_cpu(buf[0]);
 	if (items > ARRAY_SIZE(buf)) {
 		printk(KERN_ERR "SELinux: mls:  range overflow\n");
+		rc = -EINVAL;
 		goto out;
 	}
 
-- 
2.11.0

[toc] | [prev] | [next] | [standalone]


#1559290 — [PATCH 34/46] selinux: Return directly after a failed kzalloc() in common_read()

FromSF Markus Elfring <elfring@users.sourceforge.net>
Date2017-01-15 16:40 +0100
Subject[PATCH 34/46] selinux: Return directly after a failed kzalloc() in common_read()
Message-ID<sZV4u-4aR-25@gated-at.bofh.it>
In reply to#1559248
From: Markus Elfring <elfring@users.sourceforge.net>
Date: Sun, 15 Jan 2017 11:15:19 +0100

Return directly after a call of the function "kzalloc" failed
at the beginning.

Signed-off-by: Markus Elfring <elfring@users.sourceforge.net>
---
 security/selinux/ss/policydb.c | 3 +--
 1 file changed, 1 insertion(+), 2 deletions(-)

diff --git a/security/selinux/ss/policydb.c b/security/selinux/ss/policydb.c
index 9035e5329ceb..551685283399 100644
--- a/security/selinux/ss/policydb.c
+++ b/security/selinux/ss/policydb.c
@@ -1150,10 +1150,9 @@ static int common_read(struct policydb *p, struct hashtab *h, void *fp)
 	u32 len, nel;
 	int i, rc;
 
-	rc = -ENOMEM;
 	comdatum = kzalloc(sizeof(*comdatum), GFP_KERNEL);
 	if (!comdatum)
-		goto bad;
+		return -ENOMEM;
 
 	rc = next_entry(buf, fp, sizeof buf);
 	if (rc)
-- 
2.11.0

[toc] | [prev] | [next] | [standalone]


Page 2 of 3 — ← Prev page 1 [2] 3  Next page →

Back to top | Article view | linux.kernel


csiph-web