diff options
author | Lakshmi Ramasubramanian <nramas@linux.microsoft.com> | 2020-09-14 19:31:57 +0200 |
---|---|---|
committer | Paul Moore <paul@paul-moore.com> | 2020-09-15 20:36:28 +0200 |
commit | 8861d0af642c646c8e148ce34c294bdef6f32f6a (patch) | |
tree | d84b9add18050b651baf37d28579b5d5e10f9301 /security/selinux/include/security.h | |
parent | selinux: access policycaps with READ_ONCE/WRITE_ONCE (diff) | |
download | linux-8861d0af642c646c8e148ce34c294bdef6f32f6a.tar.xz linux-8861d0af642c646c8e148ce34c294bdef6f32f6a.zip |
selinux: Add helper functions to get and set checkreqprot
checkreqprot data member in selinux_state struct is accessed directly by
SELinux functions to get and set. This could cause unexpected read or
write access to this data member due to compiler optimizations and/or
compiler's reordering of access to this field.
Add helper functions to get and set checkreqprot data member in
selinux_state struct. These helper functions use READ_ONCE and
WRITE_ONCE macros to ensure atomic read or write of memory for
this data member.
Signed-off-by: Lakshmi Ramasubramanian <nramas@linux.microsoft.com>
Suggested-by: Stephen Smalley <stephen.smalley.work@gmail.com>
Suggested-by: Paul Moore <paul@paul-moore.com>
Acked-by: Stephen Smalley <stephen.smalley.work@gmail.com>
Signed-off-by: Paul Moore <paul@paul-moore.com>
Diffstat (limited to 'security/selinux/include/security.h')
-rw-r--r-- | security/selinux/include/security.h | 10 |
1 files changed, 10 insertions, 0 deletions
diff --git a/security/selinux/include/security.h b/security/selinux/include/security.h index 0ce2ef684ed0..3cc8bab31ea8 100644 --- a/security/selinux/include/security.h +++ b/security/selinux/include/security.h @@ -143,6 +143,16 @@ static inline void enforcing_set(struct selinux_state *state, bool value) } #endif +static inline bool checkreqprot_get(const struct selinux_state *state) +{ + return READ_ONCE(state->checkreqprot); +} + +static inline void checkreqprot_set(struct selinux_state *state, bool value) +{ + WRITE_ONCE(state->checkreqprot, value); +} + #ifdef CONFIG_SECURITY_SELINUX_DISABLE static inline bool selinux_disabled(struct selinux_state *state) { |