diff options
author | Paul Moore <paul@paul-moore.com> | 2016-04-18 22:41:38 +0200 |
---|---|---|
committer | Paul Moore <paul@paul-moore.com> | 2016-04-19 22:37:27 +0200 |
commit | 1ac42476263eec99fb2d3c31ee946cb44e80ddd5 (patch) | |
tree | d69cdac4dc64a6333de68d51b9697f273fb8c45c /security | |
parent | selinux: delay inode label lookup as long as possible (diff) | |
download | linux-1ac42476263eec99fb2d3c31ee946cb44e80ddd5.tar.xz linux-1ac42476263eec99fb2d3c31ee946cb44e80ddd5.zip |
selinux: check ss_initialized before revalidating an inode label
There is no point in trying to revalidate an inode's security label if
the security server is not yet initialized.
Signed-off-by: Paul Moore <paul@paul-moore.com>
Diffstat (limited to 'security')
-rw-r--r-- | security/selinux/hooks.c | 2 |
1 files changed, 1 insertions, 1 deletions
diff --git a/security/selinux/hooks.c b/security/selinux/hooks.c index b09aad7ad423..474011c46bbd 100644 --- a/security/selinux/hooks.c +++ b/security/selinux/hooks.c @@ -259,7 +259,7 @@ static int __inode_security_revalidate(struct inode *inode, might_sleep_if(may_sleep); - if (isec->initialized != LABEL_INITIALIZED) { + if (ss_initialized && isec->initialized != LABEL_INITIALIZED) { if (!may_sleep) return -ECHILD; |