aboutsummaryrefslogtreecommitdiffstats
path: root/security/integrity/evm/evm_main.c
diff options
context:
space:
mode:
authorJames Morris <james.l.morris@oracle.com>2014-10-29 15:03:54 +1100
committerJames Morris <james.l.morris@oracle.com>2014-10-29 15:03:54 +1100
commit6c880ad51b829006c5387df88967954c0e874993 (patch)
tree3a164ed2e33c874be7dbe4783037985996ac9efc /security/integrity/evm/evm_main.c
parentMerge branch 'for-3.18' of git://linux-nfs.org/~bfields/linux (diff)
parentevm: check xattr value length and type in evm_inode_setxattr() (diff)
downloadlinux-dev-6c880ad51b829006c5387df88967954c0e874993.tar.xz
linux-dev-6c880ad51b829006c5387df88967954c0e874993.zip
Merge branch 'for-linus' of git://git.kernel.org/pub/scm/linux/kernel/git/zohar/linux-integrity into for-linus
Diffstat (limited to 'security/integrity/evm/evm_main.c')
-rw-r--r--security/integrity/evm/evm_main.c9
1 files changed, 6 insertions, 3 deletions
diff --git a/security/integrity/evm/evm_main.c b/security/integrity/evm/evm_main.c
index 9685af330de5..c5ee1a7c5e8a 100644
--- a/security/integrity/evm/evm_main.c
+++ b/security/integrity/evm/evm_main.c
@@ -319,9 +319,12 @@ int evm_inode_setxattr(struct dentry *dentry, const char *xattr_name,
{
const struct evm_ima_xattr_data *xattr_data = xattr_value;
- if ((strcmp(xattr_name, XATTR_NAME_EVM) == 0)
- && (xattr_data->type == EVM_XATTR_HMAC))
- return -EPERM;
+ if (strcmp(xattr_name, XATTR_NAME_EVM) == 0) {
+ if (!xattr_value_len)
+ return -EINVAL;
+ if (xattr_data->type != EVM_IMA_XATTR_DIGSIG)
+ return -EPERM;
+ }
return evm_protect_xattr(dentry, xattr_name, xattr_value,
xattr_value_len);
}