/* we need to impose a limit on the growth of the hash table so check
* this bucket to make sure it is within the specified bounds */
idx = sel_netport_hashfn(port->psec.port);
list_add_rcu(&port->list, &sel_netport_hash[idx].list); if (sel_netport_hash[idx].size == SEL_NETPORT_HASH_BKT_LIMIT) { struct sel_netport *tail;
tail = list_entry(
rcu_dereference_protected(
list_tail_rcu(&sel_netport_hash[idx].list),
lockdep_is_held(&sel_netport_lock)), struct sel_netport, list);
list_del_rcu(&tail->list);
kfree_rcu(tail, rcu);
} else
sel_netport_hash[idx].size++;
}
spin_lock_bh(&sel_netport_lock);
port = sel_netport_find(protocol, pnum); if (port != NULL) {
*sid = port->psec.sid;
spin_unlock_bh(&sel_netport_lock); return0;
}
ret = security_port_sid(protocol, pnum, sid); if (ret != 0) goto out;
/* If this memory allocation fails still return 0. The SID *isvalid,itjustwon'tbeaddedtothecache.
*/ new = kmalloc(sizeof(*new), GFP_ATOMIC); if (new) { new->psec.port = pnum; new->psec.protocol = protocol; new->psec.sid = *sid;
sel_netport_insert(new);
}
out:
spin_unlock_bh(&sel_netport_lock); if (unlikely(ret))
pr_warn("SELinux: failure in %s(), unable to determine network port label\n",
__func__); return ret;
}
Die Informationen auf dieser Webseite wurden
nach bestem Wissen sorgfältig zusammengestellt. Es wird jedoch weder Vollständigkeit, noch Richtigkeit,
noch Qualität der bereit gestellten Informationen zugesichert.
Bemerkung:
Die farbliche Syntaxdarstellung und die Messung sind noch experimentell.