From: Krzysztof Struczynski Date: Mon, 27 Apr 2020 10:28:58 +0000 (+0200) Subject: ima: Remove redundant policy rule set in add_rules() X-Git-Tag: v5.7.5~87 X-Git-Url: https://www.infradead.org/git/?a=commitdiff_plain;h=089d3c9114d8a71ccc1e2fb8b521b8c6de408a30;p=users%2Fdwmw2%2Flinux.git ima: Remove redundant policy rule set in add_rules() [ Upstream commit 6ee28442a465ab4c4be45e3b15015af24b1ba906 ] Function ima_appraise_flag() returns the flag to be set in temp_ima_appraise depending on the hook identifier passed as an argument. It is not necessary to set the flag again for the POLICY_CHECK hook. Signed-off-by: Krzysztof Struczynski Signed-off-by: Mimi Zohar Signed-off-by: Sasha Levin --- diff --git a/security/integrity/ima/ima_policy.c b/security/integrity/ima/ima_policy.c index 1c78cbbd27d88..7414443c19bf1 100644 --- a/security/integrity/ima/ima_policy.c +++ b/security/integrity/ima/ima_policy.c @@ -643,11 +643,8 @@ static void add_rules(struct ima_rule_entry *entries, int count, list_add_tail(&entry->list, &ima_policy_rules); } - if (entries[i].action == APPRAISE) { + if (entries[i].action == APPRAISE) temp_ima_appraise |= ima_appraise_flag(entries[i].func); - if (entries[i].func == POLICY_CHECK) - temp_ima_appraise |= IMA_APPRAISE_POLICY; - } } }