static int set_config_lsm_se_context(const char *, const char *, struct lxc_conf *);
static int get_config_lsm_se_context(const char *, char *, int, struct lxc_conf *);
+static int clr_config_lsm_se_context(const char *, struct lxc_conf *);
static int set_config_cgroup(const char *, const char *, struct lxc_conf *);
static int get_config_cgroup(const char *, char *, int, struct lxc_conf *);
{ "lxc.kmsg", set_config_kmsg, get_config_kmsg, clr_config_kmsg, },
{ "lxc.aa_profile", set_config_lsm_aa_profile, get_config_lsm_aa_profile, clr_config_lsm_aa_profile, },
{ "lxc.aa_allow_incomplete", set_config_lsm_aa_incomplete, get_config_lsm_aa_incomplete, clr_config_lsm_aa_incomplete, },
- { "lxc.se_context", set_config_lsm_se_context, get_config_lsm_se_context, NULL },
+ { "lxc.se_context", set_config_lsm_se_context, get_config_lsm_se_context, clr_config_lsm_se_context, },
{ "lxc.cgroup", set_config_cgroup, get_config_cgroup, NULL },
{ "lxc.id_map", set_config_idmaps, get_config_idmaps, NULL },
{ "lxc.loglevel", set_config_loglevel, get_config_loglevel, NULL },
free(c->rootfs.bdev_type);
c->rootfs.bdev_type = NULL;
- } else if (strcmp(key, "lxc.se_context") == 0) {
- free(c->lsm_se_context);
- c->lsm_se_context = NULL;
-
} else if (strcmp(key, "lxc.seccomp") == 0) {
free(c->seccomp);
c->seccomp = NULL;
c->lsm_aa_allow_incomplete = 0;
return 0;
}
+
+static inline int clr_config_lsm_se_context(const char *key, struct lxc_conf *c)
+{
+ free(c->lsm_se_context);
+ c->lsm_se_context = NULL;
+ return 0;
+}