]> git.ipfire.org Git - thirdparty/linux.git/commitdiff
selinux: update comment on selinux_hooks[]
authorXiu Jianfeng <xiujianfeng@huawei.com>
Fri, 4 Aug 2023 03:46:52 +0000 (03:46 +0000)
committerPaul Moore <paul@paul-moore.com>
Tue, 8 Aug 2023 17:28:42 +0000 (13:28 -0400)
After commit f22f9aaf6c3d ("selinux: remove the runtime disable
functionality"), the comment on selinux_hooks[] is out-of-date,
remove the last paragraph about runtime disable functionality.

Signed-off-by: Xiu Jianfeng <xiujianfeng@huawei.com>
Signed-off-by: Paul Moore <paul@paul-moore.com>
security/selinux/hooks.c

index 7cd687284563e24eaca338240df6ea65ac96726e..cf787eaca7558819921afa6cad63c56d41cc6fef 100644 (file)
@@ -6963,10 +6963,6 @@ static int selinux_uring_cmd(struct io_uring_cmd *ioucmd)
  *    hooks ("allocating" hooks).
  *
  * Please follow block comment delimiters in the list to keep this order.
- *
- * This ordering is needed for SELinux runtime disable to work at least somewhat
- * safely. Breaking the ordering rules above might lead to NULL pointer derefs
- * when disabling SELinux at runtime.
  */
 static struct security_hook_list selinux_hooks[] __ro_after_init = {
        LSM_HOOK_INIT(binder_set_context_mgr, selinux_binder_set_context_mgr),