From: Andrew Zaborowski Date: Mon, 4 Jan 2021 16:40:48 +0000 (+0100) Subject: keys: Update comment for restrict_link_by_key_or_keyring_chain X-Git-Tag: v5.12-rc1~125^2~6 X-Git-Url: http://git.ipfire.org/?a=commitdiff_plain;h=40d32b59e37346fe89d27f83279ad81cd7dcc4a5;p=thirdparty%2Fkernel%2Flinux.git keys: Update comment for restrict_link_by_key_or_keyring_chain Add the bit of information that makes restrict_link_by_key_or_keyring_chain different from restrict_link_by_key_or_keyring to the inline docs comment. Signed-off-by: Andrew Zaborowski Acked-by: Jarkko Sakkinen Signed-off-by: Jarkko Sakkinen --- diff --git a/crypto/asymmetric_keys/restrict.c b/crypto/asymmetric_keys/restrict.c index 77ebebada29c4..84cefe3b35856 100644 --- a/crypto/asymmetric_keys/restrict.c +++ b/crypto/asymmetric_keys/restrict.c @@ -244,9 +244,10 @@ int restrict_link_by_key_or_keyring(struct key *dest_keyring, * @payload: The payload of the new key. * @trusted: A key or ring of keys that can be used to vouch for the new cert. * - * Check the new certificate only against the key or keys passed in the data - * parameter. If one of those is the signing key and validates the new - * certificate, then mark the new certificate as being ok to link. + * Check the new certificate against the key or keys passed in the data + * parameter and against the keys already linked to the destination keyring. If + * one of those is the signing key and validates the new certificate, then mark + * the new certificate as being ok to link. * * Returns 0 if the new certificate was accepted, -ENOKEY if we * couldn't find a matching parent certificate in the trusted list,