From: Krzysztof Struczynski Date: Mon, 27 Apr 2020 10:28:58 +0000 (+0200) Subject: ima: Remove redundant policy rule set in add_rules() X-Git-Tag: v5.8-rc1~119^2~6 X-Git-Url: http://git.ipfire.org/?a=commitdiff_plain;h=6ee28442a465ab4c4be45e3b15015af24b1ba906;p=thirdparty%2Fkernel%2Flinux.git ima: Remove redundant policy rule set in add_rules() Function ima_appraise_flag() returns the flag to be set in temp_ima_appraise depending on the hook identifier passed as an argument. It is not necessary to set the flag again for the POLICY_CHECK hook. Signed-off-by: Krzysztof Struczynski Signed-off-by: Mimi Zohar --- diff --git a/security/integrity/ima/ima_policy.c b/security/integrity/ima/ima_policy.c index c334e0dc60831..ea9b991f02321 100644 --- a/security/integrity/ima/ima_policy.c +++ b/security/integrity/ima/ima_policy.c @@ -643,11 +643,8 @@ static void add_rules(struct ima_rule_entry *entries, int count, list_add_tail(&entry->list, &ima_policy_rules); } - if (entries[i].action == APPRAISE) { + if (entries[i].action == APPRAISE) temp_ima_appraise |= ima_appraise_flag(entries[i].func); - if (entries[i].func == POLICY_CHECK) - temp_ima_appraise |= IMA_APPRAISE_POLICY; - } } }