diff options
| -rw-r--r-- | security/apparmor/file.c | 2 | ||||
| -rw-r--r-- | security/apparmor/include/file.h | 2 | ||||
| -rw-r--r-- | security/apparmor/include/match.h | 2 | ||||
| -rw-r--r-- | security/apparmor/include/perms.h | 4 | ||||
| -rw-r--r-- | security/apparmor/lib.c | 15 | ||||
| -rw-r--r-- | security/apparmor/lsm.c | 8 | ||||
| -rw-r--r-- | security/apparmor/match.c | 6 | ||||
| -rw-r--r-- | security/apparmor/mount.c | 3 |
8 files changed, 22 insertions, 20 deletions
diff --git a/security/apparmor/file.c b/security/apparmor/file.c index e67ca65b7bd9..d5264af92f07 100644 --- a/security/apparmor/file.c +++ b/security/apparmor/file.c @@ -93,7 +93,7 @@ static void file_audit_cb(struct audit_buffer *ab, void *va) * Returns: %0 or error on failure */ int aa_audit_file(const struct cred *subj_cred, - struct aa_profile *profile, struct aa_perms *perms, + struct aa_profile *profile, const struct aa_perms *perms, const char *op, u32 request, const char *name, const char *target, struct aa_label *tlabel, kuid_t ouid, const char *info, int error) diff --git a/security/apparmor/include/file.h b/security/apparmor/include/file.h index ef60f99bc5ae..1614c07fc53e 100644 --- a/security/apparmor/include/file.h +++ b/security/apparmor/include/file.h @@ -72,7 +72,7 @@ struct path_cond { #define COMBINED_PERM_MASK(X) ((X).allow | (X).audit | (X).quiet | (X).kill) int aa_audit_file(const struct cred *cred, - struct aa_profile *profile, struct aa_perms *perms, + struct aa_profile *profile, const struct aa_perms *perms, const char *op, u32 request, const char *name, const char *target, struct aa_label *tlabel, kuid_t ouid, const char *info, int error); diff --git a/security/apparmor/include/match.h b/security/apparmor/include/match.h index 7accb1c39849..094f6b998ea8 100644 --- a/security/apparmor/include/match.h +++ b/security/apparmor/include/match.h @@ -125,7 +125,7 @@ static inline size_t table_size(size_t len, size_t el_size) #define aa_state_t unsigned int -struct aa_dfa *aa_dfa_unpack(void *blob, size_t size, int flags); +struct aa_dfa *aa_dfa_unpack(const void *blob, size_t size, int flags); aa_state_t aa_dfa_match_len(struct aa_dfa *dfa, aa_state_t start, const char *str, int len); aa_state_t aa_dfa_match(struct aa_dfa *dfa, aa_state_t start, diff --git a/security/apparmor/include/perms.h b/security/apparmor/include/perms.h index 37a3781b99a0..bbab28ed7abb 100644 --- a/security/apparmor/include/perms.h +++ b/security/apparmor/include/perms.h @@ -96,8 +96,8 @@ struct aa_perms { #define AA_INDEX_NONE 0 #define ALL_PERMS_MASK 0xffffffff -extern struct aa_perms nullperms; -extern struct aa_perms allperms; +extern const struct aa_perms nullperms; +extern const struct aa_perms allperms; /** * aa_perms_accum_raw - accumulate perms with out masking off overlapping perms diff --git a/security/apparmor/lib.c b/security/apparmor/lib.c index e41ff57798b2..39f824c65d88 100644 --- a/security/apparmor/lib.c +++ b/security/apparmor/lib.c @@ -20,8 +20,8 @@ #include "include/perms.h" #include "include/policy.h" -struct aa_perms nullperms; -struct aa_perms allperms = { .allow = ALL_PERMS_MASK, +const struct aa_perms nullperms; +const struct aa_perms allperms = { .allow = ALL_PERMS_MASK, .quiet = ALL_PERMS_MASK, .hide = ALL_PERMS_MASK }; @@ -30,7 +30,7 @@ struct val_table_ent { int value; }; -static struct val_table_ent debug_values_table[] = { +static const struct val_table_ent debug_values_table[] = { { "N", DEBUG_NONE }, { "none", DEBUG_NONE }, { "n", DEBUG_NONE }, @@ -49,10 +49,11 @@ static struct val_table_ent debug_values_table[] = { { NULL, 0 } }; -static struct val_table_ent *val_table_find_ent(struct val_table_ent *table, - const char *name, size_t len) +static const struct val_table_ent * +val_table_find_ent(const struct val_table_ent *table, + const char *name, size_t len) { - struct val_table_ent *entry; + const struct val_table_ent *entry; for (entry = table; entry->str != NULL; entry++) { if (strncmp(entry->str, name, len) == 0 && @@ -64,7 +65,7 @@ static struct val_table_ent *val_table_find_ent(struct val_table_ent *table, int aa_parse_debug_params(const char *str) { - struct val_table_ent *ent; + const struct val_table_ent *ent; const char *next; int val = 0; diff --git a/security/apparmor/lsm.c b/security/apparmor/lsm.c index 5e21dd78d608..d502ad0ac26f 100644 --- a/security/apparmor/lsm.c +++ b/security/apparmor/lsm.c @@ -2500,16 +2500,16 @@ static int __init apparmor_nf_ip_init(void) } #endif -static char nulldfa_src[] __aligned(8) = { +static const char nulldfa_src[] __aligned(8) = { #include "nulldfa.in" }; -static struct aa_dfa *nulldfa; +static struct aa_dfa *nulldfa __ro_after_init; static char stacksplitdfa_src[] __aligned(8) = { #include "stacksplitdfa.in" }; -struct aa_dfa *stacksplitdfa; -struct aa_policydb *nullpdb; +struct aa_dfa *stacksplitdfa __ro_after_init; +struct aa_policydb *nullpdb __ro_after_init; static int __init aa_setup_dfa_engine(void) { diff --git a/security/apparmor/match.c b/security/apparmor/match.c index d43ff34d705c..52668134da9d 100644 --- a/security/apparmor/match.c +++ b/security/apparmor/match.c @@ -31,7 +31,7 @@ * * NOTE: must be freed by kvfree (not kfree) */ -static struct table_header *unpack_table(char *blob, size_t bsize) +static struct table_header *unpack_table(const char *blob, size_t bsize) { struct table_header *table = ERR_PTR(-EPROTO); struct table_header th; @@ -312,11 +312,11 @@ static struct table_header *remap_data16_to_data32(struct table_header *old) * * Returns: an unpacked dfa ready for matching or ERR_PTR on failure */ -struct aa_dfa *aa_dfa_unpack(void *blob, size_t size, int flags) +struct aa_dfa *aa_dfa_unpack(const void *blob, size_t size, int flags) { int hsize; int error = -ENOMEM; - char *data = blob; + const char *data = blob; struct table_header *table = NULL; struct aa_dfa *dfa = kzalloc_obj(struct aa_dfa); if (!dfa) diff --git a/security/apparmor/mount.c b/security/apparmor/mount.c index 2f5d918832c1..8402d29ad524 100644 --- a/security/apparmor/mount.c +++ b/security/apparmor/mount.c @@ -136,7 +136,8 @@ static int audit_mount(const struct cred *subj_cred, const char *name, const char *src_name, const char *type, const char *trans, unsigned long flags, const void *data, u32 request, - struct aa_perms *perms, const char *info, int error) + const struct aa_perms *perms, const char *info, + int error) { int audit_type = AUDIT_APPARMOR_AUTO; DEFINE_AUDIT_DATA(ad, LSM_AUDIT_DATA_NONE, AA_CLASS_MOUNT, op); |
