security: have cap_dentry_init_security return error
authorJeff Layton <jlayton@redhat.com>
Wed, 5 Mar 2014 17:47:37 +0000 (12:47 -0500)
committerJames Morris <james.l.morris@oracle.com>
Fri, 7 Mar 2014 00:50:01 +0000 (11:50 +1100)
Currently, cap_dentry_init_security returns 0 without actually
initializing the security label. This confuses its only caller
(nfs4_label_init_security) which expects an error in that situation, and
causes it to end up sending out junk onto the wire instead of simply
suppressing the label in the attributes sent.

When CONFIG_SECURITY is disabled, security_dentry_init_security returns
-EOPNOTSUPP. Have cap_dentry_init_security do the same.

Signed-off-by: Jeff Layton <jlayton@redhat.com>
Acked-by: Serge E. Hallyn <serge.hallyn@ubuntu.com>
Signed-off-by: James Morris <james.l.morris@oracle.com>
security/capability.c

index 8b4f24ae43381de05af67271edd9a8ddd57c651f..9323bbeba296b28e53667ab5bdb6b3c9508aa5d2 100644 (file)
@@ -116,7 +116,7 @@ static int cap_dentry_init_security(struct dentry *dentry, int mode,
                                        struct qstr *name, void **ctx,
                                        u32 *ctxlen)
 {
-       return 0;
+       return -EOPNOTSUPP;
 }
 
 static int cap_inode_alloc_security(struct inode *inode)