if (tomoyo_last_pid != pid) {
pr_warn("ERROR: Out of memory at %s.\n", function);
tomoyo_last_pid = pid;
} if (!tomoyo_policy_loaded)
panic("MAC Initialization failed.\n");
}
/* Memoy currently used by policy/audit log/query. */ unsignedint tomoyo_memory_used[TOMOYO_MAX_MEMORY_STAT]; /* Memory quota for "policy"/"audit log"/"query". */ unsignedint tomoyo_memory_quota[TOMOYO_MAX_MEMORY_STAT];
/** * tomoyo_memory_ok - Check memory quota. * * @ptr: Pointer to allocated memory. * * Returns true on success, false otherwise. * * Returns true if @ptr is not NULL and quota not exceeded, false otherwise. * * Caller holds tomoyo_policy_lock mutex.
*/ bool tomoyo_memory_ok(void *ptr)
{ if (ptr) { const size_t s = ksize(ptr);
/** * tomoyo_get_group - Allocate memory for "struct tomoyo_path_group"/"struct tomoyo_number_group". * * @param: Pointer to "struct tomoyo_acl_param". * @idx: Index number. * * Returns pointer to "struct tomoyo_group" on success, NULL otherwise.
*/ struct tomoyo_group *tomoyo_get_group(struct tomoyo_acl_param *param, const u8 idx)
{ struct tomoyo_group e = { }; struct tomoyo_group *group = NULL; struct list_head *list; constchar *group_name = tomoyo_read_token(param); bool found = false;
if (!tomoyo_correct_word(group_name) || idx >= TOMOYO_MAX_GROUP) return NULL;
e.group_name = tomoyo_get_name(group_name); if (!e.group_name) return NULL; if (mutex_lock_interruptible(&tomoyo_policy_lock)) goto out;
list = ¶m->ns->group_list[idx];
list_for_each_entry(group, list, head.list) { if (e.group_name != group->group_name ||
atomic_read(&group->head.users) == TOMOYO_GC_IN_PROGRESS) continue;
atomic_inc(&group->head.users);
found = true; break;
} if (!found) { struct tomoyo_group *entry = tomoyo_commit_ok(&e, sizeof(e));
if (entry) {
INIT_LIST_HEAD(&entry->member_list);
atomic_set(&entry->head.users, 1);
list_add_tail_rcu(&entry->head.list, list);
group = entry;
found = true;
}
}
mutex_unlock(&tomoyo_policy_lock);
out:
tomoyo_put_name(e.group_name); return found ? group : NULL;
}
/* * tomoyo_name_list is used for holding string data used by TOMOYO. * Since same string data is likely used for multiple times (e.g. * "/lib/libc-2.5.so"), TOMOYO shares string data in the form of * "const struct tomoyo_path_info *".
*/ struct list_head tomoyo_name_list[TOMOYO_MAX_HASH];
/** * tomoyo_get_name - Allocate permanent memory for string data. * * @name: The string to store into the permernent memory. * * Returns pointer to "struct tomoyo_path_info" on success, NULL otherwise.
*/ conststruct tomoyo_path_info *tomoyo_get_name(constchar *name)
{ struct tomoyo_name *ptr; unsignedint hash; int len; struct list_head *head;
Die Informationen auf dieser Webseite wurden
nach bestem Wissen sorgfältig zusammengestellt. Es wird jedoch weder Vollständigkeit, noch Richtigkeit,
noch Qualität der bereit gestellten Informationen zugesichert.
Bemerkung:
Die farbliche Syntaxdarstellung und die Messung sind noch experimentell.