]> git.hungrycats.org Git - linux/commitdiff
[PATCH] SELinux: allow all filesystems to specify fscreate mount option
authorJames Morris <jmorris@redhat.com>
Tue, 19 Oct 2004 01:17:18 +0000 (18:17 -0700)
committerLinus Torvalds <torvalds@ppc970.osdl.org>
Tue, 19 Oct 2004 01:17:18 +0000 (18:17 -0700)
The patch below allows all types of filesystems to specify the fscreate
mount option (which is used to specify the security context of the
filesystem itself).  This was previously only available for filesystems
with full xattr security labeling, but is also potentially required for
filesystems with e.g.  psuedo xattr labeling such as devpts and tmpfs.

An example of use is to specify at mount time the fs security context of a
tmpfs filesystem, overriding the default specified in policy for that
filesystem.

This patch has been in the Fedora kernel for some weeks with no problems.

Signed-off-by: James Morris <jmorris@redhat.com>
Signed-off-by: Stephen Smalley <sds@epoch.ncsc.mil>
Signed-off-by: Andrew Morton <akpm@osdl.org>
Signed-off-by: Linus Torvalds <torvalds@osdl.org>
security/selinux/hooks.c

index bd931774882324639d0ef155b4be2c714847edb4..40b6911892d4c361fc137a6196793dc5e88672ee 100644 (file)
@@ -387,13 +387,6 @@ static int try_context_mount(struct super_block *sb, void *data)
                                break;
 
                        case Opt_fscontext:
-                               if (sbsec->behavior != SECURITY_FS_USE_XATTR) {
-                                       rc = -EINVAL;
-                                       printk(KERN_WARNING "SELinux:  "
-                                              "fscontext option is invalid for"
-                                              " this filesystem type\n");
-                                       goto out_free;
-                               }
                                if (seen & (Opt_context|Opt_fscontext)) {
                                        rc = -EINVAL;
                                        printk(KERN_WARNING SEL_MOUNT_FAIL_MSG);