From patchwork Thu Aug 11 05:02:46 2011 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Subject: [12/13] AppArmor: Remove "permipc" command Date: Wed, 10 Aug 2011 19:02:46 -0000 From: John Johansen X-Patchwork-Id: 109529 Message-Id: <1313038967-19941-13-git-send-email-john.johansen@canonical.com> To: kernel-team@lists.ubuntu.com The "permipc" command is unused and unfinished, remove it. Signed-off-by: John Johansen --- security/apparmor/include/procattr.h | 1 - security/apparmor/lsm.c | 2 -- security/apparmor/procattr.c | 6 ------ 3 files changed, 0 insertions(+), 9 deletions(-) diff --git a/security/apparmor/include/procattr.h b/security/apparmor/include/procattr.h index 544aa6b..6bd5f33 100644 --- a/security/apparmor/include/procattr.h +++ b/security/apparmor/include/procattr.h @@ -21,6 +21,5 @@ int aa_getprocattr(struct aa_profile *profile, char **string); int aa_setprocattr_changehat(char *args, size_t size, int test); int aa_setprocattr_changeprofile(char *fqname, bool onexec, int test); -int aa_setprocattr_permipc(char *fqname); #endif /* __AA_PROCATTR_H */ diff --git a/security/apparmor/lsm.c b/security/apparmor/lsm.c index 7459547..93dea4d 100644 --- a/security/apparmor/lsm.c +++ b/security/apparmor/lsm.c @@ -586,8 +586,6 @@ static int apparmor_setprocattr(struct task_struct *task, char *name, } else if (strcmp(command, "permprofile") == 0) { error = aa_setprocattr_changeprofile(args, !AA_ONEXEC, AA_DO_TEST); - } else if (strcmp(command, "permipc") == 0) { - error = aa_setprocattr_permipc(args); } else { struct common_audit_data sa; COMMON_AUDIT_DATA_INIT(&sa, NONE); diff --git a/security/apparmor/procattr.c b/security/apparmor/procattr.c index 04a2cf8..344970a 100644 --- a/security/apparmor/procattr.c +++ b/security/apparmor/procattr.c @@ -162,9 +162,3 @@ int aa_setprocattr_changeprofile(char *fqname, bool onexec, int test) name = aa_split_fqname(fqname, &ns_name); return aa_change_profile(ns_name, name, onexec, test); } - -int aa_setprocattr_permipc(char *fqname) -{ - /* TODO: add ipc permission querying */ - return -ENOTSUPP; -}