diff options
| author | Mickaël Salaün <mic@digikod.net> | 2026-09-07 12:36:08 +0200 |
|---|---|---|
| committer | Mickaël Salaün <mic@digikod.net> | 2026-09-08 11:49:32 +0200 |
| commit | d3df7ed4683f8c1b35672a40bf20af6a08ef8ca9 (patch) | |
| tree | 450ef3879d970a84ef7c7d3c0c06536f0b28fda7 /tools/lib/python/kdoc/python_version.py | |
| parent | e7557b9ef7a87570cbd0873a163de05bde80c39b (diff) | |
landlock: Clean up ruleset validation checks
landlock_merge_ruleset() checks for a NULL ruleset after dereferencing
it in lockdep_assert_held(). Move the assertion after the check so the
defensive path remains effective.
The mask-validation comment originated in landlock_add_fs_access_mask()
to explain that its WARN_ON_ONCE() checked a caller invariant. It
became self-referential when this helper and its network and scope
counterparts were inlined into landlock_create_ruleset(). Restate the
invariant without naming the caller.
Keep both as defensive callee checks. Moving the assertion preserves
the NULL check's ability to warn and return -EINVAL, while invalid masks
remain warned about and masked.
Reported-by: Günther Noack <gnoack@google.com>
Closes: https://patch.msgid.link/aobYhIt3vcs2xN0b@google.com
Closes: https://patch.msgid.link/aobasxUDQ8b7GYXl@google.com
Reviewed-by: Günther Noack <gnoack@google.com>
Link: https://patch.msgid.link/20260907103609.113325-1-mic@digikod.net
Signed-off-by: Mickaël Salaün <mic@digikod.net>
Diffstat (limited to 'tools/lib/python/kdoc/python_version.py')
0 files changed, 0 insertions, 0 deletions
