]> git.itanic.dy.fi Git - linux-stable/commitdiff
ima: Remove ima_policy file before directory
authorStefan Berger <stefanb@linux.ibm.com>
Tue, 25 Jan 2022 22:46:23 +0000 (17:46 -0500)
committerGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Wed, 16 Feb 2022 11:44:48 +0000 (12:44 +0100)
commit f7333b9572d0559e00352a926c92f29f061b4569 upstream.

The removal of ima_dir currently fails since ima_policy still exists, so
remove the ima_policy file before removing the directory.

Fixes: 4af4662fa4a9 ("integrity: IMA policy")
Signed-off-by: Stefan Berger <stefanb@linux.ibm.com>
Cc: <stable@vger.kernel.org>
Acked-by: Christian Brauner <brauner@kernel.org>
Signed-off-by: Mimi Zohar <zohar@linux.ibm.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
security/integrity/ima/ima_fs.c

index d37f9ac46670dd287b011cdfd42c9a76d823d5c5..5306e6ae795080be4e219ff14e540382b0eaa1ff 100644 (file)
@@ -486,11 +486,11 @@ int __init ima_fs_init(void)
 
        return 0;
 out:
+       securityfs_remove(ima_policy);
        securityfs_remove(violations);
        securityfs_remove(runtime_measurements_count);
        securityfs_remove(ascii_runtime_measurements);
        securityfs_remove(binary_runtime_measurements);
        securityfs_remove(ima_dir);
-       securityfs_remove(ima_policy);
        return -1;
 }