diff options
author | David Howells <dhowells@redhat.com> | 2011-03-11 17:57:33 +0000 |
---|---|---|
committer | James Morris <jmorris@namei.org> | 2011-03-17 11:59:49 +1100 |
commit | 4aab1e896a0a9d57420ff2867caa5a369123d8cb (patch) | |
tree | 92212870353a9493c10fb46a0dd9b6ce27230012 /ipc/Makefile | |
parent | 78b7280cce23293f7570ad52c1ffe1485c6d9669 (diff) | |
download | linux-3.10-4aab1e896a0a9d57420ff2867caa5a369123d8cb.tar.gz linux-3.10-4aab1e896a0a9d57420ff2867caa5a369123d8cb.tar.bz2 linux-3.10-4aab1e896a0a9d57420ff2867caa5a369123d8cb.zip |
KEYS: Make request_key() and co. return an error for a negative key
Make request_key() and co. return an error for a negative or rejected key. If
the key was simply negated, then return ENOKEY, otherwise return the error
with which it was rejected.
Without this patch, the following command returns a key number (with the latest
keyutils):
[root@andromeda ~]# keyctl request2 user debug:foo rejected @s
586569904
Trying to print the key merely gets you a permission denied error:
[root@andromeda ~]# keyctl print 586569904
keyctl_read_alloc: Permission denied
Doing another request_key() call does get you the error, as long as it hasn't
expired yet:
[root@andromeda ~]# keyctl request user debug:foo
request_key: Key was rejected by service
Signed-off-by: David Howells <dhowells@redhat.com>
Signed-off-by: James Morris <jmorris@namei.org>
Diffstat (limited to 'ipc/Makefile')
0 files changed, 0 insertions, 0 deletions