SELinux: more user friendly unknown handling printk
I've gotten complaints and reports about people not understanding the meaning of the current unknown class/perm handling the kernel emits on every policy load. Hopefully this will make make it clear to everyone the meaning of the message and won't waste a printk the user won't care about anyway on systems where the kernel and the policy agree on everything. Signed-off-by: Eric Paris <eparis@redhat.com> Signed-off-by: James Morris <jmorris@namei.org>
This commit is contained in:
@ -356,11 +356,6 @@ static ssize_t sel_write_load(struct file *file, const char __user *buf,
|
||||
length = count;
|
||||
|
||||
out1:
|
||||
|
||||
printk(KERN_INFO "SELinux: policy loaded with handle_unknown=%s\n",
|
||||
(security_get_reject_unknown() ? "reject" :
|
||||
(security_get_allow_unknown() ? "allow" : "deny")));
|
||||
|
||||
audit_log(current->audit_context, GFP_KERNEL, AUDIT_MAC_POLICY_LOAD,
|
||||
"policy loaded auid=%u ses=%u",
|
||||
audit_get_loginuid(current),
|
||||
|
Reference in New Issue
Block a user