1320 |
invoked only when execve() request was rejected. In other words, |
invoked only when execve() request was rejected. In other words, |
1321 |
this program is invoked only when the following conditions are met. |
this program is invoked only when the following conditions are met. |
1322 |
|
|
1323 |
(1) None of "allow_execute" keywords in the domain didn't match. |
(1) None of "allow_execute" keywords in the domain matched. |
1324 |
(2) The execve() request was rejected in enforcing mode. |
(2) The execve() request was rejected in enforcing mode. |
1325 |
(3) "execute_handler" keyword is not used by the domain. |
(3) "execute_handler" keyword is not used by the domain. |
1326 |
|
|
1353 |
But the original execute request is handled by the same execute handler |
But the original execute request is handled by the same execute handler |
1354 |
unless the execute handler ignores "execute_handler". |
unless the execute handler ignores "execute_handler". |
1355 |
|
|
1356 |
Version 1.6.0 2008/??/?? Feature enhancement release. |
@ Update coding style. |
1357 |
|
|
1358 |
|
I rewrote the code to pass scripts/checkpatch.pl as much as possible. |
1359 |
|
Function names were changed to use only lower letters. |
1360 |
|
|
1361 |
|
Version 1.6.0 2008/04/01 Feature enhancement release. |
1362 |
|
|
1363 |
|
Fix 2008/??/?? |
1364 |
|
|
1365 |
|
@ Fix "Compilation failures" and "Initialization ordering bugs" |
1366 |
|
with kernels before 2.4.30/2.6.11 . |
1367 |
|
|
1368 |
|
2.6 kernels before 2.6.9 didn't have include/linux/hardirq.h , |
1369 |
|
resulting compilation error at #include <linux/hardirq.h> . |
1370 |
|
I added #elif condition. |
1371 |
|
|
1372 |
|
2.6 kernels before 2.6.11 calls do_execve() before initialization of |
1373 |
|
ccs_alloc(), resulting NULL pointer dereference. |
1374 |
|
I changed __initcall to security_initcall. |
1375 |
|
|
1376 |
|
Some distributions with 2.6.9 kernels backported kzalloc() from 2.6.14 , |
1377 |
|
resulting compilation error at kzalloc(). |
1378 |
|
I modified prototype of kzalloc(). |