|
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index] [xen stable-4.17] Revert "xen/xsm: Wire up get_dom0_console"
commit 3c7c9225ffa5605bf0603f9dd1666f3f786e2c44
Author: Jan Beulich <jbeulich@xxxxxxxx>
AuthorDate: Tue May 21 13:36:27 2024 +0200
Commit: Jan Beulich <jbeulich@xxxxxxxx>
CommitDate: Tue May 21 13:36:27 2024 +0200
Revert "xen/xsm: Wire up get_dom0_console"
This reverts commit 9cef77400470604e76c6c3aa9f647c40429ff956,
for not being applicable to this branch.
---
tools/flask/policy/modules/dom0.te | 2 +-
xen/xsm/flask/hooks.c | 4 ----
xen/xsm/flask/policy/access_vectors | 2 --
3 files changed, 1 insertion(+), 7 deletions(-)
diff --git a/tools/flask/policy/modules/dom0.te
b/tools/flask/policy/modules/dom0.te
index 16b8c9646d..f1dcff48e2 100644
--- a/tools/flask/policy/modules/dom0.te
+++ b/tools/flask/policy/modules/dom0.te
@@ -16,7 +16,7 @@ allow dom0_t xen_t:xen {
allow dom0_t xen_t:xen2 {
resource_op psr_cmt_op psr_alloc pmu_ctrl get_symbol
get_cpu_levelling_caps get_cpu_featureset livepatch_op
- coverage_op get_dom0_console
+ coverage_op
};
# Allow dom0 to use all XENVER_ subops that have checks.
diff --git a/xen/xsm/flask/hooks.c b/xen/xsm/flask/hooks.c
index 5e88c71b8e..78225f68c1 100644
--- a/xen/xsm/flask/hooks.c
+++ b/xen/xsm/flask/hooks.c
@@ -1558,10 +1558,6 @@ static int cf_check flask_platform_op(uint32_t op)
return avc_has_perm(domain_sid(current->domain), SECINITSID_XEN,
SECCLASS_XEN2, XEN2__GET_SYMBOL, NULL);
- case XENPF_get_dom0_console:
- return avc_has_perm(domain_sid(current->domain), SECINITSID_XEN,
- SECCLASS_XEN2, XEN2__GET_DOM0_CONSOLE, NULL);
-
default:
return avc_unknown_permission("platform_op", op);
}
diff --git a/xen/xsm/flask/policy/access_vectors
b/xen/xsm/flask/policy/access_vectors
index a35e3d4c51..4e6710a63e 100644
--- a/xen/xsm/flask/policy/access_vectors
+++ b/xen/xsm/flask/policy/access_vectors
@@ -99,8 +99,6 @@ class xen2
livepatch_op
# XEN_SYSCTL_coverage_op
coverage_op
-# XENPF_get_dom0_console
- get_dom0_console
}
# Classes domain and domain2 consist of operations that a domain performs on
--
generated by git-patchbot for /home/xen/git/xen.git#stable-4.17
|
![]() |
Lists.xenproject.org is hosted with RackSpace, monitoring our |