SELinux: Only store the network interface's ifindex
authorPaul Moore <paul.moore@hp.com>
Tue, 29 Jan 2008 13:38:10 +0000 (08:38 -0500)
committerJames Morris <jmorris@namei.org>
Tue, 29 Jan 2008 21:17:22 +0000 (08:17 +1100)
commitda5645a28a15aed2e541a814ecf9f7ffcd4c4673
tree8cedccebd0e12308de30573ad593d703943e3cbb
parente8bfdb9d0dfc1231a6a71e849dfbd4447acdfff6
SELinux: Only store the network interface's ifindex

Instead of storing the packet's network interface name store the ifindex.  This
allows us to defer the need to lookup the net_device structure until the audit
record is generated meaning that in the majority of cases we never need to
bother with this at all.

Signed-off-by: Paul Moore <paul.moore@hp.com>
Signed-off-by: James Morris <jmorris@namei.org>
security/selinux/avc.c
security/selinux/hooks.c
security/selinux/include/avc.h