summaryrefslogtreecommitdiffstats
path: root/security/selinux/include/netnode.h
diff options
context:
space:
mode:
authorPaul Moore2014-06-26 20:33:56 +0200
committerPaul Moore2014-06-26 20:33:56 +0200
commit615e51fdda6f274e94b1e905fcaf6111e0d9aa20 (patch)
treed0ce12f9f5e086c293a7255e3e712d2a42be02b9 /security/selinux/include/netnode.h
parentselinux: no recursive read_lock of policy_rwlock in security_genfs_sid() (diff)
downloadkernel-qcow2-linux-615e51fdda6f274e94b1e905fcaf6111e0d9aa20.tar.gz
kernel-qcow2-linux-615e51fdda6f274e94b1e905fcaf6111e0d9aa20.tar.xz
kernel-qcow2-linux-615e51fdda6f274e94b1e905fcaf6111e0d9aa20.zip
selinux: reduce the number of calls to synchronize_net() when flushing caches
When flushing the AVC, such as during a policy load, the various network caches are also flushed, with each making a call to synchronize_net() which has shown to be expensive in some cases. This patch consolidates the network cache flushes into a single AVC callback which only calls synchronize_net() once for each AVC cache flush. Reported-by: Jaejyn Shin <flagon22bass@gmail.com> Signed-off-by: Paul Moore <pmoore@redhat.com>
Diffstat (limited to 'security/selinux/include/netnode.h')
-rw-r--r--security/selinux/include/netnode.h2
1 files changed, 2 insertions, 0 deletions
diff --git a/security/selinux/include/netnode.h b/security/selinux/include/netnode.h
index df7a5ed6c694..937668dd3024 100644
--- a/security/selinux/include/netnode.h
+++ b/security/selinux/include/netnode.h
@@ -27,6 +27,8 @@
#ifndef _SELINUX_NETNODE_H
#define _SELINUX_NETNODE_H
+void sel_netnode_flush(void);
+
int sel_netnode_sid(void *addr, u16 family, u32 *sid);
#endif