tree 5198162cc55309f8653a0a333c2cbdffc64debad
parent 469ff8f7d46d75b36de68a0411a2ce80109ad00b
author Mat Martineau <mathew.j.martineau@linux.intel.com> 1472581993 -0700
committer Mat Martineau <mathew.j.martineau@linux.intel.com> 1491240296 -0700

KEYS: Split role of the keyring pointer for keyring restrict functions

The first argument to the restrict_link_func_t functions was a keyring
pointer. These functions are called by the key subsystem with this
argument set to the destination keyring, but restrict_link_by_signature
expects a pointer to the relevant trusted keyring.

Restrict functions may need something other than a single struct key
pointer to allow or reject key linkage, so the data used to make that
decision (such as the trust keyring) is moved to a new, fourth
argument. The first argument is now always the destination keyring.

Signed-off-by: Mat Martineau <mathew.j.martineau@linux.intel.com>
