[PATCH 03/12] sev-dev: use prepare credential guard

From: Christian Brauner
Date: Mon Nov 03 2025 - 10:08:49 EST


Use the prepare credential guard for allocating a new set of
credentials.

Signed-off-by: Christian Brauner <brauner@xxxxxxxxxx>
---
drivers/crypto/ccp/sev-dev.c | 5 +++--
1 file changed, 3 insertions(+), 2 deletions(-)

diff --git a/drivers/crypto/ccp/sev-dev.c b/drivers/crypto/ccp/sev-dev.c
index c5e22af04abb..09e4c9490d58 100644
--- a/drivers/crypto/ccp/sev-dev.c
+++ b/drivers/crypto/ccp/sev-dev.c
@@ -268,15 +268,16 @@ static struct file *open_file_as_root(const char *filename, int flags, umode_t m
get_fs_root(init_task.fs, &root);
task_unlock(&init_task);

- cred = prepare_creds();
+ CLASS(prepare_creds, cred)();
if (!cred)
return ERR_PTR(-ENOMEM);
+
cred->fsuid = GLOBAL_ROOT_UID;
old_cred = override_creds(cred);

fp = file_open_root(&root, filename, flags, mode);

- put_cred(revert_creds(old_cred));
+ revert_creds(old_cred);

return fp;
}

--
2.47.3