diff options
author | Linus Torvalds <torvalds@linux-foundation.org> | 2020-06-02 17:36:24 -0700 |
---|---|---|
committer | Linus Torvalds <torvalds@linux-foundation.org> | 2020-06-02 17:36:24 -0700 |
commit | d9afbb3509900a953f5cf90bc57e793ee80c1108 (patch) | |
tree | f882d48ad8e0b728f8eeb5502b71e4540c2dc92f | |
parent | f41030a20b38552a2da3b3f6bc9e7a78637d6c23 (diff) | |
parent | 56f2e3b7d819f4fa44857ba81aa6870f18714ea0 (diff) | |
download | linux-d9afbb3509900a953f5cf90bc57e793ee80c1108.tar.bz2 |
Merge branch 'next-general' of git://git.kernel.org/pub/scm/linux/kernel/git/jmorris/linux-security
Pull lockdown update from James Morris:
"An update for the security subsystem to allow unprivileged users
to see the status of the lockdown feature. From Jeremy Cline"
Also an added comment to describe CAP_SETFCAP.
* 'next-general' of git://git.kernel.org/pub/scm/linux/kernel/git/jmorris/linux-security:
capabilities: add description for CAP_SETFCAP
lockdown: Allow unprivileged users to see lockdown status
-rw-r--r-- | include/uapi/linux/capability.h | 2 | ||||
-rw-r--r-- | security/lockdown/lockdown.c | 2 |
2 files changed, 3 insertions, 1 deletions
diff --git a/include/uapi/linux/capability.h b/include/uapi/linux/capability.h index e58c9636741b..c4532b0fe00f 100644 --- a/include/uapi/linux/capability.h +++ b/include/uapi/linux/capability.h @@ -332,6 +332,8 @@ struct vfs_ns_cap_data { #define CAP_AUDIT_CONTROL 30 +/* Set or remove capabilities on files */ + #define CAP_SETFCAP 31 /* Override MAC access. diff --git a/security/lockdown/lockdown.c b/security/lockdown/lockdown.c index 5a952617a0eb..87cbdc64d272 100644 --- a/security/lockdown/lockdown.c +++ b/security/lockdown/lockdown.c @@ -150,7 +150,7 @@ static int __init lockdown_secfs_init(void) { struct dentry *dentry; - dentry = securityfs_create_file("lockdown", 0600, NULL, NULL, + dentry = securityfs_create_file("lockdown", 0644, NULL, NULL, &lockdown_ops); return PTR_ERR_OR_ZERO(dentry); } |