Commit d9afbb35 authored by Linus Torvalds's avatar Linus Torvalds
Browse files
Pull lockdown update from James Morris:
 "An update for the security subsystem to allow unprivileged users
  to see the status of the lockdown feature. From Jeremy Cline"

Also an added comment to describe CAP_SETFCAP.

* 'next-general' of git://git.kernel.org/pub/scm/linux/kernel/git/jmorris/linux-security:
  capabilities: add description for CAP_SETFCAP
  lockdown: Allow unprivileged users to see lockdown status
parents f41030a2 56f2e3b7
Loading
Loading
Loading
Loading
+2 −0
Original line number Diff line number Diff line
@@ -332,6 +332,8 @@ struct vfs_ns_cap_data {

#define CAP_AUDIT_CONTROL    30

/* Set or remove capabilities on files */

#define CAP_SETFCAP	     31

/* Override MAC access.
+1 −1
Original line number Diff line number Diff line
@@ -150,7 +150,7 @@ static int __init lockdown_secfs_init(void)
{
	struct dentry *dentry;

	dentry = securityfs_create_file("lockdown", 0600, NULL, NULL,
	dentry = securityfs_create_file("lockdown", 0644, NULL, NULL,
					&lockdown_ops);
	return PTR_ERR_OR_ZERO(dentry);
}