capability: Add new capable_noaudit

In some situations (quota enforcement bypass in this case) we'd like to
check for a specific capability without triggering spurious audit
messages from security modules like selinux.

Add a new helper so we don't need to use ns_capable_noaudit() directly.

Signed-off-by: Carlos Maiolino <cmaiolino@redhat.com>
Reviewed-by: Christoph Hellwig <hch@lst.de>
Reviewed-by: Serge Hallyn <sergeh@kernel.org>
Signed-off-by: Carlos Maiolino <cem@kernel.org>
This commit is contained in:
Carlos Maiolino 2026-08-04 11:45:52 +02:00
parent e2f62a9744
commit 1b91724d0b
2 changed files with 23 additions and 0 deletions

View File

@ -145,6 +145,7 @@ extern bool has_capability_noaudit(struct task_struct *t, int cap);
extern bool has_ns_capability_noaudit(struct task_struct *t,
struct user_namespace *ns, int cap);
extern bool capable(int cap);
bool capable_noaudit(int cap);
extern bool ns_capable(struct user_namespace *ns, int cap);
extern bool ns_capable_noaudit(struct user_namespace *ns, int cap);
extern bool ns_capable_setid(struct user_namespace *ns, int cap);
@ -167,6 +168,10 @@ static inline bool capable(int cap)
{
return true;
}
static inline bool capable_noaudit(int cap)
{
return true;
}
static inline bool ns_capable(struct user_namespace *ns, int cap)
{
return true;

View File

@ -416,6 +416,24 @@ bool capable(int cap)
return ns_capable(&init_user_ns, cap);
}
EXPORT_SYMBOL(capable);
/**
* capable_noaudit - Determine if the current task has a superior
* capability in effect by checking the process's effective
* capabilities (unaudited).
* @cap: The capability to be tested for
*
* This is the same as capable(), except it uses CAP_OPT_NOAUDIT as to prevent
* issuing spurious audit messages.
*
* This sets PF_SUPERPRIV on the task if the capability is available on the
* assumption that it's about to be used.
*/
bool capable_noaudit(int cap)
{
return ns_capable_noaudit(&init_user_ns, cap);
}
EXPORT_SYMBOL(capable_noaudit);
#endif /* CONFIG_MULTIUSER */
/**