mirror of
https://github.com/torvalds/linux.git
synced 2026-09-13 14:44:42 +02:00
capability: Add new capable_noaudit
In some situations (quota enforcement bypass in this case) we'd like to check for a specific capability without triggering spurious audit messages from security modules like selinux. Add a new helper so we don't need to use ns_capable_noaudit() directly. Signed-off-by: Carlos Maiolino <cmaiolino@redhat.com> Reviewed-by: Christoph Hellwig <hch@lst.de> Reviewed-by: Serge Hallyn <sergeh@kernel.org> Signed-off-by: Carlos Maiolino <cem@kernel.org>
This commit is contained in:
parent
e2f62a9744
commit
1b91724d0b
|
|
@ -145,6 +145,7 @@ extern bool has_capability_noaudit(struct task_struct *t, int cap);
|
|||
extern bool has_ns_capability_noaudit(struct task_struct *t,
|
||||
struct user_namespace *ns, int cap);
|
||||
extern bool capable(int cap);
|
||||
bool capable_noaudit(int cap);
|
||||
extern bool ns_capable(struct user_namespace *ns, int cap);
|
||||
extern bool ns_capable_noaudit(struct user_namespace *ns, int cap);
|
||||
extern bool ns_capable_setid(struct user_namespace *ns, int cap);
|
||||
|
|
@ -167,6 +168,10 @@ static inline bool capable(int cap)
|
|||
{
|
||||
return true;
|
||||
}
|
||||
static inline bool capable_noaudit(int cap)
|
||||
{
|
||||
return true;
|
||||
}
|
||||
static inline bool ns_capable(struct user_namespace *ns, int cap)
|
||||
{
|
||||
return true;
|
||||
|
|
|
|||
|
|
@ -416,6 +416,24 @@ bool capable(int cap)
|
|||
return ns_capable(&init_user_ns, cap);
|
||||
}
|
||||
EXPORT_SYMBOL(capable);
|
||||
|
||||
/**
|
||||
* capable_noaudit - Determine if the current task has a superior
|
||||
* capability in effect by checking the process's effective
|
||||
* capabilities (unaudited).
|
||||
* @cap: The capability to be tested for
|
||||
*
|
||||
* This is the same as capable(), except it uses CAP_OPT_NOAUDIT as to prevent
|
||||
* issuing spurious audit messages.
|
||||
*
|
||||
* This sets PF_SUPERPRIV on the task if the capability is available on the
|
||||
* assumption that it's about to be used.
|
||||
*/
|
||||
bool capable_noaudit(int cap)
|
||||
{
|
||||
return ns_capable_noaudit(&init_user_ns, cap);
|
||||
}
|
||||
EXPORT_SYMBOL(capable_noaudit);
|
||||
#endif /* CONFIG_MULTIUSER */
|
||||
|
||||
/**
|
||||
|
|
|
|||
Loading…
Reference in New Issue
Block a user