mirror of
https://github.com/torvalds/linux.git
synced 2026-06-07 22:14:04 +02:00
cgroup: Change from CAP_SYS_NICE to CAP_SYS_RESOURCE for cgroup migration permissions
Try to better match what we're pushing upstream, use CAP_SYS_RESOURCE instead of CAP_SYS_NICE, which shoudln't affect Android as Zygote and system_server already use CAP_SYS_RESOURCE. Signed-off-by: John Stultz <john.stultz@linaro.org>
This commit is contained in:
parent
9d37de65aa
commit
273daee0be
|
|
@ -2686,7 +2686,7 @@ static int cgroup_procs_write_permission(struct task_struct *task,
|
|||
if (!uid_eq(cred->euid, GLOBAL_ROOT_UID) &&
|
||||
!uid_eq(cred->euid, tcred->uid) &&
|
||||
!uid_eq(cred->euid, tcred->suid) &&
|
||||
!ns_capable(tcred->user_ns, CAP_SYS_NICE))
|
||||
!ns_capable(tcred->user_ns, CAP_SYS_RESOURCE))
|
||||
ret = -EACCES;
|
||||
|
||||
if (!ret && cgroup_on_dfl(dst_cgrp)) {
|
||||
|
|
|
|||
Loading…
Reference in New Issue
Block a user