Skip to content

Commit d9afbb3

Browse files
committed
Merge branch 'next-general' of git://git.kernel.org/pub/scm/linux/kernel/git/jmorris/linux-security
Pull lockdown update from James Morris: "An update for the security subsystem to allow unprivileged users to see the status of the lockdown feature. From Jeremy Cline" Also an added comment to describe CAP_SETFCAP. * 'next-general' of git://git.kernel.org/pub/scm/linux/kernel/git/jmorris/linux-security: capabilities: add description for CAP_SETFCAP lockdown: Allow unprivileged users to see lockdown status
2 parents f41030a + 56f2e3b commit d9afbb3

File tree

2 files changed

+3
-1
lines changed

2 files changed

+3
-1
lines changed

include/uapi/linux/capability.h

+2
Original file line numberDiff line numberDiff line change
@@ -332,6 +332,8 @@ struct vfs_ns_cap_data {
332332

333333
#define CAP_AUDIT_CONTROL 30
334334

335+
/* Set or remove capabilities on files */
336+
335337
#define CAP_SETFCAP 31
336338

337339
/* Override MAC access.

security/lockdown/lockdown.c

+1-1
Original file line numberDiff line numberDiff line change
@@ -150,7 +150,7 @@ static int __init lockdown_secfs_init(void)
150150
{
151151
struct dentry *dentry;
152152

153-
dentry = securityfs_create_file("lockdown", 0600, NULL, NULL,
153+
dentry = securityfs_create_file("lockdown", 0644, NULL, NULL,
154154
&lockdown_ops);
155155
return PTR_ERR_OR_ZERO(dentry);
156156
}

0 commit comments

Comments
 (0)