[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Date: Thu, 03 Mar 2011 10:56:55 -0800 (PST)
From: David Miller <davem@...emloft.net>
To: chrisw@...s-sol.org
Cc: kaber@...sh.net, netdev@...r.kernel.org, dm-devel@...hat.com,
linux-security-module@...r.kernel.org, drbd-dev@...ts.linbit.com
Subject: Re: [PATCH 2/2] netlink: kill eff_cap from struct netlink_skb_parms
From: Chris Wright <chrisw@...s-sol.org>
Date: Thu, 3 Mar 2011 09:32:30 -0800
> * Patrick McHardy (kaber@...sh.net) wrote:
>
>> commit 8ff259625f0ab295fa085b0718eed13093813fbc
>> Author: Patrick McHardy <kaber@...sh.net>
>> Date: Thu Mar 3 10:17:31 2011 +0100
>>
>> netlink: kill eff_cap from struct netlink_skb_parms
>>
>> Netlink message processing in the kernel is synchronous these days,
>> capabilities can be checked directly in security_netlink_recv() from
>> the current process.
>>
>> Signed-off-by: Patrick McHardy <kaber@...sh.net>
>
> Thanks for doing that Patrick. I looked at this earlier and thought
> there was still an async path, but I guess that's just to another
> userspace process.
>
> BTW, I think you missed a couple connector based callers:
>
> drivers/staging/pohmelfs/config.c: if (!cap_raised(nsp->eff_cap, CAP_SYS_AD
> drivers/video/uvesafb.c: if (!cap_raised(nsp->eff_cap, CAP_SYS_ADMIN))
>
> Fix those and:
>
> Acked-by: Chris Wright <chrisw@...s-sol.org>
Patrick, I'll apply your first patch, please respin this second patch with
the changes mentioned here.
Thanks!
--
To unsubscribe from this list: send the line "unsubscribe netdev" in
the body of a message to majordomo@...r.kernel.org
More majordomo info at http://vger.kernel.org/majordomo-info.html
Powered by blists - more mailing lists