Skip to content

Commit

Permalink
Merge branch 'next-general' of git://git.kernel.org/pub/scm/linux/ker…
Browse files Browse the repository at this point in the history
…nel/git/jmorris/linux-security

Pull lockdown update from James Morris:
 "An update for the security subsystem to allow unprivileged users
  to see the status of the lockdown feature. From Jeremy Cline"

Also an added comment to describe CAP_SETFCAP.

* 'next-general' of git://git.kernel.org/pub/scm/linux/kernel/git/jmorris/linux-security:
  capabilities: add description for CAP_SETFCAP
  lockdown: Allow unprivileged users to see lockdown status
  • Loading branch information
torvalds committed Jun 3, 2020
2 parents f41030a + 56f2e3b commit d9afbb3
Show file tree
Hide file tree
Showing 2 changed files with 3 additions and 1 deletion.
2 changes: 2 additions & 0 deletions include/uapi/linux/capability.h
Original file line number Diff line number Diff line change
Expand Up @@ -332,6 +332,8 @@ struct vfs_ns_cap_data {

#define CAP_AUDIT_CONTROL 30

/* Set or remove capabilities on files */

#define CAP_SETFCAP 31

/* Override MAC access.
Expand Down
2 changes: 1 addition & 1 deletion security/lockdown/lockdown.c
Original file line number Diff line number Diff line change
Expand Up @@ -150,7 +150,7 @@ static int __init lockdown_secfs_init(void)
{
struct dentry *dentry;

dentry = securityfs_create_file("lockdown", 0600, NULL, NULL,
dentry = securityfs_create_file("lockdown", 0644, NULL, NULL,
&lockdown_ops);
return PTR_ERR_OR_ZERO(dentry);
}
Expand Down

0 comments on commit d9afbb3

Please sign in to comment.