diff options
| author | Kees Cook <[email protected]> | 2017-08-10 03:43:17 +0000 |
|---|---|---|
| committer | Kees Cook <[email protected]> | 2017-08-17 23:28:37 +0000 |
| commit | d7caa33687cea218b6d68beea89d10a45a901e19 (patch) | |
| tree | 734350f4d0037478c7064db3a5f637ececc6fca7 /lib/dump_stack.c | |
| parent | Linux 4.13-rc2 (diff) | |
| download | kernel-d7caa33687cea218b6d68beea89d10a45a901e19.tar.gz kernel-d7caa33687cea218b6d68beea89d10a45a901e19.zip | |
pstore: Make default pstorefs root dir perms 0750
Currently only DMESG and CONSOLE record types are protected, and it isn't
obvious that they are using a capability check. Instead switch to explicit
root directory mode of 0750 to keep files private by default. This will
allow the removal of the capability check, which was non-obvious and
forces a process to have possibly too much privilege when simple post-boot
chgrp for readers would be possible without it.
Signed-off-by: Kees Cook <[email protected]>
Reviewed-by: Sergey Senozhatsky <[email protected]>
Diffstat (limited to 'lib/dump_stack.c')
0 files changed, 0 insertions, 0 deletions
