aboutsummaryrefslogtreecommitdiffstats
path: root/lib/dump_stack.c
diff options
context:
space:
mode:
authorKees Cook <[email protected]>2017-08-10 03:43:17 +0000
committerKees Cook <[email protected]>2017-08-17 23:28:37 +0000
commitd7caa33687cea218b6d68beea89d10a45a901e19 (patch)
tree734350f4d0037478c7064db3a5f637ececc6fca7 /lib/dump_stack.c
parentLinux 4.13-rc2 (diff)
downloadkernel-d7caa33687cea218b6d68beea89d10a45a901e19.tar.gz
kernel-d7caa33687cea218b6d68beea89d10a45a901e19.zip
pstore: Make default pstorefs root dir perms 0750
Currently only DMESG and CONSOLE record types are protected, and it isn't obvious that they are using a capability check. Instead switch to explicit root directory mode of 0750 to keep files private by default. This will allow the removal of the capability check, which was non-obvious and forces a process to have possibly too much privilege when simple post-boot chgrp for readers would be possible without it. Signed-off-by: Kees Cook <[email protected]> Reviewed-by: Sergey Senozhatsky <[email protected]>
Diffstat (limited to 'lib/dump_stack.c')
0 files changed, 0 insertions, 0 deletions