fs,userns: Change inode_capable to capable_wrt_inode_uidgid
The kernel has no concept of capabilities with respect to inodes; inodes exist independently of namespaces. For example, inode_capable(inode, CAP_LINUX_IMMUTABLE) would be nonsense. This patch changes inode_capable to check for uid and gid mappings and renames it to capable_wrt_inode_uidgid, which should make it more obvious what it does. Fixes CVE-2014-4014. Cc: Theodore Ts'o <tytso@mit.edu> Cc: Serge Hallyn <serge.hallyn@ubuntu.com> Cc: "Eric W. Biederman" <ebiederm@xmission.com> Cc: Dave Chinner <david@fromorbit.com> Cc: stable@vger.kernel.org Signed-off-by:Andy Lutomirski <luto@amacapital.net> Signed-off-by:
Linus Torvalds <torvalds@linux-foundation.org>
Showing
- fs/attr.c 4 additions, 4 deletionsfs/attr.c
- fs/inode.c 7 additions, 3 deletionsfs/inode.c
- fs/namei.c 6 additions, 5 deletionsfs/namei.c
- fs/xfs/xfs_ioctl.c 1 addition, 1 deletionfs/xfs/xfs_ioctl.c
- include/linux/capability.h 1 addition, 1 deletioninclude/linux/capability.h
- kernel/capability.c 8 additions, 12 deletionskernel/capability.c
Loading
Please register or sign in to comment