2d7f105edb
If the current task fails the check for the queried capability via `capable(CAP_SYS_ADMIN)` LSMs like SELinux generate a denial message. Issuing such denial messages unnecessarily can lead to a policy author granting more privileges to a subject than needed to silence them. Reorder CAP_SYS_ADMIN checks after the check whether the operation is actually privileged. Signed-off-by: Christian Göttsche <cgzones@googlemail.com> Reviewed-by: Jarkko Sakkinen <jarkko@kernel.org> Signed-off-by: Jarkko Sakkinen <jarkko@kernel.org> |
||
---|---|---|
.. | ||
encrypted-keys | ||
trusted-keys | ||
Kconfig | ||
Makefile | ||
big_key.c | ||
compat.c | ||
compat_dh.c | ||
dh.c | ||
gc.c | ||
internal.h | ||
key.c | ||
keyctl.c | ||
keyctl_pkey.c | ||
keyring.c | ||
permission.c | ||
persistent.c | ||
proc.c | ||
process_keys.c | ||
request_key.c | ||
request_key_auth.c | ||
sysctl.c | ||
user_defined.c |