summaryrefslogtreecommitdiffstats
path: root/Makefile
diff options
context:
space:
mode:
authorKees Cook <keescook@chromium.org>2017-08-10 05:43:17 +0200
committerKees Cook <keescook@chromium.org>2017-08-18 01:28:37 +0200
commitd7caa33687cea218b6d68beea89d10a45a901e19 (patch)
tree734350f4d0037478c7064db3a5f637ececc6fca7 /Makefile
parentLinux 4.13-rc2 (diff)
downloadlinux-d7caa33687cea218b6d68beea89d10a45a901e19.tar.xz
linux-d7caa33687cea218b6d68beea89d10a45a901e19.zip
pstore: Make default pstorefs root dir perms 0750
Currently only DMESG and CONSOLE record types are protected, and it isn't obvious that they are using a capability check. Instead switch to explicit root directory mode of 0750 to keep files private by default. This will allow the removal of the capability check, which was non-obvious and forces a process to have possibly too much privilege when simple post-boot chgrp for readers would be possible without it. Signed-off-by: Kees Cook <keescook@chromium.org> Reviewed-by: Sergey Senozhatsky <sergey.senozhatsky@gmail.com>
Diffstat (limited to 'Makefile')
0 files changed, 0 insertions, 0 deletions