diff options
author | Eric W. Biederman <ebiederm@xmission.com> | 2012-09-11 08:20:20 +0200 |
---|---|---|
committer | Eric W. Biederman <ebiederm@xmission.com> | 2012-09-18 02:38:42 +0200 |
commit | 34e36d8ecbd958bc15f8e63deade1227de337eb1 (patch) | |
tree | 2b6f98480e7a035c2910e39d68ca1ff453a98f89 /kernel/module.c | |
parent | userns: net: Call key_alloc with GLOBAL_ROOT_UID, GLOBAL_ROOT_GID instead of ... (diff) | |
download | linux-34e36d8ecbd958bc15f8e63deade1227de337eb1.tar.xz linux-34e36d8ecbd958bc15f8e63deade1227de337eb1.zip |
audit: Limit audit requests to processes in the initial pid and user namespaces.
This allows the code to safely make the assumption that all of the
uids gids and pids that need to be send in audit messages are in the
initial namespaces.
If someone cares we may lift this restriction someday but start with
limiting access so at least the code is always correct.
Cc: Al Viro <viro@zeniv.linux.org.uk>
Cc: Eric Paris <eparis@redhat.com>
Signed-off-by: "Eric W. Biederman" <ebiederm@xmission.com>
Diffstat (limited to 'kernel/module.c')
0 files changed, 0 insertions, 0 deletions