summaryrefslogtreecommitdiffstats
path: root/security/commoncap.c
diff options
context:
space:
mode:
authorEric W. Biederman <ebiederm@xmission.com>2017-09-19 00:58:08 +0200
committerEric W. Biederman <ebiederm@xmission.com>2018-05-24 19:02:25 +0200
commitbc6155d1326092f4c29fe05a32b614249620d88e (patch)
treed36853f7e280a4dff8d653981ce71193218c77b7 /security/commoncap.c
parentfs: Allow superblock owner to replace invalid owners of inodes (diff)
downloadlinux-bc6155d1326092f4c29fe05a32b614249620d88e.tar.xz
linux-bc6155d1326092f4c29fe05a32b614249620d88e.zip
fs: Allow superblock owner to access do_remount_sb()
Superblock level remounts are currently restricted to global CAP_SYS_ADMIN, as is the path for changing the root mount to read only on umount. Loosen both of these permission checks to also allow CAP_SYS_ADMIN in any namespace which is privileged towards the userns which originally mounted the filesystem. Signed-off-by: Seth Forshee <seth.forshee@canonical.com> Acked-by: "Eric W. Biederman" <ebiederm@xmission.com> Acked-by: Serge Hallyn <serge@hallyn.com> Acked-by: Christian Brauner <christian@brauner.io> Signed-off-by: Eric W. Biederman <ebiederm@xmission.com>
Diffstat (limited to 'security/commoncap.c')
0 files changed, 0 insertions, 0 deletions