commit | dd1384b334fbe9144677db8612f53acae8837555 | [log] [tgz] |
---|---|---|
author | Serge E. Hallyn <serge.hallyn@canonical.com> | Tue Jul 26 18:58:28 2011 +0000 |
committer | Eric W. Biederman <ebiederm@aristanetworks.com> | Thu Aug 11 10:07:51 2011 -0500 |
tree | b1f6477b4516dadb7eb0413ed60a098225d71f77 | |
parent | a3e1c336c2f555197ee86b60bb742636eb60e24c [diff] |
userns: clamp down users of cap_raised A few modules are using cap_raised(current_cap(), cap) to authorize actions, but the privilege should be applicable against the initial user namespace. Refuse privilege if the caller is not in init_user_ns. Signed-off-by: Serge E. Hallyn <serge.hallyn@canonical.com> Cc: Eric W. Biederman <ebiederm@xmission.com>