[RFC v2][PATCH 2/9] Remove CAP_SYS_ADMIN for checkpoint/restart

Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
From: Dave Hansen
Date: Wednesday, August 20, 2008 - 12:25 pm

We need to do this so that we think about the security concerns
as we add each and every bit of c/r functionality.  There's
nothing that we need privileges for, yet.  Let's keep it that
way as long as possible.

---

 oren-cr.git-dave/checkpoint/sys.c |    6 ------
 1 file changed, 6 deletions(-)

diff -puN checkpoint/sys.c~0003-Remove-CAP_SYS_ADMIN-for-checkpoint-restart checkpoint/sys.c
--- oren-cr.git/checkpoint/sys.c~0003-Remove-CAP_SYS_ADMIN-for-checkpoint-restart	2008-08-20 12:12:49.000000000 -0700
+++ oren-cr.git-dave/checkpoint/sys.c	2008-08-20 12:12:49.000000000 -0700
@@ -169,9 +169,6 @@ asmlinkage long sys_checkpoint(pid_t pid
 	int fput_needed;
 	int ret;
 
-	if (!capable(CAP_SYS_ADMIN))
-		return -EPERM;
-
 	file = fget_light(fd, &fput_needed);
 	if (!file)
 		return -EBADF;
@@ -207,9 +204,6 @@ asmlinkage long sys_restart(int crid, in
 	int fput_needed;
 	int ret;
 
-	if (!capable(CAP_SYS_ADMIN))
-		return -EPERM;
-
 	file = fget_light(fd, &fput_needed);
 	if (!file)
 		return -EBADF;
_
--
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
[RFC v2][PATCH 0/9] kernel-based checkpoint-restart, Dave Hansen, (Wed Aug 20, 12:25 pm)
[RFC v2][PATCH 2/9] Remove CAP_SYS_ADMIN for checkpoint/re ..., Dave Hansen, (Wed Aug 20, 12:25 pm)
[RFC v2][PATCH 3/9] checkpoint/restart: x86 support, Dave Hansen, (Wed Aug 20, 12:26 pm)
[RFC v2][PATCH 6/9] Simplify filename handling for now, Dave Hansen, (Wed Aug 20, 12:26 pm)
[RFC v2][PATCH 7/9] remove temporary buffer structures, Dave Hansen, (Wed Aug 20, 12:26 pm)
[RFC v2][PATCH 9/9] remove ->cksum field, Dave Hansen, (Wed Aug 20, 12:26 pm)