bpf: Avoid unnecessary audit log for CPU security mitigations
authorYafang Shao <laoar.shao@gmail.com>
Fri, 13 Oct 2023 08:39:16 +0000 (08:39 +0000)
committerAndrii Nakryiko <andrii@kernel.org>
Fri, 13 Oct 2023 19:33:21 +0000 (12:33 -0700)
commit236334aeec0f93217cf9235f2004e61a0a1a5985
tree2752c8b15edaa537be81e3beca7460a9eb0222c0
parentd2dc885b8c9ddb6fc374d93a87f8f2d1b97d2caf
bpf: Avoid unnecessary audit log for CPU security mitigations

Check cpu_mitigations_off() first to avoid calling capable() if it is off.
This can avoid unnecessary audit log.

Fixes: bc5bc309db45 ("bpf: Inherit system settings for CPU security mitigations")
Suggested-by: Andrii Nakryiko <andrii.nakryiko@gmail.com>
Signed-off-by: Yafang Shao <laoar.shao@gmail.com>
Signed-off-by: Andrii Nakryiko <andrii@kernel.org>
Link: https://lore.kernel.org/bpf/CAEf4Bza6UVUWqcWQ-66weZ-nMDr+TFU3Mtq=dumZFD-pSqU7Ow@mail.gmail.com/
Link: https://lore.kernel.org/bpf/20231013083916.4199-1-laoar.shao@gmail.com
include/linux/bpf.h