projects
/
linux-block.git
/ commitdiff
commit
grep
author
committer
pickaxe
?
search:
re
summary
|
shortlog
|
log
|
commit
| commitdiff |
tree
raw
|
patch
| inline |
side by side
(parent:
b9b5da3
)
debugfs: lockdown: Allow reading debugfs files that are not world readable
author
Michal Suchanek
<msuchanek@suse.de>
Tue, 4 Jan 2022 17:05:05 +0000
(18:05 +0100)
committer
Greg Kroah-Hartman
<gregkh@linuxfoundation.org>
Thu, 27 Jan 2022 09:54:02 +0000
(10:54 +0100)
[ Upstream commit
358fcf5ddbec4e6706405847d6a666f5933a6c25
]
When the kernel is locked down the kernel allows reading only debugfs
files with mode 444. Mode 400 is also valid but is not allowed.
Make the 444 into a mask.
Fixes:
5496197f9b08
("debugfs: Restrict debugfs when the kernel is locked down")
Signed-off-by: Michal Suchanek <msuchanek@suse.de>
Link:
https://lore.kernel.org/r/20220104170505.10248-1-msuchanek@suse.de
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
fs/debugfs/file.c
patch
|
blob
|
blame
|
history
diff --git
a/fs/debugfs/file.c
b/fs/debugfs/file.c
index 3aa5eb9ce498e46b89ef40e7cc900378de3bb29a..96059af28f5084827dceda7aaac2bb8094fe36cc 100644
(file)
--- a/
fs/debugfs/file.c
+++ b/
fs/debugfs/file.c
@@
-147,7
+147,7
@@
static int debugfs_locked_down(struct inode *inode,
struct file *filp,
const struct file_operations *real_fops)
{
- if ((inode->i_mode & 07777
) == 0444
&&
+ if ((inode->i_mode & 07777
& ~0444) == 0
&&
!(filp->f_mode & FMODE_WRITE) &&
!real_fops->unlocked_ioctl &&
!real_fops->compat_ioctl &&