]> git.ipfire.org Git - thirdparty/kernel/stable.git/commitdiff
Make TASKSTATS require root access
authorLinus Torvalds <torvalds@linux-foundation.org>
Tue, 20 Sep 2011 00:04:37 +0000 (17:04 -0700)
committerWilly Tarreau <w@1wt.eu>
Sat, 11 Feb 2012 14:38:05 +0000 (15:38 +0100)
commit 1a51410abe7d0ee4b1d112780f46df87d3621043 upstream.

Ok, this isn't optimal, since it means that 'iotop' needs admin
capabilities, and we may have to work on this some more.  But at the
same time it is very much not acceptable to let anybody just read
anybody elses IO statistics quite at this level.

Use of the GENL_ADMIN_PERM suggested by Johannes Berg as an alternative
to checking the capabilities by hand.

Reported-by: Vasiliy Kulikov <segoon@openwall.com>
Cc: Johannes Berg <johannes.berg@intel.com>
Acked-by: Balbir Singh <bsingharora@gmail.com>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
Cc: Moritz Mühlenhoff <jmm@inutil.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@suse.de>
Signed-off-by: Willy Tarreau <w@1wt.eu>
kernel/taskstats.c

index bd6be76303cf23b4c52b757a93bf1966bdbb4f0a..7fdd65b30da0e73a9d2c37d9fa58424d72a716f8 100644 (file)
@@ -574,6 +574,7 @@ static struct genl_ops taskstats_ops = {
        .cmd            = TASKSTATS_CMD_GET,
        .doit           = taskstats_user_cmd,
        .policy         = taskstats_cmd_get_policy,
+       .flags          = GENL_ADMIN_PERM,
 };
 
 static struct genl_ops cgroupstats_ops = {