From ea64aa57d596c4cbe518ffd043c52ef64089708d Mon Sep 17 00:00:00 2001 From: Paul Moore Date: Wed, 14 Jan 2026 16:23:47 -0500 Subject: [PATCH] selinux: drop the BUG() in cred_has_capability() With the compile time check located immediately above the cred_has_capability() function ensuring that we will notice if the capability set grows beyond 63 capabilities, we can safely remove the BUG() call from the cred_has_capability(). Signed-off-by: Paul Moore --- security/selinux/hooks.c | 1 - 1 file changed, 1 deletion(-) diff --git a/security/selinux/hooks.c b/security/selinux/hooks.c index 9289ed89a8ec..feda34b18d83 100644 --- a/security/selinux/hooks.c +++ b/security/selinux/hooks.c @@ -1659,7 +1659,6 @@ static int cred_has_capability(const struct cred *cred, break; default: pr_err("SELinux: out of range capability %d\n", cap); - BUG(); return -EINVAL; } -- 2.47.3