Advertisement
s243a

BarryK: cap_sys_mount-1.patch

Mar 2nd, 2021
359
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.23 KB | None | 0 0
  1. #See: https://bkhome.org/news/202012/kernel-510-lockdown-success.html
  2. diff -Naur linux-5.10/include/uapi/linux/capability.h linux-5.10P1/include/uapi/linux/capability.h
  3. --- linux-5.10/include/uapi/linux/capability.h 2020-12-07 06:25:12.000000000 +0800
  4. +++ linux-5.10P1/include/uapi/linux/capability.h 2020-12-14 11:03:39.127180439 +0800
  5. @@ -417,7 +417,9 @@
  6.  
  7. #define CAP_CHECKPOINT_RESTORE 40
  8.  
  9. -#define CAP_LAST_CAP CAP_CHECKPOINT_RESTORE
  10. +#define CAP_SYS_MOUNT 41
  11. +
  12. +#define CAP_LAST_CAP CAP_SYS_MOUNT
  13.  
  14. #define cap_valid(x) ((x) >= 0 && (x) <= CAP_LAST_CAP)
  15.  
  16. diff -Naur linux-5.10/security/selinux/include/classmap.h linux-5.10P1/security/selinux/include/classmap.h
  17. --- linux-5.10/security/selinux/include/classmap.h 2020-12-07 06:25:12.000000000 +0800
  18. +++ linux-5.10P1/security/selinux/include/classmap.h 2020-12-14 11:09:33.393857376 +0800
  19. @@ -28,9 +28,9 @@
  20.  
  21. #define COMMON_CAP2_PERMS "mac_override", "mac_admin", "syslog", \
  22. "wake_alarm", "block_suspend", "audit_read", "perfmon", "bpf", \
  23. - "checkpoint_restore"
  24. + "checkpoint_restore", "sys_mount"
  25.  
  26. -#if CAP_LAST_CAP > CAP_CHECKPOINT_RESTORE
  27. +#if CAP_LAST_CAP > CAP_SYS_MOUNT
  28. #error New capability defined, please update COMMON_CAP2_PERMS.
  29. #endif
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement