Commit 7fdd1c66 authored by Ajo Jose Panoor's avatar Ajo Jose Panoor Committed by Zheng Zengkai
Browse files

imans: Check CAP_SYS_ADMIN in userns associated with IMA NS during configuration.

hulk inclusion
category: bugfix
bugzilla: https://gitee.com/openeuler/kernel/issues/I4JC4P


CVE: NA

-----------------------------------------------------------------

Writing to securityfs (x509_for_children) fails with permission issues
during IMANS configuration. It is because IMANS is checking for
CAP_SYS_ADMIN capability in the initial user namespace and not in the
newly created user namespace where the new process is actually part off.

Signed-off-by: default avatarAjo Jose Panoor <ajo.jose.panoor@huawei.com>
Reviewed-by: default avatarXiu Jianfeng <xiujianfeng@huawei.com>
Signed-off-by: default avatarZheng Zengkai <zhengzengkai@huawei.com>
parent abde6b94
Loading
Loading
Loading
Loading
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Please to comment