aboutsummaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorRichard Guy Briggs <rgb@redhat.com>2017-10-11 20:57:13 -0400
committerJames Morris <james.l.morris@oracle.com>2017-10-20 00:22:45 -0400
commit588fb2c7e294753d3090a1dc2e7c34e7e3ce5aff (patch)
tree3f305c99b9f1cc2d5d076e464c7399c651fe285b
parentc0d1adefe0a3775cc16374dc9ebdfd8504afa14b (diff)
capabilities: fix logic for effective root or real root
Now that the logic is inverted, it is much easier to see that both real root and effective root conditions had to be met to avoid printing the BPRM_FCAPS record with audit syscalls. This meant that any setuid root applications would print a full BPRM_FCAPS record when it wasn't necessary, cluttering the event output, since the SYSCALL and PATH records indicated the presence of the setuid bit and effective root user id. Require only one of effective root or real root to avoid printing the unnecessary record. Ref: commit 3fc689e96c0c ("Add audit_log_bprm_fcaps/AUDIT_BPRM_FCAPS") See: https://github.com/linux-audit/audit-kernel/issues/16 Signed-off-by: Richard Guy Briggs <rgb@redhat.com> Reviewed-by: Serge Hallyn <serge@hallyn.com> Acked-by: James Morris <james.l.morris@oracle.com> Acked-by: Kees Cook <keescook@chromium.org> Acked-by: Paul Moore <paul@paul-moore.com> Signed-off-by: James Morris <james.l.morris@oracle.com>
-rw-r--r--security/commoncap.c5
1 files changed, 2 insertions, 3 deletions
diff --git a/security/commoncap.c b/security/commoncap.c
index 0bd94d36e635..ad7536d76820 100644
--- a/security/commoncap.c
+++ b/security/commoncap.c
@@ -770,7 +770,7 @@ static inline bool __is_setgid(struct cred *new, const struct cred *old)
770 * 770 *
771 * We do not bother to audit if 3 things are true: 771 * We do not bother to audit if 3 things are true:
772 * 1) cap_effective has all caps 772 * 1) cap_effective has all caps
773 * 2) we are root 773 * 2) we became root *OR* are were already root
774 * 3) root is supposed to have all caps (SECURE_NOROOT) 774 * 3) root is supposed to have all caps (SECURE_NOROOT)
775 * Since this is just a normal root execing a process. 775 * Since this is just a normal root execing a process.
776 * 776 *
@@ -783,8 +783,7 @@ static inline bool nonroot_raised_pE(struct cred *cred, kuid_t root)
783 783
784 if (__cap_grew(effective, ambient, cred) && 784 if (__cap_grew(effective, ambient, cred) &&
785 !(__cap_full(effective, cred) && 785 !(__cap_full(effective, cred) &&
786 __is_eff(root, cred) && 786 (__is_eff(root, cred) || __is_real(root, cred)) &&
787 __is_real(root, cred) &&
788 root_privileged())) 787 root_privileged()))
789 ret = true; 788 ret = true;
790 return ret; 789 return ret;