diff options
-rw-r--r-- | include/linux/capability.h | 6 | ||||
-rw-r--r-- | kernel/capability.c | 2 |
2 files changed, 4 insertions, 4 deletions
diff --git a/include/linux/capability.h b/include/linux/capability.h index 16ee8b49a200..11d562863e49 100644 --- a/include/linux/capability.h +++ b/include/linux/capability.h | |||
@@ -412,7 +412,6 @@ extern const kernel_cap_t __cap_init_eff_set; | |||
412 | 412 | ||
413 | # define CAP_EMPTY_SET ((kernel_cap_t){{ 0, 0 }}) | 413 | # define CAP_EMPTY_SET ((kernel_cap_t){{ 0, 0 }}) |
414 | # define CAP_FULL_SET ((kernel_cap_t){{ ~0, ~0 }}) | 414 | # define CAP_FULL_SET ((kernel_cap_t){{ ~0, ~0 }}) |
415 | # define CAP_INIT_EFF_SET ((kernel_cap_t){{ ~CAP_TO_MASK(CAP_SETPCAP), ~0 }}) | ||
416 | # define CAP_FS_SET ((kernel_cap_t){{ CAP_FS_MASK_B0 \ | 415 | # define CAP_FS_SET ((kernel_cap_t){{ CAP_FS_MASK_B0 \ |
417 | | CAP_TO_MASK(CAP_LINUX_IMMUTABLE), \ | 416 | | CAP_TO_MASK(CAP_LINUX_IMMUTABLE), \ |
418 | CAP_FS_MASK_B1 } }) | 417 | CAP_FS_MASK_B1 } }) |
@@ -423,10 +422,10 @@ extern const kernel_cap_t __cap_init_eff_set; | |||
423 | #endif /* _KERNEL_CAPABILITY_U32S != 2 */ | 422 | #endif /* _KERNEL_CAPABILITY_U32S != 2 */ |
424 | 423 | ||
425 | #define CAP_INIT_INH_SET CAP_EMPTY_SET | 424 | #define CAP_INIT_INH_SET CAP_EMPTY_SET |
425 | #define CAP_INIT_EFF_SET CAP_FULL_SET | ||
426 | 426 | ||
427 | # define cap_clear(c) do { (c) = __cap_empty_set; } while (0) | 427 | # define cap_clear(c) do { (c) = __cap_empty_set; } while (0) |
428 | # define cap_set_full(c) do { (c) = __cap_full_set; } while (0) | 428 | # define cap_set_full(c) do { (c) = __cap_full_set; } while (0) |
429 | # define cap_set_init_eff(c) do { (c) = __cap_init_eff_set; } while (0) | ||
430 | 429 | ||
431 | #define cap_raise(c, flag) ((c).cap[CAP_TO_INDEX(flag)] |= CAP_TO_MASK(flag)) | 430 | #define cap_raise(c, flag) ((c).cap[CAP_TO_INDEX(flag)] |= CAP_TO_MASK(flag)) |
432 | #define cap_lower(c, flag) ((c).cap[CAP_TO_INDEX(flag)] &= ~CAP_TO_MASK(flag)) | 431 | #define cap_lower(c, flag) ((c).cap[CAP_TO_INDEX(flag)] &= ~CAP_TO_MASK(flag)) |
@@ -547,6 +546,9 @@ extern bool capable(int cap); | |||
547 | extern bool ns_capable(struct user_namespace *ns, int cap); | 546 | extern bool ns_capable(struct user_namespace *ns, int cap); |
548 | extern bool task_ns_capable(struct task_struct *t, int cap); | 547 | extern bool task_ns_capable(struct task_struct *t, int cap); |
549 | 548 | ||
549 | extern const kernel_cap_t __cap_empty_set; | ||
550 | extern const kernel_cap_t __cap_full_set; | ||
551 | |||
550 | /** | 552 | /** |
551 | * nsown_capable - Check superior capability to one's own user_ns | 553 | * nsown_capable - Check superior capability to one's own user_ns |
552 | * @cap: The capability in question | 554 | * @cap: The capability in question |
diff --git a/kernel/capability.c b/kernel/capability.c index bf0c734d0c12..2a374d512ead 100644 --- a/kernel/capability.c +++ b/kernel/capability.c | |||
@@ -23,11 +23,9 @@ | |||
23 | 23 | ||
24 | const kernel_cap_t __cap_empty_set = CAP_EMPTY_SET; | 24 | const kernel_cap_t __cap_empty_set = CAP_EMPTY_SET; |
25 | const kernel_cap_t __cap_full_set = CAP_FULL_SET; | 25 | const kernel_cap_t __cap_full_set = CAP_FULL_SET; |
26 | const kernel_cap_t __cap_init_eff_set = CAP_INIT_EFF_SET; | ||
27 | 26 | ||
28 | EXPORT_SYMBOL(__cap_empty_set); | 27 | EXPORT_SYMBOL(__cap_empty_set); |
29 | EXPORT_SYMBOL(__cap_full_set); | 28 | EXPORT_SYMBOL(__cap_full_set); |
30 | EXPORT_SYMBOL(__cap_init_eff_set); | ||
31 | 29 | ||
32 | int file_caps_enabled = 1; | 30 | int file_caps_enabled = 1; |
33 | 31 | ||