diff options
| author | Richard Haines <[email protected]> | 2022-02-25 17:54:38 +0000 | 
|---|---|---|
| committer | Paul Moore <[email protected]> | 2022-02-25 15:35:19 -0500 | 
| commit | 65881e1db4e948614d9eb195b8e1197339822949 (patch) | |
| tree | 5412d30772bda69f399724371c13d53cfa4c1d96 /tools/perf/scripts/python/intel-pt-events.py | |
| parent | b97df7c098c531010e445da88d02b7bf7bf59ef6 (diff) | |
selinux: allow FIOCLEX and FIONCLEX with policy capability
These ioctls are equivalent to fcntl(fd, F_SETFD, flags), which SELinux
always allows too.  Furthermore, a failed FIOCLEX could result in a file
descriptor being leaked to a process that should not have access to it.
As this patch removes access controls, a policy capability needs to be
enabled in policy to always allow these ioctls.
Based-on-patch-by: Demi Marie Obenour <[email protected]>
Signed-off-by: Richard Haines <[email protected]>
[PM: subject line tweak]
Signed-off-by: Paul Moore <[email protected]>
Diffstat (limited to 'tools/perf/scripts/python/intel-pt-events.py')
0 files changed, 0 insertions, 0 deletions