[PATCH 2/2] debugfs: only allow root access to debugging interfaces
Kees Cook
kees.cook at canonical.com
Tue Feb 22 18:28:37 UTC 2011
Block access to the potentially dangerous debugging interfaces in
the debugfs filesystem.
Signed-off-by: Kees Cook <kees.cook at canonical.com>
---
fs/debugfs/inode.c | 2 +-
1 files changed, 1 insertions(+), 1 deletions(-)
diff --git a/fs/debugfs/inode.c b/fs/debugfs/inode.c
index 3cb33c3..83c61a3 100644
--- a/fs/debugfs/inode.c
+++ b/fs/debugfs/inode.c
@@ -133,7 +133,7 @@ static int debug_fill_super(struct super_block *sb, void *data, int silent)
static struct tree_descr debug_files[] = {{""}};
return simple_fill_super(sb, DEBUGFS_MAGIC, debug_files,
- S_IWUSR | S_IRUGO | S_IXUGO);
+ S_IRWXU);
}
static struct dentry *debug_mount(struct file_system_type *fs_type,
--
1.7.2.3
More information about the kernel-team
mailing list