Revert "block: grant IOPRIO_CLASS_RT to CAP_SYS_NICE"
This reverts commit 9d3a39a5f1
as that
commit causes a bunch of SELinux errors.
Signed-off-by: Greg Kroah-Hartman <gregkh@google.com>
Change-Id: I73dc15c4ecddcf1950ca7fca2cc107be27da8f3f
This commit is contained in:
@@ -69,7 +69,7 @@ int ioprio_check_cap(int ioprio)
|
|||||||
|
|
||||||
switch (class) {
|
switch (class) {
|
||||||
case IOPRIO_CLASS_RT:
|
case IOPRIO_CLASS_RT:
|
||||||
if (!capable(CAP_SYS_NICE) && !capable(CAP_SYS_ADMIN))
|
if (!capable(CAP_SYS_ADMIN))
|
||||||
return -EPERM;
|
return -EPERM;
|
||||||
fallthrough;
|
fallthrough;
|
||||||
/* rt has prio field too */
|
/* rt has prio field too */
|
||||||
|
@@ -288,8 +288,6 @@ struct vfs_ns_cap_data {
|
|||||||
processes and setting the scheduling algorithm used by another
|
processes and setting the scheduling algorithm used by another
|
||||||
process. */
|
process. */
|
||||||
/* Allow setting cpu affinity on other processes */
|
/* Allow setting cpu affinity on other processes */
|
||||||
/* Allow setting realtime ioprio class */
|
|
||||||
/* Allow setting ioprio class on other processes */
|
|
||||||
|
|
||||||
#define CAP_SYS_NICE 23
|
#define CAP_SYS_NICE 23
|
||||||
|
|
||||||
|
Reference in New Issue
Block a user