• S
    devices cgroup: allow mkfifo · 0b82ac37
    Serge E. Hallyn 提交于
    The devcgroup_inode_permission() hook in the devices whitelist cgroup has
    always bypassed access checks on fifos.  But the mknod hook did not.  The
    devices whitelist is only about block and char devices, and fifos can't
    even be added to the whitelist, so fifos can't be created at all except by
    tasks which have 'a' in their whitelist (meaning they have access to all
    devices).
    
    Fix the behavior by bypassing access checks to mkfifo.
    Signed-off-by: NSerge E. Hallyn <serue@us.ibm.com>
    Cc: Li Zefan <lizf@cn.fujitsu.com>
    Cc: Pavel Emelyanov <xemul@openvz.org>
    Cc: Paul Menage <menage@google.com>
    Cc: Lai Jiangshan <laijs@cn.fujitsu.com>
    Cc: KOSAKI Motohiro <kosaki.motohiro@jp.fujitsu.com>
    Cc: James Morris <jmorris@namei.org>
    Reported-by: NDaniel Lezcano <dlezcano@fr.ibm.com>
    Cc: <stable@kernel.org>		[2.6.27.x]
    Signed-off-by: NAndrew Morton <akpm@linux-foundation.org>
    Signed-off-by: NLinus Torvalds <torvalds@linux-foundation.org>
    0b82ac37
device_cgroup.c 11.6 KB