[PATCH 1/2] iouring: one capable call per iouring instance
Keith Busch
kbusch at kernel.org
Mon Dec 4 11:37:38 PST 2023
On Mon, Dec 04, 2023 at 02:22:22PM -0500, Jeff Moyer wrote:
> Jens Axboe <axboe at kernel.dk> writes:
>
> > On 12/4/23 11:40 AM, Jeff Moyer wrote:
> >> Finally, as Jens mentioned, I would expect dropping priviliges to, you
> >> know, drop privileges. I don't think a commit message is going to be
> >> enough documentation for a change like this.
> >
> > Only thing I can think of here is to cache the state in
> > task->io_uring->something, and then ensure those are invalidated
> > whenever caps change.
>
> I looked through the capable() code, and there is no way that I could
> find to be notified of changes.
Something like LSM_HOOK_INIT on 'capset', but needs to work without
CONFIG_SECURITY.
More information about the Linux-nvme
mailing list