Thread (10 messages) 10 messages, 7 authors, 2021-11-16

Re: [PATCH] block: Check ADMIN before NICE for IOPRIO_CLASS_RT

From: Jens Axboe <axboe@kernel.dk>
Date: 2021-11-16 01:22:40
Also in: lkml, selinux, stable

On 11/15/21 10:38 AM, Alistair Delva wrote:
Booting to Android userspace on 5.14 or newer triggers the following
SELinux denial:

avc: denied { sys_nice } for comm="init" capability=23
     scontext=u:r:init:s0 tcontext=u:r:init:s0 tclass=capability
     permissive=0

Init is PID 0 running as root, so it already has CAP_SYS_ADMIN. For
better compatibility with older SEPolicy, check ADMIN before NICE.
Seems a bit wonky to me, but the end result is the same. In any case,
this warrants a comment above it detailing why the ordering is
seemingly important.

-- 
Jens Axboe
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help