Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
cgroup-v1: Require capabilities to set release_agent
ANBZ: torvalds#432 commit 12e1ce08da69be233d6827856c0f282da1023bb5 amazonlinux. The cgroup release_agent is called with call_usermodehelper. The function call_usermodehelper starts the release_agent with a full set fo capabilities. Therefore require capabilities when setting the release_agaent. Reported-by: Tabitha Sable <tabitha.c.sable@gmail.com> Tested-by: Tabitha Sable <tabitha.c.sable@gmail.com> Fixes: 81a6a5c ("Task Control Groups: automatic userspace notification of idle cgroups") Cc: stable@vger.kernel.org # v2.6.24+ Signed-off-by: "Eric W. Biederman" <ebiederm@xmission.com> Signed-off-by: Tejun Heo <tj@kernel.org> [fllinden: modified for 4.14 for the mount options path, by looking up the right user namespace (like the fs context code) and passing it to parse_cgroupfs_options for a check] Signed-off-by: Frank van der Linden <fllinden@amazon.com> Signed-off-by: Tianchen Ding <dtcccc@linux.alibaba.com> Acked-by: Michael Wang <yun.wang@linux.alibaba.com>
- Loading branch information