yama: Better permission check for ptraceme
authorEric W. Biederman <ebiederm@xmission.com>
Thu, 21 Mar 2013 09:30:41 +0000 (02:30 -0700)
committerEric W. Biederman <ebiederm@xmission.com>
Tue, 26 Mar 2013 20:17:58 +0000 (13:17 -0700)
commiteddc0a3abff273842a94784d2d022bbc36dc9015
treed1d4eea461dbd3b32e09079f00fccac6fde07e2c
parent751c644b95bb48aaa8825f0c66abbcc184d92051
yama:  Better permission check for ptraceme

Change the permission check for yama_ptrace_ptracee to the standard
ptrace permission check, testing if the traceer has CAP_SYS_PTRACE
in the tracees user namespace.

Reviewed-by: Kees Cook <keescook@chromium.org>
Signed-off-by: "Eric W. Biederman" <ebiederm@xmission.com>
security/yama/yama_lsm.c