From: Karol Lewandowski Date: Fri, 7 Aug 2020 11:49:30 +0000 (+0200) Subject: WORKAROUND: security: smack: Allow ptracing even processes in onlycap set X-Git-Tag: submit/tizen/20200810.050403^0 X-Git-Url: http://review.tizen.org/git/?a=commitdiff_plain;h=refs%2Fchanges%2F09%2F240609%2F1;p=platform%2Fkernel%2Flinux-rpi3.git WORKAROUND: security: smack: Allow ptracing even processes in onlycap set Change-Id: I708d19703da0f1b83950454fda1362bec7369b5c Signed-off-by: Karol Lewandowski Signed-off-by: Seung-Woo Kim --- diff --git a/security/smack/smack_lsm.c b/security/smack/smack_lsm.c index 017c47eb795e..a4405f4f12c8 100644 --- a/security/smack/smack_lsm.c +++ b/security/smack/smack_lsm.c @@ -441,6 +441,8 @@ static int smk_ptrace_rule_check(struct task_struct *tracer, rc = 0; else if (smack_ptrace_rule == SMACK_PTRACE_DRACONIAN) rc = -EACCES; + else if (smack_ptrace_rule == SMACK_PTRACE_EXACT) + rc = capable(CAP_SYS_PTRACE) != 0 ? 0 : -EACCES; else if (smack_privileged_cred(CAP_SYS_PTRACE, tracercred)) rc = 0; else