diff mbox

[2/2] debugfs: only allow root access to debugging interfaces

Message ID 1298399317-19508-3-git-send-email-kees.cook@canonical.com
State Accepted
Headers show

Commit Message

Kees Cook Feb. 22, 2011, 6:28 p.m. UTC
Block access to the potentially dangerous debugging interfaces in
the debugfs filesystem.

Signed-off-by: Kees Cook <kees.cook@canonical.com>
---
 fs/debugfs/inode.c |    2 +-
 1 files changed, 1 insertions(+), 1 deletions(-)
diff mbox

Patch

diff --git a/fs/debugfs/inode.c b/fs/debugfs/inode.c
index 3cb33c3..83c61a3 100644
--- a/fs/debugfs/inode.c
+++ b/fs/debugfs/inode.c
@@ -133,7 +133,7 @@  static int debug_fill_super(struct super_block *sb, void *data, int silent)
 	static struct tree_descr debug_files[] = {{""}};
 
 	return simple_fill_super(sb, DEBUGFS_MAGIC, debug_files,
-				 S_IWUSR | S_IRUGO | S_IXUGO);
+				 S_IRWXU);
 }
 
 static struct dentry *debug_mount(struct file_system_type *fs_type,