exec: Consolidate dumpability logic
Since it's already valid to set dumpability in the early part of setup_new_exec(), we can consolidate the logic into a single place. The BINPRM_FLAGS_ENFORCE_NONDUMP is set during would_dump() calls before setup_new_exec(), so its test is safe to move as well. Signed-off-by: Kees Cook <keescook@chromium.org> Acked-by: Serge Hallyn <serge@hallyn.com> Reviewed-by: James Morris <james.l.morris@oracle.com>
This commit is contained in:
parent
35b372b76f
commit
473d89639d
11
fs/exec.c
11
fs/exec.c
@ -1354,10 +1354,12 @@ void setup_new_exec(struct linux_binprm * bprm)
|
|||||||
|
|
||||||
current->sas_ss_sp = current->sas_ss_size = 0;
|
current->sas_ss_sp = current->sas_ss_size = 0;
|
||||||
|
|
||||||
if (!bprm->secureexec)
|
/* Figure out dumpability. */
|
||||||
set_dumpable(current->mm, SUID_DUMP_USER);
|
if (bprm->interp_flags & BINPRM_FLAGS_ENFORCE_NONDUMP ||
|
||||||
else
|
bprm->secureexec)
|
||||||
set_dumpable(current->mm, suid_dumpable);
|
set_dumpable(current->mm, suid_dumpable);
|
||||||
|
else
|
||||||
|
set_dumpable(current->mm, SUID_DUMP_USER);
|
||||||
|
|
||||||
arch_setup_new_exec();
|
arch_setup_new_exec();
|
||||||
perf_event_exec();
|
perf_event_exec();
|
||||||
@ -1371,9 +1373,6 @@ void setup_new_exec(struct linux_binprm * bprm)
|
|||||||
|
|
||||||
if (bprm->secureexec) {
|
if (bprm->secureexec) {
|
||||||
current->pdeath_signal = 0;
|
current->pdeath_signal = 0;
|
||||||
} else {
|
|
||||||
if (bprm->interp_flags & BINPRM_FLAGS_ENFORCE_NONDUMP)
|
|
||||||
set_dumpable(current->mm, suid_dumpable);
|
|
||||||
}
|
}
|
||||||
|
|
||||||
/* An exec changes our domain. We are no longer part of the thread
|
/* An exec changes our domain. We are no longer part of the thread
|
||||||
|
Loading…
Reference in New Issue
Block a user