summaryrefslogtreecommitdiffstats
path: root/net
diff options
context:
space:
mode:
authorChenbo Feng <fengc@google.com>2017-05-31 18:16:00 -0700
committerDavid S. Miller <davem@davemloft.net>2017-06-02 14:24:40 -0400
commit80b7d81912d807f161d55e9c2c9cc81061666f83 (patch)
treea37d8f96dc9e71aedb6528138208bde42fbabf61 /net
parentfb9a307d11d62749d75b404f15517d73f5d6e148 (diff)
downloadlinux-stable-80b7d81912d807f161d55e9c2c9cc81061666f83.tar.gz
linux-stable-80b7d81912d807f161d55e9c2c9cc81061666f83.tar.bz2
linux-stable-80b7d81912d807f161d55e9c2c9cc81061666f83.zip
bpf: Remove the capability check for cgroup skb eBPF program
Currently loading a cgroup skb eBPF program require a CAP_SYS_ADMIN capability while attaching the program to a cgroup only requires the user have CAP_NET_ADMIN privilege. We can escape the capability check when load the program just like socket filter program to make the capability requirement consistent. Change since v1: Change the code style in order to be compliant with checkpatch.pl preference Signed-off-by: Chenbo Feng <fengc@google.com> Acked-by: Alexei Starovoitov <ast@kernel.org> Signed-off-by: David S. Miller <davem@davemloft.net>
Diffstat (limited to 'net')
0 files changed, 0 insertions, 0 deletions