diff options
author | Omar Polo <op@omarpolo.com> | 2022-02-10 22:29:51 +0000 |
---|---|---|
committer | Omar Polo <op@omarpolo.com> | 2022-02-10 22:29:51 +0000 |
commit | 98c6f8de41647ba565dcbdaccf876277b404161e (patch) | |
tree | 39a6226c6d8a24a36e99a0bab2cae4d1b2bf46d0 /compat/reallocarray.c | |
parent | be88c5d657e2a2e0a2a9f6d75910e5f08ec5e755 (diff) |
fix landlock usage
Mickaël Salaün, the landlock author, pointed out the same error on the
got implementation. The assumption that not listed access
capabilities are implicitly denied is completely wrong:
> In a nutshell, the ruleset's handled_access_fs is required for
> backward and forward compatibility (i.e. the kernel and user space may
> not know each other's supported restrictions), hence the need to be
> explicit about the denied-by-default access rights.
Diffstat (limited to 'compat/reallocarray.c')
0 files changed, 0 insertions, 0 deletions