[PATCH] capabilities: define get_vfs_caps_from_disk when file capsare not enabled

From: Eric Paris
Date: Thu Nov 13 2008 - 18:38:29 EST


When CONFIG_SECURITY_FILE_CAPABILITIES is not set the audit system may
try to call into the capabilities function vfs_cap_from_file. This
patch defines that function so kernels can build and work.

Signed-off-by: Eric Paris <eparis@xxxxxxxxxx>

---

security/commoncap.c | 6 ++++++
1 files changed, 6 insertions(+), 0 deletions(-)

diff --git a/security/commoncap.c b/security/commoncap.c
index 0b88160..574a70b 100644
--- a/security/commoncap.c
+++ b/security/commoncap.c
@@ -337,6 +337,12 @@ int cap_inode_killpriv(struct dentry *dentry)
return 0;
}

+int get_vfs_caps_from_disk(const struct dentry *dentry, struct cpu_vfs_cap_data *cpu_caps)
+{
+ memset(cpu_caps, 0, sizeof(struct cpu_vfs_cap_data));
+ return -ENODATA;
+}
+
static inline int get_file_caps(struct linux_binprm *bprm)
{
bprm_clear_caps(bprm);


--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at http://vger.kernel.org/majordomo-info.html
Please read the FAQ at http://www.tux.org/lkml/