Skip to content

Commit 4d643b6

Browse files
Niklas Casselaxboe
authored andcommitted
blk-zoned: allow BLKREPORTZONE without CAP_SYS_ADMIN
A user space process should not need the CAP_SYS_ADMIN capability set in order to perform a BLKREPORTZONE ioctl. Getting the zone report is required in order to get the write pointer. Neither read() nor write() requires CAP_SYS_ADMIN, so it is reasonable that a user space process that can read/write from/to the device, also can get the write pointer. (Since e.g. writes have to be at the write pointer.) Fixes: 3ed05a9 ("blk-zoned: implement ioctls") Signed-off-by: Niklas Cassel <[email protected]> Reviewed-by: Damien Le Moal <[email protected]> Reviewed-by: Aravind Ramesh <[email protected]> Reviewed-by: Adam Manzanares <[email protected]> Reviewed-by: Himanshu Madhani <[email protected]> Reviewed-by: Johannes Thumshirn <[email protected]> Cc: [email protected] # v4.10+ Link: https://lore.kernel.org/r/[email protected] Signed-off-by: Jens Axboe <[email protected]>
1 parent ead3b76 commit 4d643b6

File tree

1 file changed

+0
-3
lines changed

1 file changed

+0
-3
lines changed

block/blk-zoned.c

Lines changed: 0 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -360,9 +360,6 @@ int blkdev_report_zones_ioctl(struct block_device *bdev, fmode_t mode,
360360
if (!blk_queue_is_zoned(q))
361361
return -ENOTTY;
362362

363-
if (!capable(CAP_SYS_ADMIN))
364-
return -EACCES;
365-
366363
if (copy_from_user(&rep, argp, sizeof(struct blk_zone_report)))
367364
return -EFAULT;
368365

0 commit comments

Comments
 (0)