Home
last modified time | relevance | path

Searched refs:capable (Results 1 – 15 of 15) sorted by relevance

/security/
Dmin_addr.c37 if (write && !capable(CAP_SYS_RAWIO)) in mmap_min_addr_handler()
Dcommoncap.c113 if (!capable(CAP_SYS_TIME)) in cap_settime()
1345 LSM_HOOK_INIT(capable, cap_capable),
Ddevice_cgroup.c604 if (!capable(CAP_SYS_ADMIN)) in devcgroup_update_access()
Dsecurity.c729 return call_int_hook(capable, 0, cred, ns, cap, opts); in security_capable()
/security/integrity/evm/
Devm_secfs.c73 if (!capable(CAP_SYS_ADMIN) || (evm_initialized & EVM_SETUP_COMPLETE)) in evm_write_key()
183 if (!capable(CAP_SYS_ADMIN) || evm_xattrs_locked) in evm_write_xattrs()
Devm_main.c319 if (!capable(CAP_SYS_ADMIN)) in evm_protect_xattr()
/security/safesetid/
Dlsm.c154 LSM_HOOK_INIT(capable, safesetid_security_capable)
/security/keys/
Dkeyctl.c434 if (capable(CAP_SYS_ADMIN)) { in keyctl_invalidate_key()
479 if (capable(CAP_SYS_ADMIN)) { in keyctl_keyring_clear()
914 if (!capable(CAP_SYS_ADMIN)) { in keyctl_chown_key()
1021 if (capable(CAP_SYS_ADMIN) || uid_eq(key->uid, current_fsuid())) { in keyctl_setperm_key()
Dtrusted.c389 if (!capable(CAP_SYS_ADMIN)) in pcrlock()
/security/apparmor/
Dpolicy.c665 bool capable = ns_capable(user_ns, CAP_MAC_ADMIN); in policy_admin_capable() local
667 AA_DEBUG("cap_mac_admin? %d\n", capable); in policy_admin_capable()
670 return policy_view_capable(ns) && capable && !aa_g_lock_policy; in policy_admin_capable()
Dlsm.c1158 LSM_HOOK_INIT(capable, apparmor_capable),
/security/yama/
Dyama_lsm.c437 if (write && !capable(CAP_SYS_PTRACE)) in yama_dointvec_minmax()
/security/integrity/ima/
Dima_fs.c392 if (!capable(CAP_SYS_ADMIN)) in ima_open_policy()
Dima_appraise.c486 if (!capable(CAP_SYS_ADMIN)) in ima_protect_xattr()
/security/selinux/
Dhooks.c6873 LSM_HOOK_INIT(capable, selinux_capable),