Home
last modified time | relevance | path

Searched refs:capable (Results 1 – 15 of 15) sorted by relevance

/security/
Dmin_addr.c37 if (write && !capable(CAP_SYS_RAWIO)) in mmap_min_addr_handler()
Dcommoncap.c114 if (!capable(CAP_SYS_TIME)) in cap_settime()
1452 LSM_HOOK_INIT(capable, cap_capable),
Ddevice_cgroup.c619 if (!capable(CAP_SYS_ADMIN)) in devcgroup_update_access()
Dsecurity.c808 return call_int_hook(capable, 0, cred, ns, cap, opts); in security_capable()
/security/integrity/evm/
Devm_secfs.c72 if (!capable(CAP_SYS_ADMIN) || (evm_initialized & EVM_SETUP_COMPLETE)) in evm_write_key()
189 if (!capable(CAP_SYS_ADMIN) || evm_xattrs_locked) in evm_write_xattrs()
Devm_main.c548 if (!capable(CAP_SYS_ADMIN)) in evm_protect_xattr()
/security/safesetid/
Dlsm.c247 LSM_HOOK_INIT(capable, safesetid_security_capable)
/security/apparmor/
Dpolicy.c666 bool capable = ns_capable(user_ns, CAP_MAC_ADMIN); in policy_admin_capable() local
668 AA_DEBUG("cap_mac_admin? %d\n", capable); in policy_admin_capable()
671 return policy_view_capable(ns) && capable && !aa_g_lock_policy; in policy_admin_capable()
Dlsm.c1185 LSM_HOOK_INIT(capable, apparmor_capable),
/security/keys/
Dkeyctl.c433 if (capable(CAP_SYS_ADMIN)) { in keyctl_invalidate_key()
478 if (capable(CAP_SYS_ADMIN)) { in keyctl_keyring_clear()
995 if (is_privileged_op && !capable(CAP_SYS_ADMIN)) in keyctl_chown_key()
1096 if (uid_eq(key->uid, current_fsuid()) || capable(CAP_SYS_ADMIN)) { in keyctl_setperm_key()
/security/yama/
Dyama_lsm.c437 if (write && !capable(CAP_SYS_PTRACE)) in yama_dointvec_minmax()
/security/integrity/ima/
Dima_fs.c393 if (!capable(CAP_SYS_ADMIN)) in ima_open_policy()
Dima_appraise.c556 if (!capable(CAP_SYS_ADMIN)) in ima_protect_xattr()
/security/keys/trusted-keys/
Dtrusted_tpm1.c382 if (!capable(CAP_SYS_ADMIN)) in pcrlock()
/security/selinux/
Dhooks.c7176 LSM_HOOK_INIT(capable, selinux_capable),