diff options
| author | Biswajit Paul <biswajitpaul@codeaurora.org> | 2015-02-09 15:21:12 -0800 |
|---|---|---|
| committer | ShevT <shev_t@mail.ru> | 2016-08-22 14:42:24 +0300 |
| commit | c91f08c566a5ee9bb58cb72f88c38801e747c466 (patch) | |
| tree | 005ef3de351f3bee7dae879b73dcd79a00cadd05 | |
| parent | ce7ad1f8378eec5d0157cafced1a706a49e1290b (diff) | |
kernel: Restrict permissions of /proc/iomem.
The permissions of /proc/iomem currently are -r--r--r--. Everyone can
see its content. As iomem contains information about the physical memory
content of the device, restrict the information only to root.
Change-Id: If0be35c3fac5274151bea87b738a48e6ec0ae891
CRs-Fixed: 786116
Signed-off-by: Biswajit Paul <biswajitpaul@codeaurora.org>
Signed-off-by: Avijit Kanti Das <avijitnsec@codeaurora.org>
| -rw-r--r-- | kernel/resource.c | 2 |
1 files changed, 1 insertions, 1 deletions
diff --git a/kernel/resource.c b/kernel/resource.c index d7386986e..ffda5adb7 100644 --- a/kernel/resource.c +++ b/kernel/resource.c @@ -153,7 +153,7 @@ static const struct file_operations proc_iomem_operations = { static int __init ioresources_init(void) { proc_create("ioports", 0, NULL, &proc_ioports_operations); - proc_create("iomem", 0, NULL, &proc_iomem_operations); + proc_create("iomem", S_IRUSR, NULL, &proc_iomem_operations); return 0; } __initcall(ioresources_init); |
