• Nicholas Bishop's avatar
    efi/esrt: Allow ESRT access without CAP_SYS_ADMIN · d0a1865c
    Nicholas Bishop authored
    Access to the files in /sys/firmware/efi/esrt has been restricted to
    CAP_SYS_ADMIN since support for ESRT was added, but this seems overly
    restrictive given that the files are read-only and just provide
    information about UEFI firmware updates.
    
    Remove the CAP_SYS_ADMIN restriction so that a non-root process can read
    the files, provided a suitably-privileged process changes the file
    ownership first. The files are still read-only and still owned by root
    by default.
    Signed-off-by: default avatarNicholas Bishop <nicholasbishop@google.com>
    Signed-off-by: default avatarArd Biesheuvel <ardb@kernel.org>
    d0a1865c
esrt.c 10.4 KB