summaryrefslogtreecommitdiffstats
path: root/sys-kernel/boest-v4.18.14/0008-fs-Enable-link-security-restrictions-by-default.patch
blob: d1b1d0592b71f85f680dd2397fe286d13a7415c4 (plain) (blame)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
From 79933042879fff56f3c93c25d42f8e45120e93ae Mon Sep 17 00:00:00 2001
From: Ben Hutchings <ben@decadent.org.uk>
Date: Fri, 2 Nov 2012 05:32:06 +0000
Subject: [PATCH 08/14] fs: Enable link security restrictions by default

This reverts commit 561ec64ae67ef25cac8d72bb9c4bfc955edfd415
('VFS: don't do protected {sym,hard}links by default').
---
 fs/namei.c | 4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)


diff --git a/fs/namei.c b/fs/namei.c
index 734cef54fdf8..8e3b3ae0cf30 100644
--- a/fs/namei.c
+++ b/fs/namei.c
@@ -885,8 +885,8 @@ static inline void put_link(struct nameidata *nd)
 		path_put(&last->link);
 }

 
-int sysctl_protected_symlinks __read_mostly = 0;
-int sysctl_protected_hardlinks __read_mostly = 0;
+int sysctl_protected_symlinks __read_mostly = 1;
+int sysctl_protected_hardlinks __read_mostly = 1;
 
 /**
  * may_follow_link - Check symlink following for unsafe situations