diff options
| author | Alice Ryhl <aliceryhl@google.com> | 2026-07-03 06:57:02 +0000 |
|---|---|---|
| committer | Paul Moore <paul@paul-moore.com> | 2026-07-07 15:10:48 -0400 |
| commit | 15c1f17979712407a4a71f2129f89ecd625ccbe8 (patch) | |
| tree | 4c64b96ef8dd541ad505e1b5bac6e81b4e5ad630 /Documentation/security | |
| parent | ef2d3e4635761b0af2bf1b89a2252e42a3bf37f1 (diff) | |
| download | linux-next-15c1f17979712407a4a71f2129f89ecd625ccbe8.tar.gz linux-next-15c1f17979712407a4a71f2129f89ecd625ccbe8.zip | |
cred: delete task_euid()
task_euid() is a very weird operation. You can see how weird it is by
grepping for task_euid() - binder is its only user. task_euid() obtains
the objective effective UID - it looks at the credentials of the task
for purposes of acting on it as an object, but then accesses the
effective UID (which the credentials.7 man page describes as "[...] used
by the kernel to determine the permissions that the process will have
when accessing shared resources [...]").
Since usage in Binder has now been removed, get rid of the resulting
dead code.
Changes to the zh_CN translation was carried out with the help of
Gemini and Google Translate, and since adjusted as per Alex Shi's
feedback.
Suggested-by: Jann Horn <jannh@google.com>
Reviewed-by: Gary Guo <gary@garyguo.net>
Signed-off-by: Alice Ryhl <aliceryhl@google.com>
Signed-off-by: Paul Moore <paul@paul-moore.com>
Diffstat (limited to 'Documentation/security')
| -rw-r--r-- | Documentation/security/credentials.rst | 6 |
1 files changed, 2 insertions, 4 deletions
diff --git a/Documentation/security/credentials.rst b/Documentation/security/credentials.rst index 4996838491b1..a39a2a2f67aa 100644 --- a/Documentation/security/credentials.rst +++ b/Documentation/security/credentials.rst @@ -393,16 +393,14 @@ the credentials so obtained when they're finished with. The result of ``__task_cred()`` should not be passed directly to ``get_cred()`` as this may race with ``commit_cred()``. -There are a couple of convenience functions to access bits of another task's -credentials, hiding the RCU magic from the caller:: +There is a convenience function to access bits of another task's credentials, +hiding the RCU magic from the caller:: uid_t task_uid(task) Task's real UID - uid_t task_euid(task) Task's effective UID If the caller is holding the RCU read lock at the time anyway, then:: __task_cred(task)->uid - __task_cred(task)->euid should be used instead. Similarly, if multiple aspects of a task's credentials need to be accessed, RCU read lock should be used, ``__task_cred()`` called, |
