[RFC PATCH v2 1/3] capability: Move mk_kernel_cap() to header

Jinjie Ruan ruanjinjie at huawei.com
Tue Sep 29 13:01:58 UTC 2026


Move mk_kernel_cap() from capability.c to the capability header file
so that it can be reused by other security modules.

No functional change.

Signed-off-by: Jinjie Ruan <ruanjinjie at huawei.com>
---
 include/linux/capability.h | 5 +++++
 kernel/capability.c        | 5 -----
 2 files changed, 5 insertions(+), 5 deletions(-)

diff --git a/include/linux/capability.h b/include/linux/capability.h
index f8532d92fcad..7921a0b3b04a 100644
--- a/include/linux/capability.h
+++ b/include/linux/capability.h
@@ -114,6 +114,11 @@ static inline bool cap_issubset(const kernel_cap_t a, const kernel_cap_t set)
 	return !(a.val & ~set.val);
 }
 
+static inline kernel_cap_t mk_kernel_cap(u32 low, u32 high)
+{
+	return (kernel_cap_t) { (low | ((u64)high << 32)) & CAP_VALID_MASK };
+}
+
 /* Used to decide between falling back on the old suser() or fsuser(). */
 
 static inline kernel_cap_t cap_drop_fs_set(const kernel_cap_t a)
diff --git a/kernel/capability.c b/kernel/capability.c
index 90e6ab62f6db..0b8ec26ead0e 100644
--- a/kernel/capability.c
+++ b/kernel/capability.c
@@ -190,11 +190,6 @@ SYSCALL_DEFINE2(capget, cap_user_header_t, header, cap_user_data_t, dataptr)
 	return 0;
 }
 
-static kernel_cap_t mk_kernel_cap(u32 low, u32 high)
-{
-	return (kernel_cap_t) { (low | ((u64)high << 32)) & CAP_VALID_MASK };
-}
-
 /**
  * sys_capset - set capabilities for a process or (*) a group of processes
  * @header: pointer to struct that contains capability version and
-- 
2.34.1




More information about the Linux-security-module-archive mailing list