From 149b192e376d746bf7b8e1e02541c2256c3b17f0 Mon Sep 17 00:00:00 2001 From: Bill Roberts Date: Mon, 15 Jun 2026 15:03:25 -0500 Subject: [PATCH] lsm: clarify security_task_prctl() hook documentation The task_prctl hook comment incorrectly described the hook as checking whether a prctl operation is allowed. In reality, the hook exists for LSMs to handle LSM-specific prctl operations. Update the function description and kernel-doc comment to reflect the actual behavior. The old wording appears to have been copied from other permission-check hooks despite differing semantics. Signed-off-by: Bill Roberts Acked-by: Casey Schaufler Reviewed-by: Serge Hallyn [PM: subj tweak, comment tweak -> "prctl to prctl()" ] Signed-off-by: Paul Moore --- security/security.c | 5 ++--- 1 file changed, 2 insertions(+), 3 deletions(-) diff --git a/security/security.c b/security/security.c index 71aea8fdf014..2ee276ab15c5 100644 --- a/security/security.c +++ b/security/security.c @@ -3301,15 +3301,14 @@ int security_task_kill(struct task_struct *p, struct kernel_siginfo *info, } /** - * security_task_prctl() - Check if a prctl op is allowed + * security_task_prctl() - Handle an LSM specific prctl() call * @option: operation * @arg2: argument * @arg3: argument * @arg4: argument * @arg5: argument * - * Check permission before performing a process control operation on the - * current process. + * Handle lsm specific prctl() operations. * * Return: Return -ENOSYS if no-one wanted to handle this op, any other value * to cause prctl() to return immediately with that value.