[roll] Roll fuchsia [starnix] Implement CAP_SYS_ADMIN requirement in device-mapper

Verify that the caller of device-mapper ioctls has CAP_SYS_ADMIN in
the effective capability set, returning EACCES (Permission denied) if
missing, matching Linux behavior.

Also updates the device_mapper tests to expect EACCES on Starnix for the
DM_VERSION ioctl when run without capabilities, aligning Starnix
expectations with Linux.

Original-Original-Bug: 516342836
Test: fx test sestarnix_userspace_tests -- --test-filter '*device_mapper*'

TAG: agy
CONV: fa6c90ab-6670-4131-9ed4-aebdea13f459
Original-Original-Reviewed-on: https://fuchsia-review.googlesource.com/c/fuchsia/+/1685554
Original-Original-Revision: 37c694a396a407b231081767e0543cdf834c641d
GitOrigin-RevId: 6e7d37c25d8d854f9069be2c659da626ec5103b0
Change-Id: Ia87cd1df5f42f11309f16128b8ea967b6230687c
Reviewed-on: https://fuchsia-review.googlesource.com/c/integration/+/1695794
Cr-Commit-Position: refs/heads/main@{#196245}
1 file changed
tree: fa1c0d1392c2c5e221dd9e07ee1e3f8e3cfd9c45
  1. ctf/
  2. git-hooks/
  3. infra/
  4. third_party/
  5. cobalt
  6. flower
  7. jiri.lock
  8. MILESTONE
  9. minimal
  10. prebuilts
  11. README.md
  12. stem
  13. test_durations
README.md

Integration

This repository contains Fuchsia's Global Integration manifest files.

Making changes

All changes should be made to the internal version of this repository. Our infrastructure automatically updates this version when the internal one changes.

Currently all changes must be made by a Google employee. Non-Google employees wishing to make a change can ask for assistance in one of the communication channels documented at get involved.

Obtaining the source

First install Jiri.

Next run:

$ jiri init
$ jiri import minimal https://fuchsia.googlesource.com/integration
$ jiri update

Third party

Third party projects should have their own subdirectory in ./third_party.