Return-Path: Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1754267AbbEZQXS (ORCPT ); Tue, 26 May 2015 12:23:18 -0400 Received: from resqmta-ch2-08v.sys.comcast.net ([69.252.207.40]:33873 "EHLO resqmta-ch2-08v.sys.comcast.net" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1752963AbbEZQXN (ORCPT ); Tue, 26 May 2015 12:23:13 -0400 Date: Tue, 26 May 2015 11:23:10 -0500 (CDT) From: Christoph Lameter X-X-Sender: cl@gentwo.org To: Serge Hallyn cc: Andy Lutomirski , Serge Hallyn , Andrew Morton , Jarkko Sakkinen , "Ted Ts'o" , "Andrew G. Morgan" , Linux API , Mimi Zohar , Michael Kerrisk , Austin S Hemmelgarn , linux-security-module , Aaron Jones , Serge Hallyn , LKML , Markku Savela , Kees Cook , Jonathan Corbet , Andy Lutomirski Subject: Re: [PATCH v2 1/2] capabilities: Ambient capabilities In-Reply-To: <20150523193705.GA30563@mail.hallyn.com> Message-ID: References: <20150523193705.GA30563@mail.hallyn.com> Content-Type: TEXT/PLAIN; charset=US-ASCII Sender: linux-kernel-owner@vger.kernel.org List-ID: X-Mailing-List: linux-kernel@vger.kernel.org Content-Length: 713 Lines: 18 On Sat, 23 May 2015, Serge Hallyn wrote: > > You cannot use pA to try to subvert a setuid, setgid, or file-capped > > program: if you execute any such program, pA gets cleared and the > > resulting evolution rules are unchanged by this patch. > > Christoph, just to be sure, is this ^ going to suffice for you? > > Seems like it should since any program which is setuid-root, i.e. > passwd, isn't likely to be designed to exec other programs. Yes that should work. -- To unsubscribe from this list: send the line "unsubscribe linux-kernel" in the body of a message to majordomo@vger.kernel.org More majordomo info at http://vger.kernel.org/majordomo-info.html Please read the FAQ at http://www.tux.org/lkml/