Received: by 2002:ac0:a5b6:0:0:0:0:0 with SMTP id m51-v6csp693760imm; Sat, 26 May 2018 08:49:15 -0700 (PDT) X-Google-Smtp-Source: AB8JxZoorxy0CkfOIRd1IEtDzoSPjnzu5EizZzX87pivbhXHzAN/oc27ksES4YwGC1I3I1rpHwHI X-Received: by 2002:a17:902:9a06:: with SMTP id v6-v6mr6935964plp.21.1527349755511; Sat, 26 May 2018 08:49:15 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1527349755; cv=none; d=google.com; s=arc-20160816; b=HuKZ9BHl3Uq9dqDihJ0+iZ/6qz3h/vdUtfXvEintZWVz94a0SvkPNfCgdbtk74yCa6 AppwrRBoyOm2159Di608Mkix3Ff66nNj1H2NozPrq/TynG8D1ZP7cDWQcyHC3JskbWY4 wIzlFRHDw+rrzDPz0zLhEwK4NoklrBrpp2HSw511y6cO7ej3VTl4qPETFwnjaac3MlBR k0RyAAZENszcL9cTL17fd28wNJbIfXZnm7Z5dGSyPnaF9H2UKVHV+Px5QmPV8qm14ZLu Hq+16gfx67Bg3diWFSrvLhOllQ5iLkInpQQrYDWd67SHoo6tAEYdoVPWezgs1X7yMYOv k3aQ== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:sender:user-agent:in-reply-to :content-disposition:mime-version:references:message-id:subject:cc :to:from:date:dkim-signature:arc-authentication-results; bh=Vw7b0QaQXV8iLgqFGmnCFAoRgomeVqfe1psySd5n+uA=; b=WHRwBgJ1qqojGqE4QQ00Ag4yYTgIsDa1lrF3QIhtQk8IN2umqv0tO7wSbbBOZKdZ6n VyPJmH25JFX1NBqcXdfHtZ+ZIhp1NMEjMRNNfye9NePZS0S19jn1LINn7bJ3LhHE8+tJ x0UapDpFh6EqhCjq8bELLvrSeOvkMfOssN77YFhrcvmKUfW5T60y69jVvG+ocbllnTV5 +k01xoCTT2GUFNY0+XoNPcrNEMA6UAogYzFaiCkCX1zwkCOPN8YWWNLRa5tv5NBiNvJV 3cUKYRo6BtE77fkY7oqoj4FcA5hpVJJIBxAoRQ4QwyCbkfJIhA0gjFim0r600CZTDpIS mhbw== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@gmail.com header.s=20161025 header.b=D8hyC/XW; spf=pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=NONE sp=QUARANTINE dis=NONE) header.from=gmail.com Return-Path: Received: from vger.kernel.org (vger.kernel.org. [209.132.180.67]) by mx.google.com with ESMTP id g67-v6si27009700pfe.4.2018.05.26.08.49.01; Sat, 26 May 2018 08:49:15 -0700 (PDT) Received-SPF: pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) client-ip=209.132.180.67; Authentication-Results: mx.google.com; dkim=pass header.i=@gmail.com header.s=20161025 header.b=D8hyC/XW; spf=pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=NONE sp=QUARANTINE dis=NONE) header.from=gmail.com Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1032144AbeEZPsY (ORCPT + 99 others); Sat, 26 May 2018 11:48:24 -0400 Received: from mail-wr0-f195.google.com ([209.85.128.195]:43744 "EHLO mail-wr0-f195.google.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1032125AbeEZPsX (ORCPT ); Sat, 26 May 2018 11:48:23 -0400 Received: by mail-wr0-f195.google.com with SMTP id r13-v6so13790030wrj.10; Sat, 26 May 2018 08:48:22 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=date:from:to:cc:subject:message-id:references:mime-version :content-disposition:in-reply-to:user-agent; bh=Vw7b0QaQXV8iLgqFGmnCFAoRgomeVqfe1psySd5n+uA=; b=D8hyC/XWvQpkNeNYppwo6xMUUUIkjsNuxGuf/uURfOW441fUmrJfcyYn8INPlLjb89 XIIJENipFdTHtLo6MUaIzk42bBxcs+5z/aQxg83s6moSGNPcvgnB3vxpVlVE0/gd557g ytNCZcZHFQQHg9FtupuW60SNszil7p0VGMbVmSxGECNWDNPZ1B+iPh4vqpOjmgVIVe2D 4QemVm3LcXw8B4lxUz+AKCSShnZ0l+rZPfR6xYckvAmR9J3wR80VXhBoEEXpToLX6pwu V/fNX2271TI+wijwHLGnG6NdQ7Y45OLb5YwD47zNZuljmAFILyF97eW1Q1ZODXQWba4i FFsQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:date:from:to:cc:subject:message-id:references :mime-version:content-disposition:in-reply-to:user-agent; bh=Vw7b0QaQXV8iLgqFGmnCFAoRgomeVqfe1psySd5n+uA=; b=Y7vp68j9uo0kzHpQ6QD+6RD3JEExLU6FTToshBrvrGT7yfvIIlGpLnLz2ewY57HNai El1k5k8BlVSF69ItG7JEvsDx94FEmBAF12HcPJ79jdon3T4hQqOdTSM58HzlCXbVxFGH 31VyREheoq05tw8S41ah8fyKtx/hnyNNULnH7KFcXMLqxmfkfS8m4H9sN+d0i5ggZnNr OZYSx1wibrQ2vFWSRbINGAUQjXWIogkgY73xjc03n1WjqNcT0nL2UbHMqSgVYkeP+dum QT4ICT2T1/Cjnar/1Lw0gJ//1OQYbsV1VN3sLhbgQhFgljbheIhbKc56EUtVCo6Mv7Zs 9tnA== X-Gm-Message-State: ALKqPwdrVkbnBOhjCAysbYqV5WrJzyY4BE9uj5oXB+wMHlYn8iyi7waJ dqbanXOA/8Kngo0JmOgZBQ== X-Received: by 2002:adf:e2d2:: with SMTP id d18-v6mr5004731wrj.54.1527349702313; Sat, 26 May 2018 08:48:22 -0700 (PDT) Received: from avx2 (nat4-minsk-pool-46-53-177-92.telecom.by. [46.53.177.92]) by smtp.gmail.com with ESMTPSA id x65-v6sm9585934wme.31.2018.05.26.08.48.20 (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Sat, 26 May 2018 08:48:21 -0700 (PDT) Date: Sat, 26 May 2018 18:48:19 +0300 From: Alexey Dobriyan To: Salvatore Mesoraca Cc: kernel-hardening@lists.openwall.com, linux-security-module@vger.kernel.org, linux-kernel@vger.kernel.org, linux-mm@kvack.org, Andrew Morton , Akinobu Mita , Dmitry Vyukov , Arnd Bergmann , Davidlohr Bueso , Kees Cook Subject: Re: [PATCH] proc: prevent a task from writing on its own /proc/*/mem Message-ID: <20180526154819.GA14016@avx2> References: <1527346246-1334-1-git-send-email-s.mesoraca16@gmail.com> MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Disposition: inline In-Reply-To: <1527346246-1334-1-git-send-email-s.mesoraca16@gmail.com> User-Agent: Mutt/1.9.4 (2018-02-28) Sender: linux-kernel-owner@vger.kernel.org Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org On Sat, May 26, 2018 at 04:50:46PM +0200, Salvatore Mesoraca wrote: > Prevent a task from opening, in "write" mode, any /proc/*/mem > file that operates on the task's mm. > /proc/*/mem is mainly a debugging means and, as such, it shouldn't > be used by the inspected process itself. > Current implementation always allow a task to access its own > /proc/*/mem file. > A process can use it to overwrite read-only memory, making > pointless the use of security_file_mprotect() or other ways to > enforce RO memory. You can do it in security_ptrace_access_check() or security_file_open()