Received: by 2002:ad5:474a:0:0:0:0:0 with SMTP id i10csp436070imu; Tue, 27 Nov 2018 14:58:12 -0800 (PST) X-Google-Smtp-Source: AFSGD/VwHiJsszQuqy/HsNW0kTQyn73qExg9DNVwpfpbbEf9JStXY4VqR9vn/LKXCavOLyZNUN2q X-Received: by 2002:a17:902:be0c:: with SMTP id r12mr21297553pls.299.1543359492434; Tue, 27 Nov 2018 14:58:12 -0800 (PST) ARC-Seal: i=1; a=rsa-sha256; t=1543359492; cv=none; d=google.com; s=arc-20160816; b=sCWdmYtzNiQSFkAcuSFEKyN1Kxt8u/Kd6TKUVp5QL6zD8Zq48qyzsnxOVCe8uR4ci5 iAnpt6+tni5/mAnnD9z2tWk8br88k6j3E2Ndfl8o2Bn/TypA+01suZcE9nGPbYOQh8B6 R0CSsGbbnKK7xJ/q94djCuYP99KSbCvmMFqbz7/GhTgivaTy2sx71DTD/+D+QEnCWLzr B0IkABbw7ypr40UXUyPoc6COMu4kvY2uQTCKTCsjew2GcBX7sPhlagot+ER++aeUWvHr de4bOgqJ9NFBsxX37jAumTo4lOcBBzrfC8PDd8o0Rei7Io4nzxWxLNlPtzzSXlb09MCN P8EA== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:sender:content-transfer-encoding:mime-version :message-id:date:subject:cc:to:from; bh=eTN9gpZ7cym5VsgsUy3g0SA0iBP+w2VoRS/EUtd65mE=; b=ep+Oev/wTBAWMzQDTqM6yHvXCjiJHzZB7RWc8V5Zg8dtmzqlKIRH2LGZg2wJAIFcBd T+SrA1nljev5H9hvvG6CuVoQIBMMWFdxrPDRm8gGXrBsEYdejdMmPgck1JHMivWmfIqO TkRCosEdP2bqwAWIpC0fGYEG/oVEfJ9913TL/WuiJvgykt397gazHcCwChw4T4I3y3QF 39qf6pf+NgkfdBTgARNz+IgjQJ7TvJtnm2rh8uaFxWIW0APXc1gC+mZlfxksKkMDaEEQ IwKwctSGqENtz2V1bDEY4hhXuAwD9Qeq9wgtokU6lGbLP7G0Fd6PLjW1kvlduYQaaBYo +4hQ== ARC-Authentication-Results: i=1; mx.google.com; spf=pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org Return-Path: Received: from vger.kernel.org (vger.kernel.org. [209.132.180.67]) by mx.google.com with ESMTP id w16si4969616pga.328.2018.11.27.14.57.57; Tue, 27 Nov 2018 14:58:12 -0800 (PST) Received-SPF: pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) client-ip=209.132.180.67; Authentication-Results: mx.google.com; spf=pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1726802AbeK1Jye (ORCPT + 99 others); Wed, 28 Nov 2018 04:54:34 -0500 Received: from nov-007-i656.relay.mailchannels.net ([46.232.183.210]:49108 "EHLO nov-007-i656.relay.mailchannels.net" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1726445AbeK1Jyd (ORCPT ); Wed, 28 Nov 2018 04:54:33 -0500 X-Sender-Id: novatrend|x-authuser|juerg@bitron.ch Received: from relay.mailchannels.net (localhost [127.0.0.1]) by relay.mailchannels.net (Postfix) with ESMTP id D1D4EBE04A3; Tue, 27 Nov 2018 22:55:02 +0000 (UTC) Received: from srv17.tophost.ch (localhost [127.0.0.1]) by relay.mailchannels.net (Postfix) with ESMTPA id 89F58BE02D8; Tue, 27 Nov 2018 22:54:59 +0000 (UTC) X-Sender-Id: novatrend|x-authuser|juerg@bitron.ch Received: from srv17.tophost.ch (srv17.tophost.ch [193.33.128.141]) (using TLSv1.2 with cipher DHE-RSA-AES256-GCM-SHA384) by 0.0.0.0:2500 (trex/5.15.2); Tue, 27 Nov 2018 22:55:02 +0000 X-MC-Relay: Neutral X-MailChannels-SenderId: novatrend|x-authuser|juerg@bitron.ch X-MailChannels-Auth-Id: novatrend X-Lettuce-Rock: 6c600b966b144daf_1543359302634_1945183397 X-MC-Loop-Signature: 1543359302633:3464431359 X-MC-Ingress-Time: 1543359302633 Received: from [88.98.246.21] (port=40458 helo=jx1y.mynet) by srv17.tophost.ch with esmtpsa (TLSv1.2:ECDHE-RSA-AES128-SHA256:128) (Exim 4.91) (envelope-from ) id 1gRmFr-008hty-6q; Tue, 27 Nov 2018 23:54:55 +0100 From: =?UTF-8?q?J=C3=BCrg=20Billeter?= To: Andrew Morton Cc: Oleg Nesterov , Thomas Gleixner , Eric Biederman , Kees Cook , Andy Lutomirski , linux-api@vger.kernel.org, linux-kernel@vger.kernel.org, =?UTF-8?q?J=C3=BCrg=20Billeter?= Subject: [PATCH 0/1] Add prctl to kill descendants on exit Date: Tue, 27 Nov 2018 22:54:07 +0000 Message-Id: <20181127225408.7553-1-j@bitron.ch> X-Mailer: git-send-email 2.19.2 MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit X-AuthUser: juerg@bitron.ch Sender: linux-kernel-owner@vger.kernel.org Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org This patch adds a new prctl to kill all descendant processes on exit. See commit message for details of the prctl. This is a replacement of PR_SET_PDEATHSIG_PROC I proposed last year [1]. In the following discussion, Oleg suggested this approach. The motivation for this is to provide a lightweight mechanism to prevent stray processes. There is also a related Bugzilla entry [2]. PID namespaces can also be used to prevent stray processes, of course. However, they are not quite as lightweight as they typically also require a new mount namespace to be able to mount a new /proc. And they require CAP_SYS_ADMIN. User namespaces can help to gain CAP_SYS_ADMIN, however, that further increases the overhead and the other effects of the user namespace may not be desired. PID 1 in PID namespaces also exhibits non-standard signal behavior (SIGNAL_UNKILLABLE) [3]. [1] https://lkml.kernel.org/lkml/20170929123058.48924-1-j@bitron.ch/ [2] https://bugzilla.kernel.org/show_bug.cgi?id=43300 [3] https://lkml.kernel.org/lkml/20180803144021.56920-2-j@bitron.ch/ Jürg Billeter (1): prctl: add PR_{GET,SET}_KILL_DESCENDANTS_ON_EXIT fs/exec.c | 6 ++++++ include/linux/sched/signal.h | 3 +++ include/uapi/linux/prctl.h | 4 ++++ kernel/exit.c | 12 ++++++++++++ kernel/sys.c | 11 +++++++++++ security/apparmor/lsm.c | 1 + security/selinux/hooks.c | 3 +++ 7 files changed, 40 insertions(+) -- 2.19.2