Received: by 2002:a25:8b91:0:0:0:0:0 with SMTP id j17csp4116927ybl; Tue, 21 Jan 2020 13:12:48 -0800 (PST) X-Google-Smtp-Source: APXvYqwIuQWnnwAwQs1OaVcf2ZrG0fiFPZSthL94wwQC//4eDXmQbnQBCPZ3fWKs27saD8IOX0rI X-Received: by 2002:aca:4442:: with SMTP id r63mr4589958oia.33.1579641168838; Tue, 21 Jan 2020 13:12:48 -0800 (PST) ARC-Seal: i=1; a=rsa-sha256; t=1579641168; cv=none; d=google.com; s=arc-20160816; b=nKT/QElczLrEcu0Z6DbT0aYdZ9YDq+ejHDStHs1rd82WKaOfMokTopagLeae+P85hG EYIwJlP5wK7EHDScSlX4b/VApemhfB0HmgXYvezhIqJ4+K6n72MFTp9HzN2TPv2oOcyx YujaWDg/FLI0jue4n17nWUjlbj3Omt9iPPj/vm34E3BhnF0Q7NXScWH33ZLykL1jo4Ng g4Nch+DWz8Av86y8h9S3ih4m8vuamJOTkroj9VgTFX1cS7r70XUJ4ciNCxONLOmrNLcB qxeMtibhULTvEzWLiAvCS1Rx4BxNP/crAUytdj7RiiO6payuQDaLpBFFNcJU4gycYC55 0CwQ== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:sender:cc:to:subject:message-id:date:from :in-reply-to:references:mime-version:dkim-signature; bh=vbYnFtSV7P55A+Hcn9+5BPe8w8FZVi5oIFLwqhXqdqE=; b=XNg4fUlQKEvqv3GxArz25hDyEFysp9ag/7XUKUl0CEpIqCWMtL2a+7A2DOSVDAQ6Rt ISLco7BqLdLXyEvZK0qPd39eBNkiduZ8FPCkGM3u4FtIwUs7D8+2tdx53+Ev4MmuXmsX +/rCrEooM41JiPjoipJwV9w1/AR79gNxSCzhHyxVHbgnjOI+bH21a6x2VwrnItXO4A9P ypFK2cZ2HGJ9TQu/uHJ9CsPUQCV3ktORdv2qPAz6Jpr5JLKqT20v+ix98DG7GOi77/vU xOpXMliTjFnVaxqATQ+FyjwMq5es1lbSlgGo7WO0IU6PoJV4FxccAQbahBsLZ12N6xEp 1RKw== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@gmail.com header.s=20161025 header.b=ckrjIxG7; spf=pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=NONE sp=QUARANTINE dis=NONE) header.from=gmail.com Return-Path: Received: from vger.kernel.org (vger.kernel.org. [209.132.180.67]) by mx.google.com with ESMTP id w4si22219690otp.30.2020.01.21.13.12.35; Tue, 21 Jan 2020 13:12:48 -0800 (PST) Received-SPF: pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) client-ip=209.132.180.67; Authentication-Results: mx.google.com; dkim=pass header.i=@gmail.com header.s=20161025 header.b=ckrjIxG7; spf=pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=NONE sp=QUARANTINE dis=NONE) header.from=gmail.com Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1728855AbgAUVLj (ORCPT + 99 others); Tue, 21 Jan 2020 16:11:39 -0500 Received: from mail-ot1-f67.google.com ([209.85.210.67]:33966 "EHLO mail-ot1-f67.google.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1727829AbgAUVLj (ORCPT ); Tue, 21 Jan 2020 16:11:39 -0500 Received: by mail-ot1-f67.google.com with SMTP id a15so4342608otf.1; Tue, 21 Jan 2020 13:11:38 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=mime-version:references:in-reply-to:from:date:message-id:subject:to :cc; bh=vbYnFtSV7P55A+Hcn9+5BPe8w8FZVi5oIFLwqhXqdqE=; b=ckrjIxG7IMhIM3XSxTUmaUbqKeb3b5zq6j5/jldlzpEkSt7SQiD7moJom9c/0BCHUc TdTIW84Oqd6EPXM4txIqk3n5xvsQn9Bm+OEIhoQ1NjqRSo+5w39Q8pMUerZsz3jVarL+ c0QHOvILzbEoTPlF4on8AwbtxsRdUmvuDinhve8gG4JROBWIoRHINn6w6hhKW4k0hFup biTxFRJd4Szq7RuXQcj+HPDfGjFWttHDhDERAg0Jiz3WnrnTdEZNN+2R6mjPMg9yzqyq W/n1R3NdJ4iSLYORd9Tq+20KE4RrL47QsWomOZTbFSunB/4PAx5Jvi1DVwe+7QQQHCZ5 miFw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc; bh=vbYnFtSV7P55A+Hcn9+5BPe8w8FZVi5oIFLwqhXqdqE=; b=M7H4L6LWLY1I+8TKmcyBXoK8mrMurpZogzDO16A4X9O+Ax43sSOVDlL667h04GaKFR cEB35l6PHX/SYSO3fRI8wlr2GcI7/CKZi0QLy/f7QmTQIS1Rl18AyddYiv66zopUxt3/ 51kPJxpTJUkapkmuUlHB6bsVDxx5/H+F3F4/qUTryUlhvYw1MGzkA8BtdRmNChQlLnds R6bPneHn7D1PMwlrJEqh8l68Hz95GdHPBS4JguhEh5fX+/Ef1CyZEC8sv2hW2MDM+jbx sCvTRc6gmykXaYAaPmZMCgpE/dhN1CTkFPClWyju7gDewbdFf+/6EEfOaTUoNOqncsy9 JskA== X-Gm-Message-State: APjAAAWXuaJdnQ/cxSRVJ5qNB2i5K8r/FZCVM8Rn0zgWTR+puU+JM6qV 65NU5WMoNeIDeS0YaIno4FPK4WUUS4QjSyY3TNM= X-Received: by 2002:a9d:70d9:: with SMTP id w25mr5216661otj.231.1579641097958; Tue, 21 Jan 2020 13:11:37 -0800 (PST) MIME-Version: 1.0 References: <20200115171736.16994-1-christian.brauner@ubuntu.com> <20200118011701.ciqiuutgyyvtk5a4@wittgenstein> <20200118124653.k7exqcu4fyojd63e@wittgenstein> In-Reply-To: <20200118124653.k7exqcu4fyojd63e@wittgenstein> From: Andrei Vagin Date: Tue, 21 Jan 2020 13:11:26 -0800 Message-ID: Subject: Re: [PATCH] ptrace: reintroduce usage of subjective credentials in ptrace_has_cap() To: Christian Brauner Cc: LKML , Serge Hallyn , Jann Horn , Oleg Nesterov , Eric Paris , stable@vger.kernel.org, Dmitry Safonov <0x7f454c46@gmail.com>, Adrian Reber Content-Type: text/plain; charset="UTF-8" Sender: linux-kernel-owner@vger.kernel.org Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org On Sat, Jan 18, 2020 at 4:47 AM Christian Brauner wrote: > > > The criu process is started with all capabilities in the root user namespace. > > > > > > I don't have time to investigate this issue right now, will provide > > > more details next Tuesday. > > > > Yeah, we've detected the issue. security_capable() indicates success by > > returning 0 for whatever reason whereas has_ns_capability() returns 1. > > So the logic was inverted. This is fixed in the new version. Sorry for > > the noise! > > So, I just finished compiling criu and running the test suite on the > criu-dev branch. The test-suite passes fine after the security_capable() > braino in my original patch was corrected to security_capable() == 0: > > ################## ALL TEST(S) PASSED (TOTAL 178/SKIPPED 16) ################### Thank you for doing this! Not all CRIU contributors can run all tests. You rock! > > Thanks! > Christian