Return-Path: Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S936625AbYCSWvW (ORCPT ); Wed, 19 Mar 2008 18:51:22 -0400 Received: (majordomo@vger.kernel.org) by vger.kernel.org id S965945AbYCSVUP (ORCPT ); Wed, 19 Mar 2008 17:20:15 -0400 Received: from e1.ny.us.ibm.com ([32.97.182.141]:52367 "EHLO e1.ny.us.ibm.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S965920AbYCSVUM (ORCPT ); Wed, 19 Mar 2008 17:20:12 -0400 Date: Wed, 19 Mar 2008 16:20:07 -0500 From: "Serge E. Hallyn" To: Andrew Morton Cc: "Serge E. Hallyn" , linux-kernel@vger.kernel.org, torvalds@linux-foundation.org, morgan@kernel.org, buraphalinuxserver@gmail.com, lcapitulino@mandriva.com.br, stable@kernel.org Subject: Re: [PATCH 1/1] file capabilities: remove cap_task_kill() (-git) Message-ID: <20080319212007.GA12217@sergelap.austin.ibm.com> References: <20080319165635.GH5935@sergelap.ibm.com> <20080319141112.02981daf.akpm@linux-foundation.org> MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <20080319141112.02981daf.akpm@linux-foundation.org> User-Agent: Mutt/1.5.16 (2007-06-09) Sender: linux-kernel-owner@vger.kernel.org List-ID: X-Mailing-List: linux-kernel@vger.kernel.org Content-Length: 1633 Lines: 40 Quoting Andrew Morton (akpm@linux-foundation.org): > On Wed, 19 Mar 2008 11:56:35 -0500 > "Serge E. Hallyn" wrote: > > > (resending once against -git. I had sent against -stable in > > http://lkml.org/lkml/2008/2/28/225. Without this patch, > > atd is broken at least on some distros.) > > So this fix is needed in 2.6.24.x? Yes it is. > > The original justification for cap_task_kill() was as follows: > > > > check_kill_permission() does appropriate uid equivalence checks. > > However with file capabilities it becomes possible for an > > unprivileged user to execute a file with file capabilities > > resulting in a more privileged task with the same uid. > > > > However now that cap_task_kill() always returns 0 (permission > > granted) when p->uid==current->uid, the whole hook is worthless, > > and only likely to create more subtle problems in the corner cases > > where it might still be called but return -EPERM. Those cases > > are basically when uids are different but euid/suid is equivalent > > as per the check in check_kill_permission(). > > > > One example of a still-broken application is 'at' for non-root users. > > This 2.6.25-rc6 patch doesn't apply correctly to 2.6.24. I can't find a > *formal* copy of your 2.6.24 patch on stable@kernel.org, so perhaps a > resend for -stable is in order. Argh, yes, will do. Thanks. -serge -- To unsubscribe from this list: send the line "unsubscribe linux-kernel" in the body of a message to majordomo@vger.kernel.org More majordomo info at http://vger.kernel.org/majordomo-info.html Please read the FAQ at http://www.tux.org/lkml/