Return-Path: Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1756695AbZFCQcS (ORCPT ); Wed, 3 Jun 2009 12:32:18 -0400 Received: (majordomo@vger.kernel.org) by vger.kernel.org id S1751763AbZFCQcH (ORCPT ); Wed, 3 Jun 2009 12:32:07 -0400 Received: from mail-px0-f182.google.com ([209.85.216.182]:36565 "EHLO mail-px0-f182.google.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1753242AbZFCQcG (ORCPT ); Wed, 3 Jun 2009 12:32:06 -0400 MIME-Version: 1.0 In-Reply-To: References: <20090530192829.GK6535@oblivion.subreption.com> <20090531022158.GA9033@oblivion.subreption.com> <20090602203405.GC6701@oblivion.subreption.com> <7e0fb38c0906030922u3af8c2abi8a2cfdcd66151a5a@mail.gmail.com> Date: Wed, 3 Jun 2009 12:32:07 -0400 Message-ID: <7e0fb38c0906030932o28d5c963y8059672e5c2c7ecf@mail.gmail.com> Subject: Re: Security fix for remapping of page 0 (was [PATCH] Change ZERO_SIZE_PTR to point at unmapped space) From: Eric Paris To: Linus Torvalds Cc: Christoph Lameter , "Larry H." , linux-mm@kvack.org, Alan Cox , Rik van Riel , linux-kernel@vger.kernel.org, pageexec@freemail.hu Content-Type: text/plain; charset=ISO-8859-1 Content-Transfer-Encoding: 7bit Sender: linux-kernel-owner@vger.kernel.org List-ID: X-Mailing-List: linux-kernel@vger.kernel.org Content-Length: 1018 Lines: 29 On Wed, Jun 3, 2009 at 12:28 PM, Linus Torvalds wrote: > > > On Wed, 3 Jun 2009, Eric Paris wrote: >> >> As I recall the only need for CONFIG_SECURITY is for the ability to >> override the check. > > No, if you have SECURITY disabled entirely, the check goes away. I meant 'need' as in the reason I wrapped it in CONFIG_SECURITY, not that you were wrong when you said it disapeared. >> I think I could probably pretty cleanly change it to use >> CAP_SYS_RAWIO/SELinux permissions if CONFIG_SECURITY and just allow it >> for uid=0 in the non-security case? > > We probably should, since the "capability" security version should > generally essentially emulate the regular non-SECURITY case for root. Will poke/patch this afternoon. -Eric -- To unsubscribe from this list: send the line "unsubscribe linux-kernel" in the body of a message to majordomo@vger.kernel.org More majordomo info at http://vger.kernel.org/majordomo-info.html Please read the FAQ at http://www.tux.org/lkml/