Return-Path: Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1764403AbZLQRwm (ORCPT ); Thu, 17 Dec 2009 12:52:42 -0500 Received: (majordomo@vger.kernel.org) by vger.kernel.org id S1760455AbZLQRwi (ORCPT ); Thu, 17 Dec 2009 12:52:38 -0500 Received: from one.firstfloor.org ([213.235.205.2]:60996 "EHLO one.firstfloor.org" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1752182AbZLQRwf (ORCPT ); Thu, 17 Dec 2009 12:52:35 -0500 Date: Thu, 17 Dec 2009 18:52:31 +0100 From: Andi Kleen To: "Eric W. Biederman" Cc: Michael Stone , linux-kernel@vger.kernel.org, netdev@vger.kernel.org, linux-security-module@vger.kernel.org, Andi Kleen , David Lang , Oliver Hartkopp , Alan Cox , Herbert Xu , Valdis Kletnieks , Bryan Donlan , =?iso-8859-1?Q?R=E9mi?= Denis-Courmont , Evgeniy Polyakov , "C. Scott Ananian" , James Morris , Bernie Innocenti , Mark Seaborn , Linux Containers Subject: Re: Network isolation with RLIMIT_NETWORK, cont'd. Message-ID: <20091217175230.GK9804@basil.fritz.box> References: <20091213034418.GA4416@heat> MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: User-Agent: Mutt/1.5.17 (2007-11-01) Sender: linux-kernel-owner@vger.kernel.org List-ID: X-Mailing-List: linux-kernel@vger.kernel.org Content-Length: 602 Lines: 17 > Solve that with an unused uid. That ptrace_may_access check is > completely non-intuitive, and a problem if we ever remove the current > == task security module bug avoidance. I thought he wanted to do that without suid? If he can change uids he can as well just use full network namespaces. -Andi -- ak@linux.intel.com -- Speaking for myself only. -- To unsubscribe from this list: send the line "unsubscribe linux-kernel" in the body of a message to majordomo@vger.kernel.org More majordomo info at http://vger.kernel.org/majordomo-info.html Please read the FAQ at http://www.tux.org/lkml/