Return-Path: Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1753967Ab0AJVqq (ORCPT ); Sun, 10 Jan 2010 16:46:46 -0500 Received: (majordomo@vger.kernel.org) by vger.kernel.org id S1753437Ab0AJVqo (ORCPT ); Sun, 10 Jan 2010 16:46:44 -0500 Received: from tundra.namei.org ([65.99.196.166]:34645 "EHLO tundra.namei.org" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1752959Ab0AJVqn (ORCPT ); Sun, 10 Jan 2010 16:46:43 -0500 Date: Mon, 11 Jan 2010 08:44:44 +1100 (EST) From: James Morris To: Pavel Machek cc: "Serge E. Hallyn" , Michael Stone , linux-kernel@vger.kernel.org, netdev@vger.kernel.org, linux-security-module@vger.kernel.org, Andi Kleen , David Lang , Oliver Hartkopp , Alan Cox , Herbert Xu , Valdis Kletnieks , Bryan Donlan , Evgeniy Polyakov , "C. Scott Ananian" , "Eric W. Biederman" , Bernie Innocenti , Mark Seaborn , Randy Dunlap , Am?rico Wang , Tetsuo Handa , Samir Bellabes , Casey Schaufler Subject: Re: [PATCH 2/3] Security: Implement disablenetwork semantics. (v4) In-Reply-To: <20100110211609.GC26079@elf.ucw.cz> Message-ID: References: <20091227010441.GA12077@heat> <20091227010650.GA12190@heat> <20091230185053.GB18712@us.ibm.com> <20100101143100.GA3944@atrey.karlin.mff.cuni.cz> <20100110211609.GC26079@elf.ucw.cz> User-Agent: Alpine 2.00 (LRH 1167 2008-08-23) MIME-Version: 1.0 Content-Type: TEXT/PLAIN; charset=US-ASCII Sender: linux-kernel-owner@vger.kernel.org List-ID: X-Mailing-List: linux-kernel@vger.kernel.org Content-Length: 642 Lines: 25 On Sun, 10 Jan 2010, Pavel Machek wrote: > > > For the record: NAK, as it introduces security holes. > > > > Please elaborate. > > See the mailthread. Yep, wading through several weeks of it.. > > Allows user to disable suid program's access to network. That bypasses > audit, and will cause system-wide DoS if suid program decides to go > daemon. Ok. -- James Morris -- To unsubscribe from this list: send the line "unsubscribe linux-kernel" in the body of a message to majordomo@vger.kernel.org More majordomo info at http://vger.kernel.org/majordomo-info.html Please read the FAQ at http://www.tux.org/lkml/