2004-09-05 21:37:05

by Frank van Maarseveen

[permalink] [raw]
Subject: broken_suid mount option

Is this thing useful anymore? Google came up with this patch submission
and description from you:

http://www.ussg.iu.edu/hypermail/linux/kernel/0010.1/1178.html


--
Frank


-------------------------------------------------------
This SF.Net email is sponsored by BEA Weblogic Workshop
FREE Java Enterprise J2EE developer tools!
Get your free copy of BEA WebLogic Workshop 8.1 today.
http://ads.osdn.com/?ad_id=5047&alloc_id=10808&op=click
_______________________________________________
NFS maillist - [email protected]
https://lists.sourceforge.net/lists/listinfo/nfs


2004-09-05 21:43:59

by Trond Myklebust

[permalink] [raw]
Subject: Re: broken_suid mount option

P=E5 su , 05/09/2004 klokka 17:37, skreiv Frank van Maarseveen:
> Is this thing useful anymore? Google came up with this patch submission
> and description from you:
>=20
> http://www.ussg.iu.edu/hypermail/linux/kernel/0010.1/1178.html

Just yesterday I saw traces made on a college server by a student this
summer in which >99% of the traffic was broken lookups of .Xauthority by
'root' processes...

Cheers,
Trond



-------------------------------------------------------
This SF.Net email is sponsored by BEA Weblogic Workshop
FREE Java Enterprise J2EE developer tools!
Get your free copy of BEA WebLogic Workshop 8.1 today.
http://ads.osdn.com/?ad_id=5047&alloc_id=10808&op=click
_______________________________________________
NFS maillist - [email protected]
https://lists.sourceforge.net/lists/listinfo/nfs

2004-09-05 21:56:04

by Frank van Maarseveen

[permalink] [raw]
Subject: Re: broken_suid mount option

On Sun, Sep 05, 2004 at 05:43:49PM -0400, Trond Myklebust wrote:
>
> Just yesterday I saw traces made on a college server by a student this
> summer in which >99% of the traffic was broken lookups of .Xauthority by
> 'root' processes...

So they run old XFree86 software with broken setuid programs and
compensate using the broken_suid mount option. They probably use
an old kernel as well. Isn't it time to change this for 2.6?
You mentioned the word "security" ;-)

--
Frank


-------------------------------------------------------
This SF.Net email is sponsored by BEA Weblogic Workshop
FREE Java Enterprise J2EE developer tools!
Get your free copy of BEA WebLogic Workshop 8.1 today.
http://ads.osdn.com/?ad_id=5047&alloc_id=10808&op=click
_______________________________________________
NFS maillist - [email protected]
https://lists.sourceforge.net/lists/listinfo/nfs

2004-09-05 22:03:56

by Trond Myklebust

[permalink] [raw]
Subject: Re: broken_suid mount option

P=E5 su , 05/09/2004 klokka 17:55, skreiv Frank van Maarseveen:

> So they run old XFree86 software with broken setuid programs and
> compensate using the broken_suid mount option. They probably use
> an old kernel as well. Isn't it time to change this for 2.6?
> You mentioned the word "security" ;-)

If people agree that we can remove it, then I'll take the patch. The
whole point of making it a mount option (rather than the default as used
to be the case earlier) was to allow us to deprecate it.

Note, though, that we should take this one too to lkml in order to get a
proper concensus.

Cheers,
Trond



-------------------------------------------------------
This SF.Net email is sponsored by BEA Weblogic Workshop
FREE Java Enterprise J2EE developer tools!
Get your free copy of BEA WebLogic Workshop 8.1 today.
http://ads.osdn.com/?ad_id=5047&alloc_id=10808&op=click
_______________________________________________
NFS maillist - [email protected]
https://lists.sourceforge.net/lists/listinfo/nfs