mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: Alan Cox <alan@lxorguk.ukuu.org.uk>
To: Mitchell Blank Jr <mitch@sfgoth.com>
Cc: Linux Kernel Mailing List <linux-kernel@vger.kernel.org>
Subject: Re: [RFC] relinquish_fs() syscall
Date: Mon, 29 Nov 2004 11:51:29 +0000	[thread overview]
Message-ID: <1101729087.20223.14.camel@localhost.localdomain> (raw)
In-Reply-To: <20041129114331.GA33900@gaz.sfgoth.com>

On Llu, 2004-11-29 at 11:43, Mitchell Blank Jr wrote:
> This has several benefits:
> 
>  * Considerably safer against root users in cage

Pardon. Its equally ineffectual. It might take someone a week longer to
write the exploit but an hour after that its no different.

>    Normal chroot's are trivial for privileged users to break out of -
>    these tasks don't work in the namespace.  You can't create a directory
>    to do the "chroot foo; cd ../../..; chroot ." trick.  You can't
>    create device nodes or mount /proc anywhere (I added an extra check
>    to do_mount() that even prevents a mount on top of '/')

A priviledged user can ioperm/iopl their way out.

>    This is a big deal for privilege separation; currently it's hard to
>    implement except in a daemon that starts its life as root.  Now the
>    same techniques can be used by any process.

That doesn't do name lookup, character set translation, or time (and a
few other things).

>    Imagine, for example, a jpeg decoder that after opening its input and
>    output files called relinquish_fs().  Now if the decoder has a flaw and

Imagine a jpeg decoder using an SELinux policy. 


  reply	other threads:[~2004-11-29 12:58 UTC|newest]

Thread overview: 11+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2004-11-29 11:43 Mitchell Blank Jr
2004-11-29 11:51 ` Alan Cox [this message]
2004-11-29 13:55   ` Mitchell Blank Jr
2004-11-29 15:17     ` Alan Cox
2004-11-30 13:27       ` Mitchell Blank Jr
2004-11-30 13:44         ` Arjan van de Ven
2004-11-30 14:12           ` Mitchell Blank Jr
2004-11-30 13:43             ` Alan Cox
2004-12-05  0:14               ` Rob Landley
2004-11-30 12:29     ` Helge Hafting
2004-11-30 13:48       ` Mitchell Blank Jr

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=1101729087.20223.14.camel@localhost.localdomain \
    --to=alan@lxorguk.ukuu.org.uk \
    --cc=linux-kernel@vger.kernel.org \
    --cc=mitch@sfgoth.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

Powered by JetHome