From: Alan Cox <alan@lxorguk.ukuu.org.uk>
To: Mitchell Blank Jr <mitch@sfgoth.com>
Cc: Linux Kernel Mailing List <linux-kernel@vger.kernel.org>
Subject: Re: [RFC] relinquish_fs() syscall
Date: Mon, 29 Nov 2004 11:51:29 +0000 [thread overview]
Message-ID: <1101729087.20223.14.camel@localhost.localdomain> (raw)
In-Reply-To: <20041129114331.GA33900@gaz.sfgoth.com>
On Llu, 2004-11-29 at 11:43, Mitchell Blank Jr wrote:
> This has several benefits:
>
> * Considerably safer against root users in cage
Pardon. Its equally ineffectual. It might take someone a week longer to
write the exploit but an hour after that its no different.
> Normal chroot's are trivial for privileged users to break out of -
> these tasks don't work in the namespace. You can't create a directory
> to do the "chroot foo; cd ../../..; chroot ." trick. You can't
> create device nodes or mount /proc anywhere (I added an extra check
> to do_mount() that even prevents a mount on top of '/')
A priviledged user can ioperm/iopl their way out.
> This is a big deal for privilege separation; currently it's hard to
> implement except in a daemon that starts its life as root. Now the
> same techniques can be used by any process.
That doesn't do name lookup, character set translation, or time (and a
few other things).
> Imagine, for example, a jpeg decoder that after opening its input and
> output files called relinquish_fs(). Now if the decoder has a flaw and
Imagine a jpeg decoder using an SELinux policy.
next prev parent reply other threads:[~2004-11-29 12:58 UTC|newest]
Thread overview: 11+ messages / expand[flat|nested] mbox.gz Atom feed top
2004-11-29 11:43 Mitchell Blank Jr
2004-11-29 11:51 ` Alan Cox [this message]
2004-11-29 13:55 ` Mitchell Blank Jr
2004-11-29 15:17 ` Alan Cox
2004-11-30 13:27 ` Mitchell Blank Jr
2004-11-30 13:44 ` Arjan van de Ven
2004-11-30 14:12 ` Mitchell Blank Jr
2004-11-30 13:43 ` Alan Cox
2004-12-05 0:14 ` Rob Landley
2004-11-30 12:29 ` Helge Hafting
2004-11-30 13:48 ` Mitchell Blank Jr
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=1101729087.20223.14.camel@localhost.localdomain \
--to=alan@lxorguk.ukuu.org.uk \
--cc=linux-kernel@vger.kernel.org \
--cc=mitch@sfgoth.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
Powered by JetHome