From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1753403AbdHJUgl (ORCPT ); Thu, 10 Aug 2017 16:36:41 -0400 Received: from mail-pf0-f178.google.com ([209.85.192.178]:32873 "EHLO mail-pf0-f178.google.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1753017AbdHJUgi (ORCPT ); Thu, 10 Aug 2017 16:36:38 -0400 From: Kees Cook To: linux-kernel@vger.kernel.org Cc: Kees Cook , Nick Kralevich , Sebastian Schmidt , Tony Luck , Anton Vorontsov , Colin Cross , Petr Mladek , Sergey Senozhatsky , Steven Rostedt , Patrick Tjin , Mark Salyzyn Subject: [PATCH 0/2] pstore: Make default pstorefs root dir perms 0750 Date: Thu, 10 Aug 2017 13:36:33 -0700 Message-Id: <1502397395-118652-1-git-send-email-keescook@chromium.org> X-Mailer: git-send-email 2.7.4 Sender: linux-kernel-owner@vger.kernel.org List-ID: X-Mailing-List: linux-kernel@vger.kernel.org Nick Kralevich pointed out that it was rather problematic to check capabilities when reading some pstore files. Instead, opt for a more configurable DAC approach, but retain the general protection by making the pstorefs root directory mode 0750. It was 0755, but most crash-handlers will also be performing unlink operations (which DAC would require a root uid perm for already), so this shouldn't affect anyone, but rather make permissions more flexible. -Kees