mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* [PATCH] security: fix capability bug
@ 2006-03-10 19:50 Ram Gupta
  2006-03-10 20:52 ` Chris Wright
  0 siblings, 1 reply; 2+ messages in thread
From: Ram Gupta @ 2006-03-10 19:50 UTC (permalink / raw)
  To: linux mailing-list; +Cc: Andrew Morton

This patch fixes a bug of ptrace for PTRACE_TRACEME request. In this
case the call is made by the child process & code needs to check the
capabilty of the parent process to trace the child process but code
incorrectly makes check for the child process. Please apply

Signed-off-by: Ram Gupta <ram.gupta5@gmail.com>
----
-- linux-2.6.15.6-rg/security/commoncap.c.orig 2006-03-10
13:22:26.000000000 +0000
+++ linux-2.6.15.6-rg/security/commoncap.c      2006-03-10
13:26:45.000000000 +0000
@@ -59,9 +59,13 @@ int cap_settime(struct timespec *ts, str
 int cap_ptrace (struct task_struct *parent, struct task_struct *child)
 {
        /* Derived from arch/i386/kernel/ptrace.c:sys_ptrace. */
-       if (!cap_issubset (child->cap_permitted, current->cap_permitted) &&
-           !capable(CAP_SYS_PTRACE))
-               return -EPERM;
+       if (!cap_issubset (child->cap_permitted, parent->cap_permitted)){
+               if(!cap_capable(parent,CAP_SYS_PTRACE)){
+                       parent->flags |= PF_SUPERPRIV;
+               }
+               else
+                       return -EPERM;
+       }
        return 0;
 }

regards
Ram Gupta

^ permalink raw reply	[flat|nested] 2+ messages in thread

* Re: [PATCH] security: fix capability bug
  2006-03-10 19:50 [PATCH] security: fix capability bug Ram Gupta
@ 2006-03-10 20:52 ` Chris Wright
  0 siblings, 0 replies; 2+ messages in thread
From: Chris Wright @ 2006-03-10 20:52 UTC (permalink / raw)
  To: Ram Gupta; +Cc: linux mailing-list, Andrew Morton

* Ram Gupta (ram.gupta5@gmail.com) wrote:
> This patch fixes a bug of ptrace for PTRACE_TRACEME request. In this
> case the call is made by the child process & code needs to check the
> capabilty of the parent process to trace the child process but code
> incorrectly makes check for the child process. Please apply

I already submitted a fix for this (you were Cc' on the email).

thanks,
-chris

^ permalink raw reply	[flat|nested] 2+ messages in thread

end of thread, other threads:[~2006-03-10 20:48 UTC | newest]

Thread overview: 2+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2006-03-10 19:50 [PATCH] security: fix capability bug Ram Gupta
2006-03-10 20:52 ` Chris Wright

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®