From: Andrew Morton <akpm@osdl.org>
To: Petr Baudis <pasky@suse.cz>
Cc: linux-kernel@vger.kernel.org,
"Eric W. Biederman" <ebiederm@xmission.com>,
Chris Wright <chrisw@sous-sol.org>,
Ulrich Drepper <drepper@redhat.com>
Subject: Re: [RESEND][PATCH] Let even non-dumpable tasks access /proc/self/fd
Date: Mon, 19 Jun 2006 20:48:51 -0700 [thread overview]
Message-ID: <20060619204851.84467440.akpm@osdl.org> (raw)
In-Reply-To: <20060616124157.GB24203@pasky.or.cz>
On Fri, 16 Jun 2006 14:41:57 +0200
Petr Baudis <pasky@suse.cz> wrote:
> All tasks calling setuid() from root to non-root during their lifetime
> will not be able to access their /proc/self/fd. This is troublesome
> because the fstatat() and other *at() routines are emulated by accessing
> /proc/self/fd/*/path and that will break with setuid()ing programs,
> leading to various weird consequences (e.g. with the latest glibc,
> nftw() does not work with setuid()ing programs on ppc and furthermore
> causes the LSB testsuite to fail because of this).
Odd. Did something actually change in glibc to make this start happening?
> This kernel patch fixes the problem by letting the process access its
> own /proc/self/fd - as far as I can see, this should be reasonably safe
> since for the process, this does not reveal "anything new". Feel free to
> comment on this.
>
Eric, Chris - any thought on this one?
Thanks.
>
> So far it's got one positive review on LKML and not much attention
> otherwise; Pavel Machek hinted me to steer it your way...
>
> diff --git a/fs/proc/base.c b/fs/proc/base.c
> index 6cc77dc..ea36a25 100644
> --- a/fs/proc/base.c
> +++ b/fs/proc/base.c
> @@ -1368,7 +1368,9 @@ static struct inode *proc_pid_make_inode
> ei->type = ino;
> inode->i_uid = 0;
> inode->i_gid = 0;
> - if (ino == PROC_TGID_INO || ino == PROC_TID_INO || task_dumpable(task)) {
> + if (ino == PROC_TGID_INO || ino == PROC_TID_INO ||
> + ((ino == PROC_TGID_FD || ino == PROC_TID_FD || ino >= PROC_TID_FD_DIR) && task == current) ||
> + task_dumpable(task)) {
> inode->i_uid = task->euid;
> inode->i_gid = task->egid;
> }
> @@ -1398,7 +1400,9 @@ static int pid_revalidate(struct dentry
> struct inode *inode = dentry->d_inode;
> struct task_struct *task = proc_task(inode);
> if (pid_alive(task)) {
> - if (proc_type(inode) == PROC_TGID_INO || proc_type(inode) == PROC_TID_INO || task_dumpable(task)) {
> + if (proc_type(inode) == PROC_TGID_INO || proc_type(inode) == PROC_TID_INO ||
> + ((proc_type(inode) == PROC_TGID_FD || proc_type(inode) == PROC_TID_FD) && task == current) ||
> + task_dumpable(task)) {
> inode->i_uid = task->euid;
> inode->i_gid = task->egid;
> } else {
> @@ -1425,7 +1429,7 @@ static int tid_fd_revalidate(struct dent
> if (fcheck_files(files, fd)) {
> rcu_read_unlock();
> put_files_struct(files);
> - if (task_dumpable(task)) {
> + if (task_dumpable(task) || task == current) {
> inode->i_uid = task->euid;
> inode->i_gid = task->egid;
> } else {
>
>
> --
> Petr "Pasky" Baudis
> Stuff: http://pasky.or.cz/
> Right now I am having amnesia and deja-vu at the same time. I think
> I have forgotten this before.
next prev parent reply other threads:[~2006-06-20 3:49 UTC|newest]
Thread overview: 4+ messages / expand[flat|nested] mbox.gz Atom feed top
2006-06-16 12:41 Petr Baudis
2006-06-20 3:48 ` Andrew Morton [this message]
2006-06-20 6:24 ` Eric W. Biederman
2006-07-05 16:07 ` Jeff Layton
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20060619204851.84467440.akpm@osdl.org \
--to=akpm@osdl.org \
--cc=chrisw@sous-sol.org \
--cc=drepper@redhat.com \
--cc=ebiederm@xmission.com \
--cc=linux-kernel@vger.kernel.org \
--cc=pasky@suse.cz \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®