mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: Edgar Toernig <froese@gmx.de>
To: "Pekka Enberg" <penberg@cs.helsinki.fi>
Cc: "Pavel Machek" <pavel@ucw.cz>,
	linux-kernel@vger.kernel.org, linux-fsdevel@vger.kernel.org,
	akpm@osdl.org, viro@zeniv.linux.org.uk, alan@lxorguk.ukuu.org.uk,
	tytso@mit.edu, tigran@veritas.com
Subject: Re: [RFC/PATCH] revoke/frevoke system calls V2
Date: Mon, 7 Aug 2006 22:41:44 +0200	[thread overview]
Message-ID: <20060807224144.3bb64ac4.froese@gmx.de> (raw)
In-Reply-To: <84144f020608070251j2e14e909v8a18f62db85ff3d4@mail.gmail.com>

Pekka Enberg wrote:
>
> On 8/7/06, Edgar Toernig <froese@gmx.de> wrote:
> > Why do we need [f]revoke at all?  As it doesn't implement the
> > BSD semantic I can't see why it's better than fuser -k.
> 
> Which part of the BSD semantics is that?

That which talks about character devices, in particular ttys.

NetBSD revoke(2):
|
| ... a read() from a character device file which has been revoked
| returns a count of zero (end of file), and a close() call will
| succeed.
|...
| revoke is normally used to prepare a terminal device for a new
| login session, preventing any access by a previous user of the
| terminal.

Irix revoke(2) even mentions:
|
| ERRORS:
|  ...
|  [EINVAL] The named file is not a character-special file.

It seems, revoke was intended to disable access to tty devices
from old processes in a controlled way.  Sounds sane.

Your implementation is much cruder - it simply takes the fd
away from the app; any future use gives EBADF.  As a bonus,
it works for regular files and even goes as far as destroying
all mappings of the file from all processes (even root processes).
IMVHO this is a disaster from a security and reliability point
of view.

So, the behaviour regarding ttys is completely different to
other implementations and for other types of fds the Linux
semantic seems unique (the man-pages of the other systems
are pretty silent about that).

A serious question: What do you need this feature of revoking
regular files (or block devices) for?  Maybe my imagination
is lacking, but I can't find a use where fuser(1) (or similar
tools) wouldn't be as good or even better than revoke(2).

Ciao, ET.

  reply	other threads:[~2006-08-07 20:43 UTC|newest]

Thread overview: 60+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2006-07-27 14:25 Pekka J Enberg
2006-07-27 15:07 ` Alan Cox
2006-07-27 15:33   ` Pekka Enberg
2006-07-27 16:09     ` Alan Cox
2006-07-27 16:01       ` Pekka J Enberg
2006-07-27 16:30         ` Alan Cox
2006-07-27 17:07           ` Pekka J Enberg
2006-07-27 18:27           ` Pekka Enberg
2006-07-27 16:41 ` Ulrich Drepper
2006-07-27 17:05   ` Pekka J Enberg
2006-07-27 17:13     ` Ulrich Drepper
2006-07-27 17:33       ` H. Peter Anvin
2006-07-27 17:44         ` Ulrich Drepper
2006-07-27 18:00           ` H. Peter Anvin
2006-07-27 17:33     ` Alan Cox
2006-07-27 17:33       ` O_CAREFUL flag to disable open() side effects H. Peter Anvin
2006-07-27 17:43         ` Russell King
2006-07-27 17:50         ` Ulrich Drepper
2006-07-27 18:05         ` Alan Cox
2006-07-27 18:03           ` H. Peter Anvin
2006-07-27 18:14             ` Joshua Hudson
2006-08-05 21:05       ` [RFC/PATCH] revoke/frevoke system calls V2 Pavel Machek
2006-07-27 18:06 ` Petr Baudis
2006-07-27 18:10   ` Pekka Enberg
2006-07-27 19:30     ` Horst H. von Brand
2006-07-28  3:40       ` Pekka J Enberg
2006-07-27 18:34   ` Alan Cox
2006-08-05 12:29 ` Pavel Machek
2006-08-07  5:42   ` Pekka J Enberg
2006-08-07  8:17   ` Edgar Toernig
2006-08-07  9:51     ` Pekka Enberg
2006-08-07 20:41       ` Edgar Toernig [this message]
2006-08-07 22:24         ` Chase Venters
2006-08-08 12:15           ` Alan Cox
2006-08-09  8:41             ` Edgar Toernig
2006-08-09 10:39               ` Alan Cox
2006-08-09 18:00                 ` Edgar Toernig
2006-08-09 18:36                   ` Alan Cox
2006-08-09 19:13                     ` Pekka Enberg
2006-08-09 20:08                       ` Edgar Toernig
2006-08-09 21:29                       ` Edgar Toernig
2006-08-11  7:52                   ` Helge Hafting
2006-08-07 22:52         ` David Wagner
2006-08-07 22:56           ` Daniel Jacobowitz
2006-08-07 23:12             ` Chase Venters
2006-08-08 12:16               ` Pekka Enberg
2006-08-08 16:02                 ` Kari Hurtta
2006-08-08 21:54                   ` Theodore Tso
2006-08-09  6:32                     ` Pekka Enberg
2006-08-08 12:13           ` Alan Cox
2006-08-08 12:29         ` Alan Cox
2006-08-08 12:31           ` Pekka Enberg
2006-08-08 12:57           ` Pavel Machek
2006-08-08 14:14             ` Alan Cox
2006-08-08 13:57               ` Pavel Machek
2006-08-09  8:41           ` Edgar Toernig
2006-08-09 10:42             ` Alan Cox
2006-08-09 18:00               ` Edgar Toernig
2006-08-09 18:35                 ` Alan Cox
2006-08-09 19:14                   ` Pekka Enberg

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20060807224144.3bb64ac4.froese@gmx.de \
    --to=froese@gmx.de \
    --cc=akpm@osdl.org \
    --cc=alan@lxorguk.ukuu.org.uk \
    --cc=linux-fsdevel@vger.kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=pavel@ucw.cz \
    --cc=penberg@cs.helsinki.fi \
    --cc=tigran@veritas.com \
    --cc=tytso@mit.edu \
    --cc=viro@zeniv.linux.org.uk \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

Powered by JetHome