From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1754139AbYIQHk6 (ORCPT ); Wed, 17 Sep 2008 03:40:58 -0400 Received: (majordomo@vger.kernel.org) by vger.kernel.org id S1751747AbYIQHku (ORCPT ); Wed, 17 Sep 2008 03:40:50 -0400 Received: from gprs189-60.eurotel.cz ([160.218.189.60]:45553 "EHLO gprs189-60.eurotel.cz" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1750879AbYIQHkt (ORCPT ); Wed, 17 Sep 2008 03:40:49 -0400 Date: Wed, 17 Sep 2008 09:42:06 +0200 From: Pavel Machek To: Ulrich Drepper Cc: Arjan van de Ven , linux-kernel@vger.kernel.org, torvalds@linux-foundation.org, dwmw2@infradead.org, drepper@redhat.com, mingo@elte.hu, tglx@tglx.de Subject: Re: [PATCH 12/13] hrtimer: create a "timer_slack" field in the task struct Message-ID: <20080917074206.GF2659@elf.ucw.cz> References: <20080901160343.75a89ec9@infradead.org> <20080901161423.59ebf2fc@infradead.org> <20080902100439.GA11383@elf.ucw.cz> <20080902060323.70245b83@infradead.org> <20080908132713.GA18486@elf.ucw.cz> <20080908064002.7abc2a22@infradead.org> <20080908141555.GB31784@elf.ucw.cz> <20080914155744.GA4845@ucw.cz> MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: X-Warning: Reading this can be dangerous to your mental health. User-Agent: Mutt/1.5.17 (2007-11-01) Sender: linux-kernel-owner@vger.kernel.org List-ID: X-Mailing-List: linux-kernel@vger.kernel.org On Sun 2008-09-14 09:04:08, Ulrich Drepper wrote: > On Sun, Sep 14, 2008 at 8:57 AM, Pavel Machek wrote: > >> LD_PRELOAD and other variables are ignored in security-relevant > >> contexts and environments are cleared in many situations. Sure, you > > > > ...but that's okay, right? You would not want passwd to inherit huge > > slack specified by attacker...? > > No, it's not OK. There are enough apps which are privileged and need > to be handled this way. Take the X server, for instance. _Need_ to be handled? They are not handled that way today, and it still seems to work ok. (Plus X is no longer setuid on new distros...) So -- how do you prevent user from setting excessively high slack and interfering with ping or passwd? > > Well, it is not too much, but... is the cost for userspace really > > significant? You'd clearly want it stored in environment, not > > filesystem... > > You cannot really use the environment for anything meaningful. > Especially for this case, you couldn't change the setting for a > running process. What a fully-userlevel implementation would have Is this important enough to warrant setting for already-running processes? I don't think so... Pavel -- (english) http://www.livejournal.com/~pavelmachek (cesky, pictures) http://atrey.karlin.mff.cuni.cz/~pavel/picture/horses/blog.html