From: Alan Cox <alan@lxorguk.ukuu.org.uk>
To: Tejun Heo <tj@kernel.org>
Cc: Paolo Bonzini <pbonzini@redhat.com>,
Ric Wheeler <rwheeler@redhat.com>,
Petr Matousek <pmatouse@redhat.com>, Kay Sievers <kay@redhat.com>,
Jens Axboe <axboe@kernel.dk>,
linux-kernel@vger.kernel.org,
"James E.J. Bottomley" <James.Bottomley@HansenPartnership.com>
Subject: Re: setting up CDB filters in udev (was Re: [PATCH v2 0/3] block: add queue-private command filter, editable via sysfs)
Date: Fri, 2 Nov 2012 17:21:45 +0000 [thread overview]
Message-ID: <20121102172145.184abfe3@pyramind.ukuu.org.uk> (raw)
In-Reply-To: <20121102164828.GA3823@mtj.dyndns.org>
> > Not a good model. Any removal of filters and passing them to a task
> > should be explicit. The behaviour really ought to be to permit the
> > intentional setting of explicit filters then passing them, not touch the
> > default behaviour.
>
> Yeah, well, then I guess it'll have to be a separate ioctl to switch
> SG_IO for !root users.
My first thought would be to have the basic behaviour as
allowed IFF passes user filter
&& CAP_SYS_RAWIO || passes 'root' filter
that allows untrusted to also push unprivileged filters for their own
purposes (consider things like exokernel experiments or just trying to
ensure a raw disk emulation doesn't go wrong). The default user feature
would be 'allow anything'.
then add a way to 'set' the root filter only if you have CAP_SYS_RAWIO
with the default 'root' filter being the current hardcoded filter.
That also means that a normal app running as superuser for some reason
would set its user filter and any accidentally inherited descriptors will
be less dangerous as the are today. It also means a CAP_SYS_RAWIO capable
app can still use filters itself as good programming practise.
It effectively means you have to deliberately and intentionally set up an
'inherited' extra rights case.
Alan
next prev parent reply other threads:[~2012-11-02 17:16 UTC|newest]
Thread overview: 37+ messages / expand[flat|nested] mbox.gz Atom feed top
2012-09-25 15:30 [PATCH v2 0/3] block: add queue-private command filter, editable via sysfs Paolo Bonzini
2012-09-25 15:30 ` [PATCH v2 1/3] block: add back queue-private command filter Paolo Bonzini
2012-09-25 15:30 ` [PATCH v2 2/3] scsi: create an all-zero filter for scanners Paolo Bonzini
2012-09-25 15:30 ` [PATCH v2 3/3] block: add back command filter modification via sysfs Paolo Bonzini
2012-10-04 10:12 ` [PATCH v2 0/3] block: add queue-private command filter, editable " Paolo Bonzini
2012-10-19 0:22 ` Tejun Heo
2012-10-19 9:07 ` Paolo Bonzini
[not found] ` <2007908429.13363375.1350637872646.JavaMail.root@redhat.com>
[not found] ` <20121019201058.GP13370@google.com>
[not found] ` <5087E093.50700@redhat.com>
[not found] ` <CAOS58YM5ZO9h0XUCNxV+6U3UzpeUen5ZuyqsNEUaJ81ux=QKvw@mail.gmail.com>
[not found] ` <5088EC43.2010600@redhat.com>
2012-10-25 18:00 ` setting up CDB filters in udev (was Re: [PATCH v2 0/3] block: add queue-private command filter, editable via sysfs) Tejun Heo
2012-10-25 18:35 ` Paolo Bonzini
2012-10-31 12:52 ` Paolo Bonzini
2012-10-31 21:22 ` Tejun Heo
2012-11-02 14:49 ` Paolo Bonzini
2012-11-02 15:35 ` Alan Cox
2012-11-02 16:48 ` Tejun Heo
2012-11-02 17:21 ` Alan Cox [this message]
2012-11-02 17:30 ` Tejun Heo
2012-11-02 20:18 ` Alan Cox
2012-11-02 20:21 ` Tejun Heo
2012-11-02 20:48 ` Alan Cox
2012-11-02 22:59 ` Tejun Heo
2012-11-02 23:52 ` Alan Cox
2012-11-02 23:58 ` Tejun Heo
2012-11-03 0:19 ` Alan Cox
2012-11-03 0:23 ` Tejun Heo
2012-11-03 0:52 ` Alan Cox
2012-11-02 16:51 ` Tejun Heo
2012-11-02 17:49 ` Paolo Bonzini
2012-11-02 17:53 ` Tejun Heo
2012-11-03 13:20 ` Paolo Bonzini
2012-11-03 14:50 ` Alan Cox
2012-11-05 11:08 ` Paolo Bonzini
2012-11-05 18:18 ` Tejun Heo
2012-11-05 20:12 ` Alan Cox
2012-11-05 20:09 ` Tejun Heo
2012-11-05 20:17 ` Alan Cox
2012-11-05 20:15 ` Tejun Heo
2012-11-05 18:26 ` Tejun Heo
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20121102172145.184abfe3@pyramind.ukuu.org.uk \
--to=alan@lxorguk.ukuu.org.uk \
--cc=James.Bottomley@HansenPartnership.com \
--cc=axboe@kernel.dk \
--cc=kay@redhat.com \
--cc=linux-kernel@vger.kernel.org \
--cc=pbonzini@redhat.com \
--cc=pmatouse@redhat.com \
--cc=rwheeler@redhat.com \
--cc=tj@kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®