From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1753878Ab2KTX74 (ORCPT ); Tue, 20 Nov 2012 18:59:56 -0500 Received: from lxorguk.ukuu.org.uk ([81.2.110.251]:33394 "EHLO lxorguk.ukuu.org.uk" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1753235Ab2KTX7y (ORCPT ); Tue, 20 Nov 2012 18:59:54 -0500 Date: Wed, 21 Nov 2012 00:05:10 +0000 From: Alan Cox To: Kees Cook Cc: linux-kernel@vger.kernel.org, Greg Kroah-Hartman , ellyjones@chromium.org, Kay Sievers , Roland Eggner Subject: Re: [PATCH v3] devtmpfs: mount with noexec and nosuid Message-ID: <20121121000510.7a3c6673@pyramind.ukuu.org.uk> In-Reply-To: <20121120215059.GA1859@www.outflux.net> References: <20121120215059.GA1859@www.outflux.net> X-Mailer: Claws Mail 3.8.1 (GTK+ 2.24.8; x86_64-redhat-linux-gnu) Face: iVBORw0KGgoAAAANSUhEUgAAADAAAAAwBAMAAAClLOS0AAAAFVBMVEWysKsSBQMIAwIZCwj///8wIhxoRDXH9QHCAAABeUlEQVQ4jaXTvW7DIBAAYCQTzz2hdq+rdg494ZmBeE5KYHZjm/d/hJ6NfzBJpp5kRb5PHJwvMPMk2L9As5Y9AmYRBL+HAyJKeOU5aHRhsAAvORQ+UEgAvgddj/lwAXndw2laEDqA4x6KEBhjYRCg9tBFCOuJFxg2OKegbWjbsRTk8PPhKPD7HcRxB7cqhgBRp9Dcqs+B8v4CQvFdqeot3Kov6hBUn0AJitrzY+sgUuiA8i0r7+B3AfqKcN6t8M6HtqQ+AOoELCikgQSbgabKaJW3kn5lBs47JSGDhhLKDUh1UMipwwinMYPTBuIBjEclSaGZUk9hDlTb5sUTYN2SFFQuPe4Gox1X0FZOufjgBiV1Vls7b+GvK3SU4wfmcGo9rPPQzgIabfj4TYQo15k3bTHX9RIw/kniir5YbtJF4jkFG+dsDK1IgE413zAthU/vR2HVMmFUPIHTvF6jWCpFaGw/A3qWgnbxpSm9MSmY5b3pM1gvNc/gQfwBsGwF0VCtxZgAAAAASUVORK5CYII= Mime-Version: 1.0 Content-Type: text/plain; charset=US-ASCII Content-Transfer-Encoding: 7bit Sender: linux-kernel-owner@vger.kernel.org List-ID: X-Mailing-List: linux-kernel@vger.kernel.org > +config DEVTMPFS_SAFE > + bool "Use nosuid,noexec mount options on devtmpfs" > + depends on DEVTMPFS > + help > + This instructs the kernel to include the MS_NOEXEC and > + MS_NOSUID mount flags when mounting devtmpfs. This prevents > + certain kinds of code-execution attacks on embedded platforms. This description appears to be wrong as well as the code being pointless. It doesn't prevent any meaningful code execution attacks and the config entry might give people the delusion its useful or a security feature. Please provide a valid and meaningful example.