From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org X-Spam-Level: X-Spam-Status: No, score=-0.8 required=3.0 tests=HEADER_FROM_DIFFERENT_DOMAINS, MAILING_LIST_MULTI,SPF_HELO_NONE,SPF_PASS autolearn=no autolearn_force=no version=3.4.0 Received: from mail.kernel.org (mail.kernel.org [198.145.29.99]) by smtp.lore.kernel.org (Postfix) with ESMTP id 8CC72C54E8B for ; Tue, 12 May 2020 09:45:26 +0000 (UTC) Received: from vger.kernel.org (vger.kernel.org [23.128.96.18]) by mail.kernel.org (Postfix) with ESMTP id 743CF20661 for ; Tue, 12 May 2020 09:45:26 +0000 (UTC) Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1729273AbgELJpZ (ORCPT ); Tue, 12 May 2020 05:45:25 -0400 Received: from shells.gnugeneration.com ([66.240.222.126]:48870 "EHLO shells.gnugeneration.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1728416AbgELJpZ (ORCPT ); Tue, 12 May 2020 05:45:25 -0400 Received: by shells.gnugeneration.com (Postfix, from userid 1000) id 2577B1A40053; Tue, 12 May 2020 02:45:24 -0700 (PDT) Date: Tue, 12 May 2020 02:45:24 -0700 From: Vito Caputo To: linux-kernel Subject: Question regarding blocking set[ug]id on processes including via suid executables Message-ID: <20200512094524.662gnls64rwjhct2@shells.gnugeneration.com> MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline Sender: linux-kernel-owner@vger.kernel.org Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org Hello folks, I'm curious if someone knows a way to do this using existing linux interfaces. I'd like to create a login lacking the ability to switch uid/gid. Even if the process has access to suid executables like /bin/su, and the user has the root password, I'd like the descendant processes of their login to be simply incapable of changing uid/gid, even when it's in the form of running a program w/suid bit set on an existing and accessible executable in the filesystem. No matter what, it just can't happen. Do we have any such thing today? I'd really like to be able to set this on a specific user and all logins of that user are simply stuck on that uid no matter what. Thanks in advance, Vito Caputo