From: "Jack O'Quin" <joq@io.com>
To: Jody McIntyre <realtime-lsm@modernduck.com>
Cc: James Morris <jmorris@redhat.com>,
Lee Revell <rlrevell@joe-job.com>,
linux-kernel <linux-kernel@vger.kernel.org>,
torbenh@gmx.de
Subject: Re: [PATCH] Realtime LSM
Date: 16 Sep 2004 13:27:02 -0500 [thread overview]
Message-ID: <87zn3qoyrt.fsf@sulphur.joq.us> (raw)
In-Reply-To: <20040916155127.GG2945@conscoop.ottawa.on.ca>
Jody McIntyre <realtime-lsm@modernduck.com> writes:
> On Wed, Sep 15, 2004 at 11:48:29PM -0500, Jack O'Quin wrote:
>
> > What are the serialization issues with variable updates via /proc? I
> > presume they can change at any time, even while the LSM is running on
> > some other processor. If so, I'll need to be careful to fetch each
> > variable only once and use that value for the entire capability
> > computation, right? That should be straightforward.
>
> It doesn't matter. There's no added security risk if gid changes
> halfway through the permission check, and the other variables are used
> only once. It's probably cleaner to check the gid in a separate
> function though.
Agreed.
One could probably get a false negative, but it's hard to imagine a
sensible usage example. I just like to be tidy any time concurrency
issues arise.
> However, I just noticed something interesting:
>
> If "any" and "gid" is set, any is ignored and only the gid check is
> effective. This is counter to the documentation, so I assume it is a
> bug.
Quite right, good eye. :-)
I must not have tested that combination. :-(
> I also added the sysctl interface to the documentation.
Good. I thought about that, too.
> > But, perhaps we should consider removing this option entirely. It is
> > the only one with a potentially serious security exposure. The others
> > at worst allow Denial of Service attacks.
>
> I hate allcaps too. Maybe you should just use a shell script wrapper
> like (untested):
>
> ----
> if echo uname -r |grep '^2\.4\.' ; then
> jackstart $@
> else
> jackd $@
> fi
> ----
I am willing to do that if the kernel developers think it better.
It recently occurred to me that jackstart might be able to detect this
situation and exec jackd, anyway. (AFAICT, the only reasonably
POSIX-compliant method for detecting that a process has the
"appropriate permission" to do something is trying it to see whether
it returns EPERM.)
Thanks for helping...
--
joq
next prev parent reply other threads:[~2004-09-16 18:32 UTC|newest]
Thread overview: 72+ messages / expand[flat|nested] mbox.gz Atom feed top
2004-09-12 5:46 Lee Revell
2004-09-12 13:58 ` James Morris
2004-09-12 14:05 ` James Morris
2004-09-12 19:03 ` Lee Revell
2004-09-12 19:16 ` Jack O'Quin
2004-09-16 2:31 ` Jody McIntyre
2004-09-16 4:48 ` Jack O'Quin
2004-09-16 15:51 ` Jody McIntyre
2004-09-16 18:27 ` Jack O'Quin [this message]
2004-09-17 7:08 ` torbenh
2004-09-17 20:01 ` Jack O'Quin
2004-09-20 20:20 ` Jody McIntyre
2004-09-12 15:50 ` Kronos
2004-09-13 23:22 ` Lee Revell
2004-09-13 23:34 ` Chris Wright
2004-09-14 2:18 ` Lee Revell
2004-09-14 3:01 ` William Lee Irwin III
2004-09-14 3:46 ` Lee Revell
2004-09-14 3:50 ` William Lee Irwin III
2004-09-20 20:23 ` Jody McIntyre
2004-09-21 0:11 ` Jack O'Quin
2004-09-21 7:52 ` torbenh
2004-09-30 21:14 ` Jody McIntyre
2004-09-30 21:53 ` Lee Revell
2004-10-01 0:37 ` Jack O'Quin
2004-10-01 1:20 ` Chris Wright
2004-10-01 4:05 ` Jack O'Quin
2004-10-01 20:40 ` Lee Revell
2004-10-01 21:23 ` Chris Wright
2004-10-01 22:19 ` Lee Revell
2004-10-01 22:27 ` Chris Wright
2004-10-01 22:32 ` Lee Revell
2004-10-01 22:44 ` Chris Wright
2004-10-05 5:55 ` Jack O'Quin
2004-10-07 23:51 ` Lee Revell
2004-10-08 20:58 ` Lee Revell
2004-10-08 21:21 ` Andrew Morton
2004-10-08 21:22 ` Lee Revell
2004-10-08 21:25 ` Lee Revell
2004-10-08 21:45 ` Chris Wright
2004-10-08 21:49 ` Lee Revell
2004-10-08 21:52 ` Chris Wright
2004-10-08 22:05 ` Lee Revell
2004-10-08 22:09 ` Chris Wright
2004-10-08 22:19 ` Chris Wright
2004-10-08 22:24 ` Chris Wright
2004-10-08 23:05 ` Lee Revell
2004-10-08 23:12 ` Chris Wright
2004-10-08 23:15 ` Lee Revell
2004-10-08 23:20 ` Chris Wright
2004-10-09 1:01 ` Jack O'Quin
2004-10-09 5:16 ` Chris Wright
2004-10-09 16:16 ` Jack O'Quin
2004-10-09 19:11 ` Chris Wright
2004-10-09 20:27 ` Jack O'Quin
2004-10-09 22:53 ` Chris Wright
2004-10-22 23:59 ` Jack O'Quin
2004-10-23 0:36 ` Lee Revell
2004-10-23 1:23 ` Jack O'Quin
2004-10-23 1:27 ` Lee Revell
2004-10-23 5:08 ` Jack O'Quin
2004-10-23 18:17 ` Jack O'Quin
2004-10-25 2:03 ` Jack O'Quin
2004-10-23 20:04 ` Chris Wright
2004-10-05 4:00 ` Jack O'Quin
2004-10-15 1:55 ` Rusty Russell
2004-10-15 2:08 ` Lee Revell
[not found] <87acu0p0nw.fsf@sulphur.joq.us>
2004-11-09 22:39 ` Jack O'Quin
2004-11-20 2:44 ` Lee Revell
2004-11-20 3:55 ` Lee Revell
2004-11-20 6:19 ` Jack O'Quin
2004-11-20 6:43 ` Lee Revell
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=87zn3qoyrt.fsf@sulphur.joq.us \
--to=joq@io.com \
--cc=jmorris@redhat.com \
--cc=linux-kernel@vger.kernel.org \
--cc=realtime-lsm@modernduck.com \
--cc=rlrevell@joe-job.com \
--cc=torbenh@gmx.de \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®