mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: ebiederm@xmission.com (Eric W. Biederman)
To: Paul Jackson <pj@sgi.com>
Cc: akpm@osdl.org, laurent.riffard@free.fr, jesper.juhl@gmail.com,
	linux-kernel@vger.kernel.org, rjw@sisk.pl, mbligh@mbligh.org,
	clameter@engr.sgi.com
Subject: Re: 2.6.16-rc5-mm1
Date: Tue, 28 Feb 2006 21:57:34 -0700	[thread overview]
Message-ID: <m1mzgapxs1.fsf@ebiederm.dsl.xmission.com> (raw)
In-Reply-To: <20060228202632.cba12ae7.pj@sgi.com> (Paul Jackson's message of "Tue, 28 Feb 2006 20:26:32 -0800")

Paul Jackson <pj@sgi.com> writes:

> Eric wrote:
>> The logic is can I access this file in some other way besides through
>> /proc.
>> 
>> When applied to /proc/<pid>/exe
>> When applied to /proc/<pid>/root
>> When applied to /proc/<pid>/cwd
>
> I can't make sense of the above.  Could you elaborate?

Sorry.  What I ment was when applied to the above files the
permission checks are not quite correct because I should check
to see if you share a fs_struct with them, checking for a shared
files_struct for exe,root,cwd is nonsense.

The permission check is not quite in the right place yet
in /proc.

The logical check which I have implemented imperfectly is:
Without going through /proc/fd can I see this file.

Part of the reason this happens now is the old check
unchanged since 2.2 was it only checked to see if the two
processes were in the same chroot.  I made the check test
the actual files that were returned.  Which is much more
correct, and much more likely to prevent information leaks.

> And explain how any of these permission checks fail for
> a root shell?

Because I probably need a check something like
if (capable(CAP_DAC_OVERRIDE))
	return 0;
To allow an appropriately privileged root user to do anything.

The short answer is that I bug fixed the permission checks into working
but that is not sufficient for the permission checks to be correct. :(

These checks were previously done so badly they were mistaken for
generic permission checks that all files in /proc should have.  Which
resulted in tons of useless cruft.

At this point the code is working as designed but it is clearly not
working as it needs to.

I am also beginning to think that readlink and followlink
should have different permissions.  Especially to keep fuser
and his friends happy.

I am glad I found this issue with permissions on /proc/<pid>/fd,
but it is clear there is still more todo.

Ok. Now back to hunting bugs that crash the kernel.


Eric

  reply	other threads:[~2006-03-01  4:59 UTC|newest]

Thread overview: 74+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2006-02-28 12:24 2.6.16-rc5-mm1 Andrew Morton
2006-02-28 14:41 ` 2.6.16-rc5-mm1 Cornelia Huck
2006-02-28 14:55   ` 2.6.16-rc5-mm1 Martin Schwidefsky
2006-02-28 15:08   ` 2.6.16-rc5-mm1 gsmith
2006-02-28 15:01 ` 2.6.16-rc5-mm1 Michal Piotrowski
2006-02-28 16:20   ` 2.6.16-rc5-mm1 Michal Piotrowski
2006-03-01  2:16     ` 2.6.16-rc5-mm1 Nick Piggin
2006-03-01  2:44       ` 2.6.16-rc5-mm1 Andrew Morton
2006-03-01  3:10         ` 2.6.16-rc5-mm1 Nick Piggin
2006-03-01  3:21           ` 2.6.16-rc5-mm1 Andrew Morton
2006-03-01  3:30             ` 2.6.16-rc5-mm1 Nick Piggin
2006-03-01  3:42               ` 2.6.16-rc5-mm1 Andrew Morton
2006-02-28 19:40 ` usb usb5: Manufacturer: Linux 2.6.16-rc5-mm1 ehci_hcd Alexey Dobriyan
2006-02-28 20:48   ` [linux-usb-devel] " Alan Stern
2006-02-28 20:48 ` 2.6.16-rc5-mm1 Mattia Dongili
2006-02-28 23:49   ` 2.6.16-rc5-mm1 Alessandro Zummo
2006-02-28 21:13 ` 2.6.16-rc5-mm1 Jesper Juhl
2006-02-28 22:27   ` 2.6.16-rc5-mm1 Jiri Slaby
2006-02-28 22:30     ` 2.6.16-rc5-mm1 Jesper Juhl
2006-02-28 23:18       ` 2.6.16-rc5-mm1 Laurent Riffard
2006-02-28 23:57         ` 2.6.16-rc5-mm1 Jesper Juhl
2006-03-01  0:21         ` 2.6.16-rc5-mm1 Andrew Morton
2006-03-01  0:33           ` 2.6.16-rc5-mm1 Jesper Juhl
2006-03-01  3:05           ` 2.6.16-rc5-mm1 Paul Jackson
2006-03-01  3:20             ` 2.6.16-rc5-mm1 Paul Jackson
2006-03-01  4:15             ` 2.6.16-rc5-mm1 Eric W. Biederman
2006-03-01  4:26               ` 2.6.16-rc5-mm1 Paul Jackson
2006-03-01  4:57                 ` Eric W. Biederman [this message]
2006-03-01 10:06           ` 2.6.16-rc5-mm1 Laurent Riffard
2006-03-01 10:32             ` 2.6.16-rc5-mm1 Andrew Morton
2006-03-01 11:25               ` 2.6.16-rc5-mm1 Andrew Morton
2006-03-01 18:14                 ` 2.6.16-rc5-mm1 Ashok Raj
2006-03-01 18:48                   ` 2.6.16-rc5-mm1 Andrew Morton
2006-03-01 19:31                     ` 2.6.16-rc5-mm1 Ashok Raj
2006-03-01 13:58               ` 2.6.16-rc5-mm1 Mike Galbraith
2006-03-01 14:50                 ` 2.6.16-rc5-mm1 Laurent Riffard
2006-03-01 15:33                   ` 2.6.16-rc5-mm1 Mike Galbraith
2006-03-01 20:12                     ` 2.6.16-rc5-mm1 Andrew Morton
2006-03-01 20:19                       ` 2.6.16-rc5-mm1 Andrew Morton
2006-03-01 20:35                       ` 2.6.16-rc5-mm1 Peter Staubach
2006-03-01 20:43                       ` 2.6.16-rc5-mm1 Eric W. Biederman
2006-03-02  4:52                       ` 2.6.16-rc5-mm1 Nick Piggin
2006-03-02 16:37                       ` [PATCH] proc: Use sane permission checks on the /proc/<pid>/fd/ symlinks Eric W. Biederman
2006-03-03  8:49                         ` Andrew Morton
2006-03-03 12:00                           ` Eric W. Biederman
2006-03-01 14:22               ` 2.6.16-rc5-mm1 J.A. Magallon
2006-03-02  4:51                 ` 2.6.16-rc5-mm1 Andrew Morton
2006-03-02 21:11                   ` 2.6.16-rc5-mm1 J.A. Magallon
2006-03-02 22:31                     ` 2.6.16-rc5-mm1 Andrew Morton
2006-03-02  3:10               ` 2.6.16-rc5-mm1 Paul Jackson
2006-03-01 10:35             ` 2.6.16-rc5-mm1 Laurent Riffard
2006-03-01 10:47               ` 2.6.16-rc5-mm1 Andrew Morton
2006-03-02  1:41           ` 2.6.16-rc5-mm1 Jesper Juhl
2006-03-02 20:16             ` 2.6.16-rc5-mm1 Jesper Juhl
2006-03-02 22:34               ` 2.6.16-rc5-mm1 Eric W. Biederman
2006-03-06  0:05                 ` 2.6.16-rc5-mm1 Jesper Juhl
2006-02-28 23:15   ` 2.6.16-rc5-mm1 Andrew Morton
2006-02-28 23:33     ` 2.6.16-rc5-mm1 Jesper Juhl
2006-02-28 22:34 ` 2.6.16-rc5-mm1 Rafael J. Wysocki
2006-02-28 23:48   ` 2.6.16-rc5-mm1 Andrew Morton
2006-03-01  0:52     ` 2.6.16-rc5-mm1 Eric W. Biederman
2006-03-01 11:42       ` 2.6.16-rc5-mm1 Rafael J. Wysocki
2006-02-28 23:56 ` 2.6.16-rc5-mm1 Martin Bligh
2006-03-01 16:45   ` [PATCH] Fix powerpc bad_page_fault output (Re: 2.6.16-rc5-mm1) Olof Johansson
2006-03-02  0:09     ` Paul E. McKenney
2006-03-02  0:35     ` Paul Mackerras
2006-03-02  1:14       ` Martin Bligh
2006-03-02  2:22         ` Olof Johansson
2006-03-02  5:24           ` Anton Blanchard
2006-03-02  5:16         ` Paul Mackerras
2006-03-02 10:27 ` 2.6.16-rc5-mm1 -- strange load balancing problems Peter Williams
2006-03-02 22:23   ` Peter Williams
2006-03-13  4:46     ` Peter Williams
2006-03-03 15:32 ` 2.6.16-rc5-mm1: USB compile errors Adrian Bunk

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=m1mzgapxs1.fsf@ebiederm.dsl.xmission.com \
    --to=ebiederm@xmission.com \
    --cc=akpm@osdl.org \
    --cc=clameter@engr.sgi.com \
    --cc=jesper.juhl@gmail.com \
    --cc=laurent.riffard@free.fr \
    --cc=linux-kernel@vger.kernel.org \
    --cc=mbligh@mbligh.org \
    --cc=pj@sgi.com \
    --cc=rjw@sisk.pl \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

Powered by JetHome