mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: ebiederm@xmission.com (Eric W. Biederman)
To: "Serge E. Hallyn" <serge@hallyn.com>
Cc: LSM <linux-security-module@vger.kernel.org>,
	Andrew Morton <akpm@osdl.org>, James Morris <jmorris@namei.org>,
	Kees Cook <kees.cook@canonical.com>,
	containers@lists.linux-foundation.org,
	kernel list <linux-kernel@vger.kernel.org>,
	Alexey Dobriyan <adobriyan@gmail.com>,
	Michael Kerrisk <mtk.manpages@gmail.com>,
	xemul@parallels.com, dhowells@redhat.com
Subject: Re: [PATCH 6/9] user namespaces: convert all capable checks in kernel/sys.c
Date: Thu, 17 Feb 2011 17:57:15 -0800	[thread overview]
Message-ID: <m1r5b6ayv8.fsf@fess.ebiederm.org> (raw)
In-Reply-To: <20110217150342.GF26395@mail.hallyn.com> (Serge E. Hallyn's message of "Thu, 17 Feb 2011 15:03:42 +0000")

"Serge E. Hallyn" <serge@hallyn.com> writes:

> This allows setuid/setgid in containers.  It also fixes some
> corner cases where kernel logic foregoes capability checks when
> uids are equivalent.  The latter will need to be done throughout
> the whole kernel.

Except for the extra printk in sethostname this looks good.

Acked-by: "Eric W. Biederman" <ebiederm@xmission.com>

>
> Changelog:
> 	Jan 11: Use nsown_capable() as suggested by Bastian Blank.
> 	Jan 11: Fix logic errors in uid checks pointed out by Bastian.
> 	Feb 15: allow prlimit to current (was regression in previous version)
>
> Signed-off-by: Serge E. Hallyn <serge.hallyn@canonical.com>
> ---
>  kernel/sys.c |   74 ++++++++++++++++++++++++++++++++++++---------------------
>  1 files changed, 47 insertions(+), 27 deletions(-)
>
> diff --git a/kernel/sys.c b/kernel/sys.c
> index 7a1bbad..075370d 100644
> --- a/kernel/sys.c
> +++ b/kernel/sys.c
> @@ -118,17 +118,29 @@ EXPORT_SYMBOL(cad_pid);
>  
>  void (*pm_power_off_prepare)(void);
>  
> +/* called with rcu_read_lock, creds are safe */
> +static inline int set_one_prio_perm(struct task_struct *p)
> +{
> +	const struct cred *cred = current_cred(), *pcred = __task_cred(p);
> +
> +	if (pcred->user->user_ns == cred->user->user_ns &&
> +	    (pcred->uid  == cred->euid ||
> +	     pcred->euid == cred->euid))
> +		return 1;
> +	if (ns_capable(pcred->user->user_ns, CAP_SYS_NICE))
> +		return 1;
> +	return 0;
> +}
> +
>  /*
>   * set the priority of a task
>   * - the caller must hold the RCU read lock
>   */
>  static int set_one_prio(struct task_struct *p, int niceval, int error)
>  {
> -	const struct cred *cred = current_cred(), *pcred = __task_cred(p);
>  	int no_nice;
>  
> -	if (pcred->uid  != cred->euid &&
> -	    pcred->euid != cred->euid && !capable(CAP_SYS_NICE)) {
> +	if (!set_one_prio_perm(p)) {
>  		error = -EPERM;
>  		goto out;
>  	}
> @@ -502,7 +514,7 @@ SYSCALL_DEFINE2(setregid, gid_t, rgid, gid_t, egid)
>  	if (rgid != (gid_t) -1) {
>  		if (old->gid == rgid ||
>  		    old->egid == rgid ||
> -		    capable(CAP_SETGID))
> +		    nsown_capable(CAP_SETGID))
>  			new->gid = rgid;
>  		else
>  			goto error;
> @@ -511,7 +523,7 @@ SYSCALL_DEFINE2(setregid, gid_t, rgid, gid_t, egid)
>  		if (old->gid == egid ||
>  		    old->egid == egid ||
>  		    old->sgid == egid ||
> -		    capable(CAP_SETGID))
> +		    nsown_capable(CAP_SETGID))
>  			new->egid = egid;
>  		else
>  			goto error;
> @@ -546,7 +558,7 @@ SYSCALL_DEFINE1(setgid, gid_t, gid)
>  	old = current_cred();
>  
>  	retval = -EPERM;
> -	if (capable(CAP_SETGID))
> +	if (nsown_capable(CAP_SETGID))
>  		new->gid = new->egid = new->sgid = new->fsgid = gid;
>  	else if (gid == old->gid || gid == old->sgid)
>  		new->egid = new->fsgid = gid;
> @@ -613,7 +625,7 @@ SYSCALL_DEFINE2(setreuid, uid_t, ruid, uid_t, euid)
>  		new->uid = ruid;
>  		if (old->uid != ruid &&
>  		    old->euid != ruid &&
> -		    !capable(CAP_SETUID))
> +		    !nsown_capable(CAP_SETUID))
>  			goto error;
>  	}
>  
> @@ -622,7 +634,7 @@ SYSCALL_DEFINE2(setreuid, uid_t, ruid, uid_t, euid)
>  		if (old->uid != euid &&
>  		    old->euid != euid &&
>  		    old->suid != euid &&
> -		    !capable(CAP_SETUID))
> +		    !nsown_capable(CAP_SETUID))
>  			goto error;
>  	}
>  
> @@ -670,7 +682,7 @@ SYSCALL_DEFINE1(setuid, uid_t, uid)
>  	old = current_cred();
>  
>  	retval = -EPERM;
> -	if (capable(CAP_SETUID)) {
> +	if (nsown_capable(CAP_SETUID)) {
>  		new->suid = new->uid = uid;
>  		if (uid != old->uid) {
>  			retval = set_user(new);
> @@ -712,7 +724,7 @@ SYSCALL_DEFINE3(setresuid, uid_t, ruid, uid_t, euid, uid_t, suid)
>  	old = current_cred();
>  
>  	retval = -EPERM;
> -	if (!capable(CAP_SETUID)) {
> +	if (!nsown_capable(CAP_SETUID)) {
>  		if (ruid != (uid_t) -1 && ruid != old->uid &&
>  		    ruid != old->euid  && ruid != old->suid)
>  			goto error;
> @@ -776,7 +788,7 @@ SYSCALL_DEFINE3(setresgid, gid_t, rgid, gid_t, egid, gid_t, sgid)
>  	old = current_cred();
>  
>  	retval = -EPERM;
> -	if (!capable(CAP_SETGID)) {
> +	if (!nsown_capable(CAP_SETGID)) {
>  		if (rgid != (gid_t) -1 && rgid != old->gid &&
>  		    rgid != old->egid  && rgid != old->sgid)
>  			goto error;
> @@ -836,7 +848,7 @@ SYSCALL_DEFINE1(setfsuid, uid_t, uid)
>  
>  	if (uid == old->uid  || uid == old->euid  ||
>  	    uid == old->suid || uid == old->fsuid ||
> -	    capable(CAP_SETUID)) {
> +	    nsown_capable(CAP_SETUID)) {
>  		if (uid != old_fsuid) {
>  			new->fsuid = uid;
>  			if (security_task_fix_setuid(new, old, LSM_SETID_FS) == 0)
> @@ -869,7 +881,7 @@ SYSCALL_DEFINE1(setfsgid, gid_t, gid)
>  
>  	if (gid == old->gid  || gid == old->egid  ||
>  	    gid == old->sgid || gid == old->fsgid ||
> -	    capable(CAP_SETGID)) {
> +	    nsown_capable(CAP_SETGID)) {
>  		if (gid != old_fsgid) {
>  			new->fsgid = gid;
>  			goto change_okay;
> @@ -1177,8 +1189,11 @@ SYSCALL_DEFINE2(sethostname, char __user *, name, int, len)
>  	int errno;
>  	char tmp[__NEW_UTS_LEN];
>  
> -	if (!ns_capable(current->nsproxy->uts_ns->user_ns, CAP_SYS_ADMIN))
> +	if (!ns_capable(current->nsproxy->uts_ns->user_ns, CAP_SYS_ADMIN)) {
> +		printk(KERN_NOTICE "%s: did not have CAP_SYS_ADMIN\n", __func__);
>  		return -EPERM;
> +	}
> +	printk(KERN_NOTICE "%s: did have CAP_SYS_ADMIN\n", __func__);

Ouch!  This new print statement could be really annoying if an
unprivileged user calls sethostname.  Could you remove it?

>  	if (len < 0 || len > __NEW_UTS_LEN)
>  		return -EINVAL;
>  	down_write(&uts_sem);
> @@ -1226,7 +1241,7 @@ SYSCALL_DEFINE2(setdomainname, char __user *, name, int, len)
>  	int errno;
>  	char tmp[__NEW_UTS_LEN];
>  
> -	if (!capable(CAP_SYS_ADMIN))
> +	if (!ns_capable(current->nsproxy->uts_ns->user_ns, CAP_SYS_ADMIN))
>  		return -EPERM;
>  	if (len < 0 || len > __NEW_UTS_LEN)
>  		return -EINVAL;
> @@ -1341,6 +1356,8 @@ int do_prlimit(struct task_struct *tsk, unsigned int resource,
>  	rlim = tsk->signal->rlim + resource;
>  	task_lock(tsk->group_leader);
>  	if (new_rlim) {
> +		/* Keep the capable check against init_user_ns until
> +		   cgroups can contain all limits */
>  		if (new_rlim->rlim_max > rlim->rlim_max &&
>  				!capable(CAP_SYS_RESOURCE))
>  			retval = -EPERM;
> @@ -1384,19 +1401,22 @@ static int check_prlimit_permission(struct task_struct *task)
>  {
>  	const struct cred *cred = current_cred(), *tcred;
>  
> -	tcred = __task_cred(task);
> -	if (current != task &&
> -	    (cred->uid != tcred->euid ||
> -	     cred->uid != tcred->suid ||
> -	     cred->uid != tcred->uid  ||
> -	     cred->gid != tcred->egid ||
> -	     cred->gid != tcred->sgid ||
> -	     cred->gid != tcred->gid) &&
> -	     !capable(CAP_SYS_RESOURCE)) {
> -		return -EPERM;
> -	}
> +	if (current == task)
> +		return 0;
>  
> -	return 0;
> +	tcred = __task_cred(task);
> +	if (cred->user->user_ns == tcred->user->user_ns &&
> +	    (cred->uid == tcred->euid &&
> +	     cred->uid == tcred->suid &&
> +	     cred->uid == tcred->uid  &&
> +	     cred->gid == tcred->egid &&
> +	     cred->gid == tcred->sgid &&
> +	     cred->gid == tcred->gid))
> +		return 0;
> +	if (ns_capable(tcred->user->user_ns, CAP_SYS_RESOURCE))
> +		return 0;
> +
> +	return -EPERM;
>  }
>  
>  SYSCALL_DEFINE4(prlimit64, pid_t, pid, unsigned int, resource,

  reply	other threads:[~2011-02-18  1:57 UTC|newest]

Thread overview: 68+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2011-02-17 15:02 userns: targeted capabilities v5 Serge E. Hallyn
2011-02-17 15:02 ` [PATCH 1/9] Add a user_namespace as creator/owner of uts_namespace Serge E. Hallyn
2011-02-18  3:31   ` Eric W. Biederman
2011-02-18 16:57   ` Daniel Lezcano
2011-02-18 23:59   ` Andrew Morton
2011-02-17 15:03 ` [PATCH 2/9] security: Make capabilities relative to the user namespace Serge E. Hallyn
2011-02-18  3:46   ` Eric W. Biederman
2011-02-18 23:44   ` Daniel Lezcano
2011-02-18 23:59   ` Andrew Morton
2011-02-17 15:03 ` [PATCH 3/9] allow sethostname in a container Serge E. Hallyn
2011-02-18  3:05   ` Eric W. Biederman
2011-02-18 23:46   ` Daniel Lezcano
2011-02-17 15:03 ` [PATCH 4/9] allow killing tasks in your own or child userns Serge E. Hallyn
2011-02-18  3:00   ` Eric W. Biederman
2011-02-18 23:59   ` Andrew Morton
2011-02-24  0:48     ` Serge E. Hallyn
2011-02-24  0:54       ` Andrew Morton
2011-02-19 10:55   ` Daniel Lezcano
2011-02-17 15:03 ` [PATCH 5/9] Allow ptrace from non-init user namespaces Serge E. Hallyn
2011-02-18  2:59   ` Eric W. Biederman
2011-02-18  4:36     ` Serge E. Hallyn
2011-02-24  0:49       ` [PATCH] userns: ptrace: incorporate feedback from Eric Serge E. Hallyn
2011-02-24  0:56         ` Andrew Morton
2011-02-24  3:15           ` Serge E. Hallyn
2011-02-18 23:59   ` [PATCH 5/9] Allow ptrace from non-init user namespaces Andrew Morton
2011-02-24  0:43     ` Serge E. Hallyn
2011-02-19 17:49   ` Daniel Lezcano
2011-02-17 15:03 ` [PATCH 6/9] user namespaces: convert all capable checks in kernel/sys.c Serge E. Hallyn
2011-02-18  1:57   ` Eric W. Biederman [this message]
2011-02-18 23:59   ` Andrew Morton
2011-02-19  0:01   ` Andrew Morton
2011-02-19 17:52   ` Daniel Lezcano
2011-02-17 15:03 ` [PATCH 7/9] add a user namespace owner of ipc ns Serge E. Hallyn
2011-02-18  3:19   ` Eric W. Biederman
2011-02-18 23:59   ` Andrew Morton
2011-02-19 17:57   ` Daniel Lezcano
2011-02-17 15:03 ` [PATCH 8/9] user namespaces: convert several capable() calls Serge E. Hallyn
2011-02-18  1:51   ` Eric W. Biederman
2011-02-19 19:07   ` Daniel Lezcano
2011-02-17 15:04 ` [PATCH 9/9] userns: check user namespace for task->file uid equivalence checks Serge E. Hallyn
2011-02-18  1:29   ` Eric W. Biederman
2011-02-18 23:59   ` Andrew Morton
2011-02-24  3:24     ` Serge E. Hallyn
2011-02-24  5:08       ` Andrew Morton
2011-02-19 19:22   ` Daniel Lezcano
2011-02-18  0:21 ` userns: targeted capabilities v5 Andrew Morton
2011-02-18  3:53   ` Eric W. Biederman
2011-02-18  4:28   ` Serge E. Hallyn
2011-02-23 11:40 ` [PATCH 2/9] security: Make capabilities relative to the user namespace David Howells
2011-02-23 12:01 ` David Howells
2011-02-23 13:43   ` Serge E. Hallyn
2011-02-23 12:05 ` User namespaces and keys David Howells
2011-02-23 13:58   ` Serge E. Hallyn
2011-02-23 14:46     ` Eric W. Biederman
2011-02-23 15:06   ` David Howells
2011-02-23 15:45     ` Eric W. Biederman
2011-02-23 15:53       ` Serge E. Hallyn
2011-02-23 19:24         ` Casey Schaufler
2011-02-23 20:55           ` Eric W. Biederman
2011-02-23 21:37             ` Casey Schaufler
2011-02-24  6:56               ` Eric W. Biederman
2011-02-23 16:59 ` [PATCH 2/9] security: Make capabilities relative to the user namespace David Howells
2011-02-23 17:05 ` [PATCH 5/9] Allow ptrace from non-init user namespaces David Howells
2011-02-23 17:11 ` David Howells
2011-02-23 17:16 ` [PATCH 1/9] Add a user_namespace as creator/owner of uts_namespace David Howells
2011-02-23 21:21   ` Eric W. Biederman
2011-02-23 23:19   ` David Howells
2011-02-23 23:54     ` Eric W. Biederman

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=m1r5b6ayv8.fsf@fess.ebiederm.org \
    --to=ebiederm@xmission.com \
    --cc=adobriyan@gmail.com \
    --cc=akpm@osdl.org \
    --cc=containers@lists.linux-foundation.org \
    --cc=dhowells@redhat.com \
    --cc=jmorris@namei.org \
    --cc=kees.cook@canonical.com \
    --cc=linux-kernel@vger.kernel.org \
    --cc=linux-security-module@vger.kernel.org \
    --cc=mtk.manpages@gmail.com \
    --cc=serge@hallyn.com \
    --cc=xemul@parallels.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

Powered by JetHome