From: ebiederm@xmission.com (Eric W. Biederman)
To: Ingo Molnar <mingo@elte.hu>
Cc: Albert Cahalan <acahalan@gmail.com>,
Guillaume Chazarain <guichaz@yahoo.fr>,
akpm@linux-foundation.org, mm-commits@vger.kernel.org,
oleg@tv-sign.ru, rjw@sisk.pl, roland@redhat.com,
xemul@openvz.org, linux-kernel <linux-kernel@vger.kernel.org>,
Ulrich Drepper <drepper@redhat.com>
Subject: Re: + proc-fix-the-threaded-proc-self.patch added to -mm tree
Date: Wed, 28 Nov 2007 04:42:22 -0700 [thread overview]
Message-ID: <m1r6iaegv5.fsf@ebiederm.dsl.xmission.com> (raw)
In-Reply-To: <m1ve7mehcm.fsf@ebiederm.dsl.xmission.com> (Eric W. Biederman's message of "Wed, 28 Nov 2007 04:31:53 -0700")
ebiederm@xmission.com (Eric W. Biederman) writes:
> I am not certain the two components make sense as we have a possible
> permission problem where it is remotely possible that a task will
> have permission to access /proc/<tid> but not /proc/<tgid>.
Got it. I can totally avoid in permission issues by having a
follow_link method that just goes to the target directory without
checking permissions as we go.
So in the worst case with weird selinux permission rules you
might be able to access /proc/task but not /proc/self or
/proc/task/..
At least for what I care about, weird cases with unshare where the
mounts and the other namespaces may be different between threads in
someones home rolled thread package that uses CLONE_THREAD
we should be ok.
Eric
next prev parent reply other threads:[~2007-11-28 11:44 UTC|newest]
Thread overview: 11+ messages / expand[flat|nested] mbox.gz Atom feed top
[not found] <200711262339.lAQNdNrw029057@imap1.linux-foundation.org>
[not found] ` <20071128014901.4b303954@inria.fr>
2007-11-28 9:41 ` Albert Cahalan
2007-11-28 10:46 ` Ingo Molnar
2007-11-28 11:31 ` Eric W. Biederman
2007-11-28 11:42 ` Eric W. Biederman [this message]
2007-11-28 17:47 ` Albert Cahalan
2007-11-29 21:40 ` Eric W. Biederman
2007-11-30 0:10 ` Ingo Molnar
2007-11-30 7:44 ` Albert Cahalan
2007-12-02 4:00 ` Eric W. Biederman
2007-11-28 18:14 ` Albert Cahalan
2007-11-29 12:34 ` Ingo Molnar
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=m1r6iaegv5.fsf@ebiederm.dsl.xmission.com \
--to=ebiederm@xmission.com \
--cc=acahalan@gmail.com \
--cc=akpm@linux-foundation.org \
--cc=drepper@redhat.com \
--cc=guichaz@yahoo.fr \
--cc=linux-kernel@vger.kernel.org \
--cc=mingo@elte.hu \
--cc=mm-commits@vger.kernel.org \
--cc=oleg@tv-sign.ru \
--cc=rjw@sisk.pl \
--cc=roland@redhat.com \
--cc=xemul@openvz.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®