From: ebiederm@xmission.com (Eric W. Biederman)
To: "YOSHIFUJI Hideaki / 吉藤英明" <yoshfuji@linux-ipv6.org>
Cc: akpm@linux-foundation.org, linux-kernel@vger.kernel.org,
devel@openvz.org, adobriyan@sw.ru
Subject: Re: [PATCH 3/3] sysctl: Error on bad sysctl tables
Date: Thu, 09 Aug 2007 20:15:37 -0600 [thread overview]
Message-ID: <m1wsw46som.fsf@ebiederm.dsl.xmission.com> (raw)
In-Reply-To: <20070810.110144.117508471.yoshfuji@linux-ipv6.org> (YOSHIFUJI Hideaki's message of "Fri, 10 Aug 2007 11:01:44 +0900 (JST)")
YOSHIFUJI Hideaki / 吉藤英明 <yoshfuji@linux-ipv6.org> writes:
> Hello.
>
> In article <m1hcn8a2rq.fsf_-_@ebiederm.dsl.xmission.com> (at Thu, 09 Aug 2007
> 14:09:29 -0600), ebiederm@xmission.com (Eric W. Biederman) says:
>
>> After going through the kernels sysctl tables several times it has
>> become clear that code review and testing is just not effective in
>> prevent problematic sysctl tables from being used in the stable
>> kernel. I certainly can't seem to fix the problems as fast as
>> they are introduced.
> :
>> The biggest part of the code is the table of valid binary sysctl
>> entries, but since we have frozen our set of binary sysctls this table
>> should not need to change, and it makes it much easier to detect
>> when someone unintentionally adds a new binary sysctl value.
>
> I don't think everyone needs to have this code, so
> it is better to make it configurable via
> CONFIG_SYSCTL_DEBUG or something..., ...no?
I wouldn't reject such a patch. We are a ways out from the next
stable kernel merge window and I'd love to see what else falls out so
I'd like to have it on by default for a bit.
Eric
next prev parent reply other threads:[~2007-08-10 2:35 UTC|newest]
Thread overview: 35+ messages / expand[flat|nested] mbox.gz Atom feed top
2007-07-26 16:45 [PATCH] Remove CTL_UNNUMBERED Alexey Dobriyan
2007-07-26 17:24 ` Eric W. Biederman
2007-07-27 14:52 ` Alexey Dobriyan
2007-08-06 12:45 ` [PATCH 2/2] sysctl: remove CTL_UNNUMBERED Alexey Dobriyan
2007-08-09 19:44 ` Eric W. Biederman
2007-08-09 19:50 ` [PATCH 1/3] sysctl core: Stop using the unnecessary ctl_table typedef Eric W. Biederman
2007-08-09 19:52 ` [PATCH 2/3] sysctl: Factor out sysctl_data Eric W. Biederman
2007-08-09 20:09 ` [PATCH 3/3] sysctl: Error on bad sysctl tables Eric W. Biederman
2007-08-10 0:49 ` [PATCH 01/10] sysctl: Update sysctl_check_table Eric W. Biederman
2007-08-10 0:51 ` [PATCH 02/10] sysct mqueue: Remove the binary sysctl numbers Eric W. Biederman
2007-08-10 0:53 ` [PATCH 03/10] sysctl: Remove binary sysctl support where it clearly doesn't work Eric W. Biederman
2007-08-10 0:56 ` [PATCH 04/10] sysctl: Fix neighbour table sysctls Eric W. Biederman
2007-08-10 0:57 ` [PATCH 05/10] sysctl: ipv6 route flushing (kill binary path) Eric W. Biederman
2007-08-10 0:58 ` [PATCH 06/10] sysctl: Remove broken sunrpc debug binary sysctls Eric W. Biederman
2007-08-10 0:59 ` [PATCH 07/10] sysctl: x86_64 remove unnecessary binary paths Eric W. Biederman
2007-08-10 1:01 ` [PATCH 08/10] sysctl: Remove broken cdrom binary sysctls Eric W. Biederman
2007-08-10 1:02 ` [PATCH 09/10] sysctl: ipv4 remove binary sysctl paths where they are broken Eric W. Biederman
2007-08-10 1:03 ` [PATCH 10/10] sysctl: Remove the binary interface for aio-nr, aio-max-nr, acpi_video_flags Eric W. Biederman
2007-08-10 13:33 ` [PATCH 08/10] sysctl: Remove broken cdrom binary sysctls Alan Cox
2007-08-10 15:55 ` Eric W. Biederman
2007-08-10 17:16 ` Alan Cox
2007-08-10 18:30 ` Eric W. Biederman
2007-08-10 1:04 ` [PATCH 06/10] sysctl: Remove broken sunrpc debug " Eric W. Biederman
2007-08-10 1:47 ` [PATCH 04/10] sysctl: Fix neighbour table sysctls YOSHIFUJI Hideaki / 吉藤英明
2007-08-10 1:49 ` David Miller
2007-08-10 2:14 ` YOSHIFUJI Hideaki / 吉藤英明
2007-08-10 2:23 ` Eric W. Biederman
2007-08-10 2:29 ` YOSHIFUJI Hideaki / 吉藤英明
2007-08-10 2:35 ` Eric W. Biederman
2007-08-10 1:55 ` Andrew Morton
2007-08-10 2:12 ` Eric W. Biederman
2007-08-10 2:22 ` YOSHIFUJI Hideaki / 吉藤英明
2007-08-10 2:01 ` [PATCH 3/3] sysctl: Error on bad sysctl tables YOSHIFUJI Hideaki / 吉藤英明
2007-08-10 2:15 ` Eric W. Biederman [this message]
2007-08-10 2:18 ` Eric W. Biederman
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=m1wsw46som.fsf@ebiederm.dsl.xmission.com \
--to=ebiederm@xmission.com \
--cc=adobriyan@sw.ru \
--cc=akpm@linux-foundation.org \
--cc=devel@openvz.org \
--cc=linux-kernel@vger.kernel.org \
--cc=yoshfuji@linux-ipv6.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
Powered by JetHome