oss-sec mailing list archives
Re: [RFC PATCH RESEND] vfs: Move security_inode_killpriv() after permission checks
From: Ben Hutchings <ben () decadent org uk>
Date: Wed, 21 Jan 2015 20:49:47 +0000
On Wed, 2015-01-21 at 13:54 +0300, Solar Designer wrote:
Ben, all - On Sat, Jan 17, 2015 at 11:26:46PM +0000, Ben Hutchings wrote:chown() and write() should clear all privilege attributes on a file - setuid, setgid, setcap and any other extended privilege attributes. However, any attributes beyond setuid and setgid are managed by the LSM and not directly by the filesystem, so they cannot be set along with the other attributes.[...] First of all, thank you for your work on the Linux kernel! Going forward, I think it may be better to CC this sort of messages to the kernel-hardening list (like it's been done on some occasions before, see below) rather than to oss-security - and only post summary messages to oss-security, separately (not CC'ed to anywhere else).
[...] Sorry, I'd forgotten about that one. I'll try to pick the right list in future. Ben. -- Ben Hutchings Larkinson's Law: All laws are basically false.
Attachment:
signature.asc
Description: This is a digitally signed message part
Current thread:
- [RFC PATCH RESEND] vfs: Move security_inode_killpriv() after permission checks Ben Hutchings (Jan 17)
- Re: [RFC PATCH RESEND] vfs: Move security_inode_killpriv() after permission checks James Morris (Jan 20)
- Re: [RFC PATCH RESEND] vfs: Move security_inode_killpriv() after permission checks Casey Schaufler (Jan 20)
- Re: [RFC PATCH RESEND] vfs: Move security_inode_killpriv() after permission checks Stephen Smalley (Jan 21)
- Re: [RFC PATCH RESEND] vfs: Move security_inode_killpriv() after permission checks Casey Schaufler (Jan 21)
- Re: [RFC PATCH RESEND] vfs: Move security_inode_killpriv() after permission checks Solar Designer (Jan 21)
- Re: [RFC PATCH RESEND] vfs: Move security_inode_killpriv() after permission checks Ben Hutchings (Jan 21)
- Re: [RFC PATCH RESEND] vfs: Move security_inode_killpriv() after permission checks Josh Boyer (Feb 16)
- Re: [RFC PATCH RESEND] vfs: Move security_inode_killpriv() after permission checks James Morris (Jan 20)