- To: James Morris <jmorris@xxxxxxxxx>
- Subject: Re: [PATCH v18 01/15] Add PR_{GET,SET}_NO_NEW_PRIVS to prevent execve from granting privs
- From: Andy Lutomirski <luto@xxxxxxxxxxxxxx>
- Date: Thu, 12 Apr 2012 21:40:13 -0700
- Cc: Andrew Lutomirski <luto@xxxxxxx>, Will Drewry <wad@xxxxxxxxxxxx>, linux-kernel@xxxxxxxxxxxxxxx, linux-man@xxxxxxxxxxxxxxx, linux-security-module@xxxxxxxxxxxxxxx, linux-arch@xxxxxxxxxxxxxxx, linux-doc@xxxxxxxxxxxxxxx, kernel-hardening@xxxxxxxxxxxxxxxxxx, netdev@xxxxxxxxxxxxxxx, x86@xxxxxxxxxx, arnd@xxxxxxxx, "David S. Miller" <davem@xxxxxxxxxxxxx>, hpa@xxxxxxxxx, mingo@xxxxxxxxxx, Oleg Nesterov <oleg@xxxxxxxxxx>, peterz@xxxxxxxxxxxxx, rdunlap@xxxxxxxxxxxx, mcgrathr@xxxxxxxxxxxx, tglx@xxxxxxxxxxxxx, Eric Paris <eparis@xxxxxxxxxx>, Serge Hallyn <serge.hallyn@xxxxxxxxxxxxx>, djm@xxxxxxxxxxx, scarybeasts@xxxxxxxxx, indan@xxxxxx, pmoore@xxxxxxxxxx, Andrew Morton <akpm@xxxxxxxxxxxxxxxxxxxx>, Jonathan Corbet <corbet@xxxxxxx>, eric.dumazet@xxxxxxxxx, markus@xxxxxxxxxxxx, coreyb@xxxxxxxxxxxxxxxxxx, Kees Cook <keescook@xxxxxxxxxxxx>, Stephen Smalley <sds@xxxxxxxxxxxxx>
- In-reply-to: <alpine.LRH.2.02.1204131432430.22093@tundra.namei.org>
On Thu, Apr 12, 2012 at 9:34 PM, James Morris <jmorris@xxxxxxxxx> wrote:
> On Thu, 12 Apr 2012, Andrew Lutomirski wrote:
>
>> > What about dynamic transitions in SELinux ?
>> >
>>
>> What's a dynamic transition?
>
> The security label can be changed without an exec:
>
> See selinux_setprocattr(), for "current".
Ah.
I see nothing wrong with that, for the same reason I see nothing wrong
with setuid (the system call) after PR_SET_NO_NEW_PRIVS. The
privileges granted by writing to /proc/self/attr/current were already
available in the sense that you could have written to current whenever
you wanted to.
(FWIW, I think that selinux should have made that the only way to
change contexts, full stop. And I think that the setuid and setgid
bits were mistakes. Water under the bridge...)
--Andy
--
To unsubscribe from this list: send the line "unsubscribe linux-man" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at http://vger.kernel.org/majordomo-info.html
[Netdev]
[Linux Ethernet Bridging]
[Linux Wireless]
[Kernel Newbies]
[Memory]
[Security]
[Linux for Hams]
[Netfilter]
[Bugtraq]
[Photo]
[Yosemite]
[Yosemite News]
[MIPS Linux]
[ARM Linux]
[Linux RAID]
[Linux Admin]
[Samba]
[Video 4 Linux]
[Linux Resources]