Thread (22 messages) 22 messages, 7 authors, 2015-05-27

Re: [PATCH v2 1/2] capabilities: Ambient capabilities

From: Lukasz Pawelczyk <hidden>
Date: 2015-05-15 11:32:11
Also in: lkml

On czw, 2015-05-14 at 23:39 -0700, Andy Lutomirski wrote:
quoted hunk ↗ jump to hunk
@@ -696,10 +729,18 @@ static inline void cap_emulate_setxuid(struct cred *new, const struct cred *old)
 	     uid_eq(old->suid, root_uid)) &&
 	    (!uid_eq(new->uid, root_uid) &&
 	     !uid_eq(new->euid, root_uid) &&
-	     !uid_eq(new->suid, root_uid)) &&
-	    !issecure(SECURE_KEEP_CAPS)) {
-		cap_clear(new->cap_permitted);
-		cap_clear(new->cap_effective);
+	     !uid_eq(new->suid, root_uid))) {
+		if (!issecure(SECURE_KEEP_CAPS)) {
+			cap_clear(new->cap_permitted);
+			cap_clear(new->cap_effective);
+		}
+
+		/*
+		 * Pre-ambient programs except setresuid to nonroot followed
I think you meant "expect". This typo changes the meaning of the
sentence.
+		 * by exec to drop capabilities.  We should make sure that
+		 * this remains the case.
+		 */
+		cap_clear(new->cap_ambient);
 	}

-- 
Lukasz Pawelczyk

Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help