Thread (13 messages) 13 messages, 6 authors, 2020-09-14

Re: [RFC PATCH v9 0/3] Add introspect_access(2) (was O_MAYEXEC)

From: Mickaël Salaün <mic@digikod.net>
Date: 2020-09-11 12:18:33
Also in: linux-fsdevel, linux-integrity, linux-security-module, lkml

On 10/09/2020 22:05, Matthew Wilcox wrote:
On Thu, Sep 10, 2020 at 09:00:10PM +0100, Al Viro wrote:
quoted
On Thu, Sep 10, 2020 at 07:40:33PM +0100, Matthew Wilcox wrote:
quoted
On Thu, Sep 10, 2020 at 08:38:21PM +0200, Mickaël Salaün wrote:
quoted
There is also the use case of noexec mounts and file permissions. From
user space point of view, it doesn't matter which kernel component is in
charge of defining the policy. The syscall should then not be tied with
a verification/integrity/signature/appraisal vocabulary, but simply an
access control one.
permission()?
int lsm(int fd, const char *how, char *error, int size);

Seriously, this is "ask LSM to apply special policy to file"; let's
_not_ mess with flags, etc. for that; give it decent bandwidth
and since it's completely opaque for the rest of the kernel,
just a pass a string to be parsed by LSM as it sees fit.
Well, I don't know why you're so angry against LSM, but as noticed by
Matthew, the main focus of this patch series is not about LSM (no hook,
no security/* code, only file permission and mount option checks,
nothing fancy). Moreover, the syscall you're proposing doesn't make
sense, but I guess it's yet another sarcastic reply. Please, cool down.
We asked for constructive comments and already followed your previous
requests (even if we didn't get answers for some questions), but
seriously, this one is nonsense.
Hang on, it does have some things which aren't BD^W^WLSM.  It lets
the interpreter honour the mount -o noexec option.  I presume it's
not easily defeated by
	cat /home/salaun/bin/bad.pl | perl -
Funny. I know there is a lot of text and links but please read the
commit messages before further comments.
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help