Alexey Gladkov [off-list ref] writes:
On Fri, May 11, 2018 at 03:58:39PM +0200, Jann Horn wrote:
quoted
On Fri, May 11, 2018 at 11:37 AM, Alexey Gladkov
[off-list ref] wrote:
quoted
This allows to hide all files and directories in the procfs that are not
related to tasks.
/proc/$pid/net and /proc/$pid/task/$tid/net aren't in scope for this
protection, even though they contain information about the whole
network namespace of the task, right?
Yes. The pidonly makes visible only pids subset. You can still access the
process namespaces via /proc/$pid/ns.
We can think of additional constraints since the parameters are not
stored in the pid namespace anymore.
pidonly is fine.
You have to be very careful with this. The existing hidepid option
needs to live in the pid namespace. The issue is if someone is allowed
to mount proc and play with these options as in remount you this may
cause issues.
Eric
--
To unsubscribe from this list: send the line "unsubscribe linux-security-module" in
the body of a message to majordomo at vger.kernel.org
More majordomo info at http://vger.kernel.org/majordomo-info.html