From: Jeff Layton <jlayton@redhat.com>
To: Miklos Szeredi <miklos@szeredi.hu>
Cc: trond.myklebust@fys.uio.no, linux-kernel@vger.kernel.org,
linux-fsdevel@vger.kernel.org, mikulas@artax.karlin.mff.cuni.cz,
zippel@linux-m68k.org, joel.becker@oracle.com,
wli@holomorphy.com, dhowells@redhat.com,
bfennema@falcon.csc.calpoly.edu
Subject: Re: [fuse-devel] [PATCH 01/25] VFS: move attr_kill logic from notify_change into helper function
Date: Tue, 7 Aug 2007 07:27:29 -0400 [thread overview]
Message-ID: <20070807072729.71f15109.jlayton@redhat.com> (raw)
In-Reply-To: <E1III7U-0006ju-00@dorka.pomaz.szeredi.hu>
On Tue, 07 Aug 2007 08:00:40 +0200
Miklos Szeredi <miklos@szeredi.hu> wrote:
> (cutting out lists from CC)
>
> > > > > Your patch is changing the API in a very unsafe way, since there will
> > > > > be no error or warning on an unconverted fs. And that could lead to
> > > > > security holes.
> > > > >
> > > > > If we would rename the setattr method to setattr_new as well as
> > > > > changing it's behavior, that would be fine. But I guess we do not
> > > > > want to do that.
> > > >
> > > > Which "unconverted fses"? If we're talking out of tree stuff, then too
> > > > bad: it is _their_ responsibility to keep up with kernel changes.
> > >
> > > It is usually a good idea to not change the semantics of an API in a
> > > backward incompatible way without changing the syntax as well.
> >
> > We're taking two setattr flags ATTR_KILL_SGID, and ATTR_KILL_SUID which
> > have existed for several years in the VFS, and making them visible to
> > the filesystems. Out-of-tree filesystems that care can check for them in
> > a completely backward compatible way: you don't even need to add a
> > #define.
>
> Making flags visible is not the problem.
>
> Making another flag invisible (ATTR_MODE) at the same time _is_.
>
> > > This is true regardless of whether we care about out-of-tree code or
> > > not (and we should care to some degree). And especially true if the
> > > change in question is security sensitive.
> >
> > It is not true "regardless": the in-tree code is being converted.
> > Out-of-tree code is the only "problem" here, and their only problem is
> > that they may have to add support for the new flags if they also support
> > suid/sgid mode bits.
>
> Yes. And there would be no problem with that, as long as it would be
> breaking the API in a visible way. It does not do that and that is
> unsafe.
>
> The other thing with this change is, that it's generally a good idea
> to let the VFS do as much as possible, because then filesystem writers
> won't get it wrong.
>
> In this case the suid/sgid check needs to be omitted for _very_ few
> filesystems (NFS and fuse). So it makes sense to leave the check
> outside filesystem code, and move it inside only when necessary.
>
On the other hand, the filesystem writers here are declaring their own
setattr operation. Is it unreasonable for them to take responsibility
for handling this too?
There are other in-tree filesystems that likely need to have this check
omitted (other networked filesystems in particular), but this
patchset tries to make this change transparent for now. Those authors
can go back and fix this up later.
As Trond said, in-tree filesystems will be converted so they won't
be an issue. The only danger is someone who is running unconverted
out-of-tree filesystem code on a kernel with this patch. Is that enough
of an issue to warrant us taking extra steps to deal with it?
Another alternative might be to rename notify_change(). I don't really
like gratuitously breaking the API, though, and that function is
referenced in a lot of documentation. Changing it might be confusing...
--
Jeff Layton <jlayton@redhat.com>
next prev parent reply other threads:[~2007-08-07 11:30 UTC|newest]
Thread overview: 14+ messages / expand[flat|nested] mbox.gz Atom feed top
2007-08-06 13:54 [PATCH 01/25] VFS: move attr_kill logic from notify_change into helper function Jeff Layton
[not found] ` <200708061354.l76Ds6sq002260-f+VxlG6Paaj0UfVguI6niVaTQe2KTcn/@public.gmane.org>
2007-08-06 17:43 ` Miklos Szeredi
2007-08-06 18:13 ` [fuse-devel] " Jeff Layton
[not found] ` <20070806141333.0f54ab17.jlayton-H+wXaHxf7aLQT0dZR+AlfA@public.gmane.org>
2007-08-06 18:28 ` Miklos Szeredi
2007-08-06 19:04 ` [fuse-devel] " Trond Myklebust
2007-08-06 19:37 ` Miklos Szeredi
2007-08-06 21:23 ` Trond Myklebust
2007-08-07 6:00 ` Miklos Szeredi
2007-08-07 10:05 ` Miklos Szeredi
2007-08-07 10:21 ` Miklos Szeredi
2007-08-07 11:27 ` Jeff Layton [this message]
2007-08-07 11:53 ` Miklos Szeredi
2007-08-07 20:51 ` Christoph Hellwig
2007-08-07 22:20 ` Jeff Layton
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20070807072729.71f15109.jlayton@redhat.com \
--to=jlayton@redhat.com \
--cc=bfennema@falcon.csc.calpoly.edu \
--cc=dhowells@redhat.com \
--cc=joel.becker@oracle.com \
--cc=linux-fsdevel@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=miklos@szeredi.hu \
--cc=mikulas@artax.karlin.mff.cuni.cz \
--cc=trond.myklebust@fys.uio.no \
--cc=wli@holomorphy.com \
--cc=zippel@linux-m68k.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox