From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp-8faa.mail.infomaniak.ch (smtp-8faa.mail.infomaniak.ch [83.166.143.170]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 5AB061922FB for ; Thu, 5 Dec 2024 17:56:36 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=83.166.143.170 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1733421399; cv=none; b=mKcVjGfUVAUlo6Eu6X73NrdAlEOjiu/8d7iRjceL7t6jLKMhbFueqZFHTzJOGaLJsAMbZXDm29Fn/xvnl9RFAqamy/MtvuVmiiTyZ/ZF6Bv8DN2CSgjPMcO5CTr08j8/RnJQ2/LRu0JvhDla1847rqTZSnTywLZwg/pxOe9migo= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1733421399; c=relaxed/simple; bh=91fE6MXNHvHfTG8mh42aiRrYkN/U3yVGkH6W8pDMPgI=; h=Date:From:To:Cc:Subject:Message-ID:References:MIME-Version: Content-Type:Content-Disposition:In-Reply-To; b=hwyQqwth35mo4ZcRvxUjsS73oIb4yA/JOMYSDawgmx+gh5u5EEFORkfWzh/pnJ3GoGvAZls2N/Q3kcPyXm79TydIddRhiM1UF9jId51QWC8gAL+KgKqmApip/TGfUGtsatMTJEJpV9AWtrRCAgjgtaru/Nz0WUcbl3ihqC+uRCw= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=digikod.net; spf=pass smtp.mailfrom=digikod.net; dkim=pass (1024-bit key) header.d=digikod.net header.i=@digikod.net header.b=FZXEghZN; arc=none smtp.client-ip=83.166.143.170 Authentication-Results: smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=digikod.net Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=digikod.net Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=digikod.net header.i=@digikod.net header.b="FZXEghZN" Received: from smtp-3-0001.mail.infomaniak.ch (smtp-3-0001.mail.infomaniak.ch [10.4.36.108]) by smtp-3-3000.mail.infomaniak.ch (Postfix) with ESMTPS id 4Y421P2SvXzsD9; Thu, 5 Dec 2024 18:48:25 +0100 (CET) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=digikod.net; s=20191114; t=1733420905; bh=hi8ArFvU5BqDG4ro/0Wsd51wN4Jn9lVCsIY7xuWXd78=; h=Date:From:To:Cc:Subject:References:In-Reply-To:From; b=FZXEghZNBtryfZ3By/HdncgyfMjMG6/IaRrt2aBigqjpfhCNpFUd6XYRogo64//U5 eJf58QkPnXAFRQyM9ddrm1fZlwvD0JGAUPqJiD1Htq5+dY2jtQaTdOg30X2zv7/z8h +mwr1hKKufgXPBvsjArOPk5itV9+b7tcdWmXjwKA= Received: from unknown by smtp-3-0001.mail.infomaniak.ch (Postfix) with ESMTPA id 4Y421H5gBtzG4R; Thu, 5 Dec 2024 18:48:19 +0100 (CET) Date: Thu, 5 Dec 2024 18:48:17 +0100 From: =?utf-8?Q?Micka=C3=ABl_Sala=C3=BCn?= To: Al Viro , Christian Brauner , Kees Cook , Paul Moore , Serge Hallyn Cc: Adhemerval Zanella Netto , Alejandro Colomar , Aleksa Sarai , Andrew Morton , Andy Lutomirski , Arnd Bergmann , Casey Schaufler , Christian Heimes , Dmitry Vyukov , Elliott Hughes , Eric Biggers , Eric Chiang , Fan Wu , Florian Weimer , Geert Uytterhoeven , James Morris , Jan Kara , Jann Horn , Jeff Xu , Jonathan Corbet , Jordan R Abrahams , Lakshmi Ramasubramanian , Linus Torvalds , Luca Boccassi , Luis Chamberlain , "Madhavan T . Venkataraman" , Matt Bobrowski , Matthew Garrett , Matthew Wilcox , Miklos Szeredi , Mimi Zohar , Nicolas Bouchinet , Roberto Sassu , Scott Shell , Shuah Khan , Shuah Khan , Stephen Rothwell , Steve Dower , Steve Grubb , Theodore Ts'o , Thibaut Sautereau , Vincent Strubel , Xiaoming Ni , kernel-hardening@lists.openwall.com, linux-api@vger.kernel.org, linux-fsdevel@vger.kernel.org, linux-integrity@vger.kernel.org, linux-kernel@vger.kernel.org, linux-security-module@vger.kernel.org Subject: Re: [PATCH v22 0/8] Script execution control (was O_MAYEXEC) Message-ID: <20241205.ohw5cohsee8A@digikod.net> References: <20241205160925.230119-1-mic@digikod.net> Precedence: bulk X-Mailing-List: linux-security-module@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Disposition: inline Content-Transfer-Encoding: 8bit In-Reply-To: <20241205160925.230119-1-mic@digikod.net> X-Infomaniak-Routing: alpha On Thu, Dec 05, 2024 at 05:09:17PM +0100, Mickaël Salaün wrote: > Hi, > > The goal of this patch series is to be able to ensure that direct file > execution (e.g. ./script.sh) and indirect file execution (e.g. sh > script.sh) lead to the same result, especially from a security point of > view. > > The main changes from the previous version are the IMA patch to properly > log access check requests with audit, removal of audit change, an > extended documentation for tailored distros, a rebase on v6.13-rc1, and > some minor cosmetic changes. > > The current status is summarized in this article: > https://lwn.net/Articles/982085/ > I also gave a talk at LPC last month: > https://lpc.events/event/18/contributions/1692/ > And here is a proof of concept for Python (for now, for the previous > version: v19): https://github.com/zooba/spython/pull/12 > > Kees, would you like to take this series in your tree? > > Previous versions > ----------------- > v21: https://lore.kernel.org/r/20241112191858.162021-1-mic@digikod.net > v20: https://lore.kernel.org/r/20241011184422.977903-1-mic@digikod.net > v19: https://lore.kernel.org/r/20240704190137.696169-1-mic@digikod.net > v18: https://lore.kernel.org/r/20220104155024.48023-1-mic@digikod.net > v17: https://lore.kernel.org/r/20211115185304.198460-1-mic@digikod.net > v16: https://lore.kernel.org/r/20211110190626.257017-1-mic@digikod.net > v15: https://lore.kernel.org/r/20211012192410.2356090-1-mic@digikod.net > v14: https://lore.kernel.org/r/20211008104840.1733385-1-mic@digikod.net > v13: https://lore.kernel.org/r/20211007182321.872075-1-mic@digikod.net > v12: https://lore.kernel.org/r/20201203173118.379271-1-mic@digikod.net > v11: https://lore.kernel.org/r/20201019164932.1430614-1-mic@digikod.net > v10: https://lore.kernel.org/r/20200924153228.387737-1-mic@digikod.net > v9: https://lore.kernel.org/r/20200910164612.114215-1-mic@digikod.net > v8: https://lore.kernel.org/r/20200908075956.1069018-1-mic@digikod.net > v7: https://lore.kernel.org/r/20200723171227.446711-1-mic@digikod.net > v6: https://lore.kernel.org/r/20200714181638.45751-1-mic@digikod.net > v5: https://lore.kernel.org/r/20200505153156.925111-1-mic@digikod.net > v4: https://lore.kernel.org/r/20200430132320.699508-1-mic@digikod.net > v3: https://lore.kernel.org/r/20200428175129.634352-1-mic@digikod.net > v2: https://lore.kernel.org/r/20190906152455.22757-1-mic@digikod.net > v1: https://lore.kernel.org/r/20181212081712.32347-1-mic@digikod.net