From: Luca Barbieri <ldb@ldb.ods.org>
To: Alan Cox <alan@lxorguk.ukuu.org.uk>
Cc: Thunder from the hill <thunder@lightweight.ods.org>,
Zheng Jian-Ming <zjm@cis.nctu.edu.tw>,
Linux-Kernel ML <linux-kernel@vger.kernel.org>
Subject: Re: problems with changing UID/GID
Date: 26 Aug 2002 20:49:19 +0200 [thread overview]
Message-ID: <1030387759.1488.22.camel@ldb> (raw)
In-Reply-To: <1030382219.1751.14.camel@irongate.swansea.linux.org.uk>
[-- Attachment #1: Type: text/plain, Size: 744 bytes --]
On Mon, 2002-08-26 at 19:16, Alan Cox wrote:
> On Mon, 2002-08-26 at 15:58, Thunder from the hill wrote:
> > I personally like the task->cred->cr_uid, etc. approach. Helps a lot.
>
> It changes the whole semantics of every security test in Linux, and
> breaks most of them totally. Our syscalls know the uid is constant
> during the call
This is easily fixable by having a shared structure separate from the
private one and propagating modifications only when entering kernel
mode.
If we combine the syscall-trace and cred-propagation checks this can be
done without overhead in the common case (but needs care to avoid
races).
This is similar to what user space would do but faster and transparent.
(BTW, I don't plan to code this myself)
[-- Attachment #2: This is a digitally signed message part --]
[-- Type: application/pgp-signature, Size: 189 bytes --]
next prev parent reply other threads:[~2002-08-27 0:28 UTC|newest]
Thread overview: 24+ messages / expand[flat|nested] mbox.gz Atom feed top
2002-08-26 13:30 problems with changing UID/GID Zheng Jian-Ming
2002-08-26 13:45 ` Alan Cox
2002-08-27 21:21 ` Mike Touloumtzis
2002-08-28 11:51 ` Florian Weimer
2002-08-28 14:01 ` Alan Cox
2002-08-26 14:58 ` Thunder from the hill
2002-08-26 17:16 ` Alan Cox
2002-08-26 17:31 ` Thunder from the hill
2002-08-26 18:47 ` Trond Myklebust
2002-08-26 18:49 ` Luca Barbieri [this message]
2002-08-27 7:54 ` Chris Wedgwood
2002-08-27 15:42 ` Thunder from the hill
2002-08-27 18:12 ` Chris Wedgwood
2002-08-27 19:08 ` Thunder from the hill
2002-08-27 20:00 ` Chris Wedgwood
2002-08-27 20:25 ` Thunder from the hill
2002-08-27 20:52 ` Chris Wedgwood
2002-08-27 19:35 ` Trond Myklebust
2002-08-27 20:01 ` Chris Wedgwood
2002-08-27 22:09 ` Trond Myklebust
2002-08-28 14:24 ` Dave McCracken
2002-08-28 18:30 ` Trond Myklebust
2002-08-28 20:59 ` Dave McCracken
2002-08-28 23:20 ` Trond Myklebust
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=1030387759.1488.22.camel@ldb \
--to=ldb@ldb.ods.org \
--cc=alan@lxorguk.ukuu.org.uk \
--cc=linux-kernel@vger.kernel.org \
--cc=thunder@lightweight.ods.org \
--cc=zjm@cis.nctu.edu.tw \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox