public inbox for linux-kernel@vger.kernel.org
 help / color / mirror / Atom feed
From: Lionel Bouton <Lionel.Bouton@free.fr>
To: cs@zip.com.au, Linux Kernel List <linux-kernel@vger.kernel.org>
Subject: Re: ISA slot detection on PCI systems?
Date: Thu, 03 Jan 2002 22:15:00 +0100	[thread overview]
Message-ID: <3C34C9D4.4030705@free.fr> (raw)
In-Reply-To: <20020102170833.A17655@thyrsus.com> <E16Lu2i-0005nd-00@the-village.bc.nu> <20020102172448.A18153@thyrsus.com> <3C339219.4040808@free.fr> <20020103144904.A644@zapff.research.canon.com.au>

I made a stupid post elsewhere in this thread and recognised it. But 
here I'm far from convinced I should have shut my big mouth :-p

Cameron Simpson wrote:

> [...]
> | Reading proc files requires running kernel space code, do we have kernel
> | space code running with *user* priviledge now?
> 
> Oh please don't inject (more) noise into this1 Doing ANYTHING involves
> running kerel space code somewhere.


Nothing to do with my point. You can't make usefull code without kernel 
syscalls sure but you don't need kernel code for most of your code.

We speak of code priviledge here. If you put the whole dmidecode in 
kernel space you make it running at full system level priviledge. So 
there's little difference (and in fact favorable to suid solution) to 
the priviledge level of the running code. Point.

Anyway this thread branch is dead, we didn't understand Eric's point 
which was on the level of priviledge the *user* using the code needs.

> It is still possible to talk
> meaningfully about:
> 
> 	- opening a publicly readable file in /proc to get some info,
> 	  which will run some kernel code (which can presumably be trusted;
> 	  if you don't trust your kernel you have a serious problem)


I have different levels of trusting. For example I trust code I've read 
and understood (somehow did program proof) as much as I trust my 
capability to understand the code. So in short I don't fully trust 
anything but have more confidence in some things (experience running it, 
heard good things from people I *trust*, ...).


>     versus
> 
> 	- running a setuid binary (however audited) to get the info; said
> 	  binary may have bugs, security holes, race conditions etc;


These aren't things kernel code is immune to.

> it may be
> 	  hacked post boot (no so easy to do to the live kernel image), etc
> 


Hacked post boot <- security bug outside of dmidecode. If security is of 
concern this bug should be corrected with or without existance of an 
user-level dmidecode.
You mean probability of bug greater out-of-kernel than in-kernel ? I 
don't deal with such things as bug probabilities on corner cases like 
this, sorry. If you have enough security bugs in a corner case of 
reading (not even writing to) /dev/kmem (BIOS tables, not kernel data) 
to make probabilities I don't trust your systems :-p

> Further, binaries which grovel in /dev/kmem tend to have to be kept in sync
> with the kernel;


Read dmidecode.c, it's an exception.

> in-kernel code is fundamentally in sync.
> 

Wrong, history shows there are always parts of the kernel behind.

LB.


  parent reply	other threads:[~2002-01-03 21:15 UTC|newest]

Thread overview: 187+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2002-01-02 20:15 ISA slot detection on PCI systems? Eric S. Raymond
2002-01-02 20:45 ` Jeff Garzik
2002-01-02 20:46 ` Brian Gerst
2002-01-02 20:59 ` Alan Cox
2002-01-02 20:46   ` Eric S. Raymond
2002-01-02 21:13     ` Dave Jones
2002-01-02 21:19     ` Alan Cox
2002-01-02 21:04       ` Eric S. Raymond
2002-01-02 22:34         ` Alan Cox
2002-01-03  9:26         ` Vojtech Pavlik
2002-01-03  8:44     ` Eric W. Biederman
2002-01-03 12:46     ` Horst von Brand
2002-01-04 15:04       ` Kai Henningsen
2002-01-02 21:00   ` Dave Jones
2002-01-02 21:23     ` Bill Nottingham
2002-01-02 21:13       ` Eric S. Raymond
2002-01-02 21:31         ` Dave Jones
2002-01-02 21:30           ` Eric S. Raymond
2002-01-02 21:48             ` Dave Jones
2002-01-02 21:47               ` Eric S. Raymond
2002-01-02 22:12                 ` Dave Jones
2002-01-02 22:08                   ` Eric S. Raymond
2002-01-02 22:39                     ` Alan Cox
2002-01-02 22:24                       ` Eric S. Raymond
2002-01-02 22:50                         ` Alan Cox
2002-01-02 22:34                           ` Eric S. Raymond
2002-01-02 23:09                             ` Alan Cox
2002-01-02 23:09                               ` Eric S. Raymond
2002-01-02 23:52                                 ` Alan Cox
2002-01-02 23:56                                 ` Mike Castle
2002-01-03  0:00                                   ` Dave Jones
2002-01-03  0:37                                     ` Mike Castle
2002-01-03  0:58                                       ` Dave Jones
2002-01-03 13:35                                         ` Horst von Brand
2002-01-03 13:46                                           ` Dave Jones
2002-01-03 16:42                                             ` Horst von Brand
2002-01-03 18:06                                               ` Alex
2002-01-03 18:16                                                 ` Horst von Brand
2002-01-03 18:22                                                 ` Patrick Mochel
2002-01-03 22:26                                                   ` Alan Cox
2002-01-03 22:20                                                     ` Patrick Mochel
2002-01-03 22:31                                                       ` Alan Cox
2002-01-03 18:41                                                 ` Gábor Lénárt
2002-01-03 22:24                                                   ` Alan Cox
2002-01-07 21:56                                                 ` Mark H. Wood
2002-01-03 13:10                             ` Horst von Brand
2002-01-02 22:53                         ` Mike Castle
2002-01-02 23:16                           ` Alan Cox
2002-01-02 23:31                             ` Dave Jones
2002-01-02 23:04                         ` Lionel Bouton
2002-01-03  3:49                           ` Cameron Simpson
2002-01-03  4:03                             ` Dave Jones
2002-01-03  6:46                             ` Mike Castle
2002-01-03 12:35                             ` Alan Cox
2002-01-03 12:39                               ` Vojtech Pavlik
2002-01-05  7:03                                 ` H. Peter Anvin
2002-01-05 17:16                                   ` Albert D. Cahalan
2002-01-05 17:34                                     ` Dave Jones
2002-01-05 20:29                                       ` H. Peter Anvin
2002-01-06  1:19                                         ` Dave Jones
2002-01-06 12:19                                           ` Mr. James W. Laferriere
2002-01-06 13:16                                             ` Dave Jones
2002-01-06 15:26                                               ` Mr. James W. Laferriere
2002-01-06 18:20                                                 ` Dave Jones
2002-01-07 13:35                                                   ` Mr. James W. Laferriere
2002-01-06 21:03                                   ` Vojtech Pavlik
2002-01-06 22:16                                     ` Alan Cox
2002-01-07  7:42                                       ` Vojtech Pavlik
2002-01-03 16:00                               ` Cryto verification of Kernel against Trojan code?? Timothy Covell
2002-01-03 21:58                               ` ISA slot detection on PCI systems? Cameron Simpson
2002-01-03 21:15                             ` Lionel Bouton [this message]
2002-01-03 21:26                               ` Dave Jones
2002-01-05  6:58                         ` H. Peter Anvin
2002-01-02 22:46                     ` Lionel Bouton
2002-01-02 22:51                       ` Dave Jones
2002-01-02 22:48                         ` Eric S. Raymond
2002-01-02 23:10                           ` Dave Jones
2002-01-03  2:10                             ` Eric S. Raymond
2002-01-03  2:44                               ` Dave Jones
2002-01-03  3:03                                 ` Eric S. Raymond
2002-01-03  3:26                                   ` Dave Jones
2002-01-03  3:18                                     ` Eric S. Raymond
2002-01-03  3:36                                       ` Brian Gerst
2002-01-03  3:35                                         ` Eric S. Raymond
2002-01-03  4:15                                           ` Brian Gerst
2002-01-03  4:15                                             ` Eric S. Raymond
2002-01-03  4:27                                               ` Brian Gerst
2002-01-03  4:30                                                 ` Eric S. Raymond
2002-01-03  3:39                                       ` Dave Jones
2002-01-03  3:34                                   ` Brian Gerst
2002-01-03 14:37                                     ` Horst von Brand
2002-01-04  7:09                                     ` [OT] " Paul Duncan
2002-01-03 11:25                                   ` Henrik Hovi
2002-01-05  7:09                                     ` H. Peter Anvin
2002-01-03 14:31                                   ` Horst von Brand
2002-01-03 15:00                                     ` Jesse Pollard
2002-01-03 15:15                                     ` Richard B. Johnson
2002-01-04 15:30                                       ` Kai Henningsen
2002-01-03  5:30                                 ` Andrew Morton
2002-01-03  5:42                                   ` Jeff Garzik
2002-01-03  5:55                                     ` Daniel Phillips
2002-01-03  5:46                                   ` Eric S. Raymond
2002-01-03  9:14                                 ` David Woodhouse
2002-01-03  9:09                                   ` Eric S. Raymond
2002-01-03 12:14                                     ` Alan Cox
2002-01-03 12:34                                       ` Vojtech Pavlik
2002-01-04 18:28                                         ` Maciej W. Rozycki
2002-01-04 19:04                                           ` Vojtech Pavlik
2002-01-04 19:05                                             ` Eric S. Raymond
2002-01-04 19:21                                               ` Vojtech Pavlik
2002-01-04 19:41                                                 ` Eric S. Raymond
2002-01-04 20:09                                                   ` Dave Jones
2002-01-08 12:52                                                     ` Rob Landley
2002-01-04 20:19                                                   ` David Weinehall
2002-01-04 20:30                                                     ` Maciej W. Rozycki
2002-01-04 20:36                                                       ` Eric S. Raymond
2002-01-05  7:12                                                         ` H. Peter Anvin
2002-01-04 20:20                                                   ` Vojtech Pavlik
2002-01-04 20:44                                                     ` Eric S. Raymond
2002-01-04 19:45                                               ` Dave Jones
2002-01-04 19:50                                               ` Maciej W. Rozycki
2002-01-04 19:54                                                 ` Dave Jones
2002-01-04 20:24                                                   ` Maciej W. Rozycki
2002-01-04 20:31                                                     ` Dave Jones
2002-01-04 20:33                                                       ` Eric S. Raymond
2002-01-04 20:56                                                         ` Vojtech Pavlik
2002-01-04 20:57                                                         ` Dave Jones
2002-01-04 20:49                                                           ` Eric S. Raymond
2002-01-04 21:08                                                             ` Dave Jones
2002-01-04 20:59                                                               ` Eric S. Raymond
2002-01-04 21:18                                                                 ` Dave Jones
2002-01-04 21:23                                                                 ` Patrick Mochel
2002-01-05  0:13                                                                 ` Alan Cox
2002-01-04 21:17                                                               ` David Woodhouse
2002-01-04 21:04                                                         ` Charles Cazabon
2002-01-05 17:28                                                         ` Horst von Brand
2002-01-04 19:36                                             ` Maciej W. Rozycki
2002-01-04 19:45                                               ` Vojtech Pavlik
2002-01-04 20:08                                                 ` Maciej W. Rozycki
2002-01-03 16:52                                     ` Rik van Riel
2002-01-03 17:01                                       ` Dave Jones
2002-01-03 17:27                                         ` Eric S. Raymond
2002-01-03  9:24                                   ` David Woodhouse
2002-01-03 14:12                               ` Horst von Brand
2002-01-03  3:07                             ` Greg Hennessy
2002-01-03  9:08                             ` David Woodhouse
2002-01-03  9:03                               ` Eric S. Raymond
2002-01-03 12:20                                 ` Alan Cox
2002-01-03 12:07                                   ` BALBIR SINGH
2002-01-03 12:40                                     ` Alan Cox
2002-01-03 21:44                                       ` Lionel Bouton
2002-01-03 22:17                                         ` David Weinehall
2002-01-04 18:41                                           ` Maciej W. Rozycki
2002-01-03 22:36                                         ` Alan Cox
2002-01-04 12:10                                         ` Alex
2002-01-04 12:20                                           ` Dave Jones
2002-01-04 12:22                                             ` Alex
2002-01-04 12:30                                               ` Dave Jones
2002-01-04 12:47                                                 ` Alex
2002-01-03 12:56                                   ` Urban Widmark
2002-01-03  9:19                               ` David Woodhouse
2002-01-03  9:12                                 ` Eric S. Raymond
2002-01-03  9:31                                 ` David Woodhouse
2002-01-03 10:34                             ` Kai Henningsen
2002-01-03 14:42                               ` Dave Jones
2002-01-04 15:39                                 ` Kai Henningsen
2002-01-02 23:15                           ` Alan Cox
2002-01-02 23:07                             ` Eric S. Raymond
2002-01-02 23:33                               ` Lionel Bouton
2002-01-02 23:37                                 ` Dave Jones
2002-01-03  2:19                                   ` Eric S. Raymond
2002-01-03  2:17                                 ` Eric S. Raymond
2002-01-02 23:19                           ` Mike Castle
2002-01-02 23:23                           ` Lionel Bouton
2002-01-02 23:44                             ` Mike Castle
2002-01-03  0:11                               ` Lionel Bouton
2002-01-03  2:20                             ` Eric S. Raymond
2002-01-05  7:05                           ` H. Peter Anvin
2002-01-05  6:56                     ` H. Peter Anvin
2002-01-03 13:00                 ` Horst von Brand
2002-01-02 21:59               ` Mike Castle
2002-01-02 22:08             ` Alan Cox
2002-01-02 21:22       ` Dave Jones
2002-01-02 21:28 ` Christian Koenig
2002-01-02 22:04   ` Timothy Covell
  -- strict thread matches above, loose matches on Subject: below --
2002-01-04  9:56 Giacomo A. Catenazzi
2002-01-04 10:29 ` Alan Cox

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=3C34C9D4.4030705@free.fr \
    --to=lionel.bouton@free.fr \
    --cc=cs@zip.com.au \
    --cc=linux-kernel@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox