Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Date: Wed, 21 Jan 2015 20:49:47 +0000
From: Ben Hutchings <ben@...adent.org.uk>
To: Solar Designer <solar@...nwall.com>
Cc: oss-security@...ts.openwall.com
Subject: Re: [RFC PATCH RESEND] vfs: Move
 security_inode_killpriv() after permission checks

On Wed, 2015-01-21 at 13:54 +0300, Solar Designer wrote:
> Ben, all -
> 
> On Sat, Jan 17, 2015 at 11:26:46PM +0000, Ben Hutchings wrote:
> > chown() and write() should clear all privilege attributes on
> > a file - setuid, setgid, setcap and any other extended
> > privilege attributes.
> > 
> > However, any attributes beyond setuid and setgid are managed by the
> > LSM and not directly by the filesystem, so they cannot be set along
> > with the other attributes.
> [...]
> 
> First of all, thank you for your work on the Linux kernel!
> 
> Going forward, I think it may be better to CC this sort of messages to
> the kernel-hardening list (like it's been done on some occasions before,
> see below) rather than to oss-security - and only post summary messages
> to oss-security, separately (not CC'ed to anywhere else).
[...]

Sorry, I'd forgotten about that one.  I'll try to pick the right list in
future.

Ben.

-- 
Ben Hutchings
Larkinson's Law: All laws are basically false.

Download attachment "signature.asc" of type "application/pgp-signature" (812 bytes)

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.