Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Date: Mon, 10 Aug 2020 22:09:09 +0000
From: David Laight <David.Laight@...LAB.COM>
To: 'Al Viro' <viro@...iv.linux.org.uk>, Mickaël Salaün
	<mic@...ikod.net>
CC: Kees Cook <keescook@...omium.org>, Andrew Morton
	<akpm@...ux-foundation.org>, "linux-kernel@...r.kernel.org"
	<linux-kernel@...r.kernel.org>, Aleksa Sarai <cyphar@...har.com>, "Alexei
 Starovoitov" <ast@...nel.org>, Andy Lutomirski <luto@...nel.org>, "Christian
 Brauner" <christian.brauner@...ntu.com>, Christian Heimes
	<christian@...hon.org>, Daniel Borkmann <daniel@...earbox.net>, Deven Bowers
	<deven.desai@...ux.microsoft.com>, Dmitry Vyukov <dvyukov@...gle.com>, "Eric
 Biggers" <ebiggers@...nel.org>, Eric Chiang <ericchiang@...gle.com>, "Florian
 Weimer" <fweimer@...hat.com>, James Morris <jmorris@...ei.org>, Jan Kara
	<jack@...e.cz>, Jann Horn <jannh@...gle.com>, Jonathan Corbet
	<corbet@....net>, Lakshmi Ramasubramanian <nramas@...ux.microsoft.com>,
	Matthew Garrett <mjg59@...gle.com>, Matthew Wilcox <willy@...radead.org>,
	Michael Kerrisk <mtk.manpages@...il.com>, Mimi Zohar <zohar@...ux.ibm.com>,
	Philippe Trébuchet <philippe.trebuchet@....gouv.fr>,
	"Scott Shell" <scottsh@...rosoft.com>, Sean Christopherson
	<sean.j.christopherson@...el.com>, Shuah Khan <shuah@...nel.org>, Steve Dower
	<steve.dower@...hon.org>, Steve Grubb <sgrubb@...hat.com>, Tetsuo Handa
	<penguin-kernel@...ove.sakura.ne.jp>, Thibaut Sautereau
	<thibaut.sautereau@...p-os.org>, Vincent Strubel
	<vincent.strubel@....gouv.fr>, "kernel-hardening@...ts.openwall.com"
	<kernel-hardening@...ts.openwall.com>, "linux-api@...r.kernel.org"
	<linux-api@...r.kernel.org>, "linux-integrity@...r.kernel.org"
	<linux-integrity@...r.kernel.org>, "linux-security-module@...r.kernel.org"
	<linux-security-module@...r.kernel.org>, "linux-fsdevel@...r.kernel.org"
	<linux-fsdevel@...r.kernel.org>
Subject: RE: [PATCH v7 0/7] Add support for O_MAYEXEC

> On Mon, Aug 10, 2020 at 10:11:53PM +0200, Mickaël Salaün wrote:
> > It seems that there is no more complains nor questions. Do you want me
> > to send another series to fix the order of the S-o-b in patch 7?
> 
> There is a major question regarding the API design and the choice of
> hooking that stuff on open().  And I have not heard anything resembling
> a coherent answer.

To me O_MAYEXEC is just the wrong name.
The bit would be (something like) O_INTERPRET to indicate
what you want to do with the contents.

The kernel 'policy' then decides whether that needs 'r-x'
access or whether 'r--' access in enough.

I think that is what you 100 line comment in 0/n means.

	David

-
Registered Address Lakeside, Bramley Road, Mount Farm, Milton Keynes, MK1 1PT, UK
Registration No: 1397386 (Wales)

Powered by blists - more mailing lists

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.