Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.kernel > #60128
| From | Antoine Beaupré <anarcat@debian.org> |
|---|---|
| Newsgroups | linux.debian.bugs.dist, linux.debian.kernel |
| Subject | Bug#889098: enforce fs.protected_hardlinks in sysctl.d by default |
| Date | 2018-02-03 15:50 +0100 |
| Message-ID | <vf7iF-4rQ-1@gated-at.bofh.it> (permalink) |
| References | (2 earlier) <vevn3-4z6-5@gated-at.bofh.it> <veQ89-1wq-3@gated-at.bofh.it> <vf2M2-1v6-11@gated-at.bofh.it> <vevn3-4z6-5@gated-at.bofh.it> <vf2M2-1v6-11@gated-at.bofh.it> |
| Organization | Debian |
Cross-posted to 2 groups.
On 2018-02-03 10:54:18, Salvatore Bonaccorso wrote:
> Hi
>
> On Fri, Feb 02, 2018 at 09:25:31PM +0100, Moritz Mühlenhoff wrote:
>> Antoine Beaupré wrote:
>> > There are, however, people *not* running Debian-built kernels, and
>> > sometimes for good reasons. This is a configuration that we should
>> > still support.
>>
>> Is it supported, but it's also clearly documented that people need to
>> enable this sysctl for custom kernels:
>> https://www.debian.org/releases/jessie/amd64/release-notes/ch-whats-new.en.html#security
>
> Just to add a note: if procps is as well going to ship this hardening
> for fs.protected_hardlinks then I think it would be best to follow the
> kernel and do the same for fs.protected_symlinks as well, not only
> the fs.protected_hardlinks.
Agreed.
>> > Incidentally, I wonder if we should remove the patch we have on the
>> > Debian kernels to change the defaults, and instead rely on the
>> > sysctl. I have added the kernel team in CC to have their input.
>>
>> Why revert the kernel? That doesn't buy us anything. It would be
>> better to ask upstream to revisit this decision (e.g. by contacting
>> KSPP mailing list). I suppose that SuSE, Ubuntu and Red Hat have
>> are shipping similar patches/defaults, so it's probably safe to say
>> that those protections are now the status quo (as opposed to five
>> years ago when that feature was freshly introduced).
>
> Agreed with you and Ben to actually not revert the sane defaults in
> the Debian kernel.
>
> Btw, upstream did initially as well set those, then reverted due to
> some userspace programms breaking, they are/were rare, but the rule is
> to not break userspace (this was done in the referenced commit, "VFS:
> don't do protected {sym,hard}links by default", where it's noted that
> it e.g. broke AFD.)
Right. But we've been running with this as default in Debian for a
while. We also have good mechanisms (config file tracking) to allow
custom changes for users that build their own kernels, although that
might need a release notes update or something because that won't be
flagged by those mechanisms.
A.
--
Drowning people
Sometimes die
Fighting their rescuers.
- Octavia Butler
Back to linux.debian.kernel | Previous | Next — Previous in thread | Find similar | Unroll thread
Bug#889098: enforce fs.protected_hardlinks in sysctl.d by default Antoine Beaupré <anarcat@debian.org> - 2018-02-01 23:20 +0100
Bug#889098: enforce fs.protected_hardlinks in sysctl.d by default Moritz Mühlenhoff <jmm@inutil.org> - 2018-02-02 21:30 +0100
Bug#889098: enforce fs.protected_hardlinks in sysctl.d by default Antoine Beaupré <anarcat@debian.org> - 2018-02-02 23:30 +0100
Bug#889098: enforce fs.protected_hardlinks in sysctl.d by default Craig Small <csmall@debian.org> - 2018-02-03 02:00 +0100
Bug#889098: enforce fs.protected_hardlinks in sysctl.d by default Ben Hutchings <ben@decadent.org.uk> - 2018-02-03 14:20 +0100
Bug#889098: enforce fs.protected_hardlinks in sysctl.d by default Salvatore Bonaccorso <carnil@debian.org> - 2018-02-03 11:00 +0100
Bug#889098: enforce fs.protected_hardlinks in sysctl.d by default Antoine Beaupré <anarcat@debian.org> - 2018-02-03 15:50 +0100
csiph-web