Path: csiph.com!feeder.erje.net!1.eu.feeder.erje.net!weretis.net!feeder7.news.weretis.net!news.mixmin.net!aioe.org!bofh.it!news.nic.it!robomod From: Craig Small Newsgroups: linux.debian.kernel,linux.debian.bugs.dist Subject: Fwd: Bug#920552: procps: Enable regular file and FIFO protection Date: Thu, 31 Jan 2019 06:00:02 +0100 Message-ID: References: X-Original-To: debian-kernel@lists.debian.org X-Mailbox-Line: From debian-kernel-request@lists.debian.org Thu Jan 31 04:50:34 2019 Old-Return-Path: X-Amavis-Spam-Status: No, score=-4.9 tagged_above=-10000 required=5.3 tests=[BAYES_00=-2, DIGITS_LETTERS=1, FOURLA=0.1, HEADER_FROM_DIFFERENT_DOMAINS=0.001, HTML_MESSAGE=2, LDO_WHITELIST=-5, MD5_SHA1_SUM=-1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=-0.001] autolearn=no autolearn_force=no X-Policyd-Weight: NOT_IN_SBL_XBL_SPAMHAUS=-1.5 CL_IP_EQ_HELO_IP=-2 (check from: .enc. - helo: .mail-it1-f173.google. - helo-domain: .google.) FROM/MX_MATCHES_HELO(DOMAIN)=-2; rate: -5.5 X-Google-Dkim-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc; bh=VqSCz2gjmmPwwghD5apqav06mI7ixyamyMEFdF+7SgM=; b=b3UQ+iS7oIpy6CkTs/lhcijHeywNKDp4OrV4UkvL6/Znit0pZFLw3V0V1rMfQFSmRi JKaduUMiFdN/jl7ybsSYcW4NqB9XSno3o0732LRcOBQpiEAUPi9rH1hYlq1D3qtRDh6c PITwbE67h0ozgJc0uNxpMnlzFJRhXekhf7QsjUZICmSJpaFF55OvsPay8QVipnkobWLj kYLGXUJFyuDgOiKP/wigTV2Ozey2rytpQup41rb9+02on/IEEDEe3MChEplJcnsJbOMV lW/H4IfsxQZpP9JIZPwb4/RAOwAu/YiUBkHYOQ95vivP+EB+6DEBpVWPNlSjILNZI8Zl xiMg== X-Gm-Message-State: AJcUukcgsmsBN/3P0L9bsDcetlz/oBf+iwbj0hQ7CA/B9oz1cPWM+hTK bOKb6oWX161Msqcz8QXwkeGtvej59/Uomw== X-Google-SMTP-Source: ALg8bN6HMwtq2dd5YTgd1sCWh7zNT8TUpQoMBDU6KGVmsksJVLObym8y+s1QENzi62tCt4PGJEKAaQ== X-Received: by 2002:a02:8943:: with SMTP id u3mr20055317jaj.92.1548910216311; Wed, 30 Jan 2019 20:50:16 -0800 (PST) X-Received: by 2002:a5e:8704:: with SMTP id y4mr17019578ioj.27.1548910215963; Wed, 30 Jan 2019 20:50:15 -0800 (PST) MIME-Version: 1.0 X-Gmail-Original-Message-ID: Content-Type: multipart/alternative; boundary="0000000000003643f70580b9c360" X-Mailing-List: archive/latest/119408 List-ID: List-URL: List-Archive: https://lists.debian.org/msgid-search/CALy8Cw5LhWYdChNhuFgk7POn=rH3U8Xe8Z1J+8KgbAqPUowSww@mail.gmail.com Approved: robomod@news.nic.it Lines: 159 Organization: linux.* mail to news gateway Sender: robomod@news.nic.it X-Original-Cc: 920552@bugs.debian.org X-Original-Date: Thu, 31 Jan 2019 15:50:04 +1100 X-Original-Message-ID: X-Original-References: <154854078979.11725.8806897076065472334.reportbug@piranha.localnet> Xref: csiph.com linux.debian.kernel:63205 linux.debian.bugs.dist:942240 --0000000000003643f70580b9c360 Content-Type: text/plain; charset="UTF-8" Hi Debian Kernel maintainers, I have had a request to add some kernel system configuration lines in for procps. What is the planned changes for the kernel? The previous bug report which got the protection for hard and soft symlinks had a analogous change occurring in the kernel too, so it was the same either way and was added for non-Debian kernel users. I can't actually see what the Debian systemd people use for sysctl configuration files, I think they use the procps one so the upstream systemd-sysctl change won't mean much here. - Craig ---------- Forwarded message --------- From: Frederik Himpe Date: Sun, 27 Jan 2019 at 09:15 Subject: Bug#920552: procps: Enable regular file and FIFO protection To: Debian Bug Tracking System Package: procps Version: 2:3.3.15-2 Severity: normal In analogy with bug #889098, procps should by default enabling the regular file and FIFO protection added in 4.19 by setting: fs.protected_regular = 1 fs.protected_fifos = 1 This will be done by default in systemd 241, but as Debian does not use Systemd's sysctl settings, it should be made in procps. References: https://github.com/torvalds/linux/commit/30aba6656f https://github.com/systemd/systemd/commit/2732587540035227fe59e4b64b60127352611b35 https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=889098 -- System Information: Debian Release: buster/sid APT prefers unstable-debug APT policy: (500, 'unstable-debug'), (500, 'testing-debug'), (500, 'testing'), (400, 'unstable'), (250, 'stable'), (160, 'experimental'), (100, 'oldstable') Architecture: amd64 (x86_64) Foreign Architectures: i386 Kernel: Linux 4.19.0-1-amd64 (SMP w/12 CPU cores) Locale: LANG=en_GB.UTF-8, LC_CTYPE=en_GB.UTF-8 (charmap=UTF-8), LANGUAGE=en_GB.UTF-8 (charmap=UTF-8) Shell: /bin/sh linked to /bin/dash Init: systemd (via /run/systemd/system) LSM: AppArmor: enabled Versions of packages procps depends on: ii init-system-helpers 1.56+nmu1 ii libc6 2.28-5 ii libncurses6 6.1+20181013-1 ii libncursesw6 6.1+20181013-1 ii libprocps7 2:3.3.15-2 ii libtinfo6 6.1+20181013-1 ii lsb-base 10.2018112800 Versions of packages procps recommends: ii psmisc 23.2-1 procps suggests no packages. -- no debconf information --0000000000003643f70580b9c360 Content-Type: text/html; charset="UTF-8" Content-Transfer-Encoding: quoted-printable
Hi Debian Kernel maintainers,
=C2=A0 I have had a requ= est to add some kernel system configuration lines in for procps.=C2=A0 What= is the planned changes for the kernel? The previous bug report which got t= he protection for hard and soft symlinks had a analogous change occurring i= n the=C2=A0 kernel too, so it was the same either way and was added for non= -Debian kernel users.

I can't actually see what the Debian syste= md people use for sysctl configuration files, I think they use the procps o= ne so the upstream systemd-sysctl change won't mean much here.

=C2=A0- Craig

---------- Forwarded message ---------From: Frederik Himpe <frederik@fr= ehi.be>
Date: Sun, 27 Jan 2019 at 09:15
Subject: Bug#92= 0552: procps: Enable regular file and FIFO protection
To: Debian Bug Tr= acking System <submit@bugs.deb= ian.org>


Package: procps
Version: 2:3.3.15-2
Severity: normal

In analogy with bug #889098, procps should by default enabling the regular = file
and FIFO protection added in 4.19 by setting:

fs.protected_regular =3D 1
fs.protected_fifos =3D 1

This will be done by default in systemd 241, but as Debian does not use
Systemd's sysctl settings, it should be made in procps.

References:
https://github.com/torvalds/linux/commit/30aba665= 6f
https://github.com= /systemd/systemd/commit/2732587540035227fe59e4b64b60127352611b35
https://bugs.debian.org/cgi-bin/bugreport= .cgi?bug=3D889098



-- System Information:
Debian Release: buster/sid
=C2=A0 APT prefers unstable-debug
=C2=A0 APT policy: (500, 'unstable-debug'), (500, 'testing-debu= g'), (500, 'testing'), (400, 'unstable'), (250, 'st= able'), (160, 'experimental'), (100, 'oldstable')
Architecture: amd64 (x86_64)
Foreign Architectures: i386

Kernel: Linux 4.19.0-1-amd64 (SMP w/12 CPU cores)
Locale: LANG=3Den_GB.UTF-8, LC_CTYPE=3Den_GB.UTF-8 (charmap=3DUTF-8), LANGU= AGE=3Den_GB.UTF-8 (charmap=3DUTF-8)
Shell: /bin/sh linked to /bin/dash
Init: systemd (via /run/systemd/system)
LSM: AppArmor: enabled

Versions of packages procps depends on:
ii=C2=A0 init-system-helpers=C2=A0 1.56+nmu1
ii=C2=A0 libc6=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 2.28-= 5
ii=C2=A0 libncurses6=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 6.1+20181013-1
ii=C2=A0 libncursesw6=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A06.1+20181013-1
ii=C2=A0 libprocps7=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A02:3.3.15-2
ii=C2=A0 libtinfo6=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 6.1+20181013-1<= br> ii=C2=A0 lsb-base=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A010.2018112= 800

Versions of packages procps recommends:
ii=C2=A0 psmisc=C2=A0 23.2-1

procps suggests no packages.

-- no debconf information
--0000000000003643f70580b9c360--