Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.kernel > #1377009
| From | Kees Cook <keescook@chromium.org> |
|---|---|
| Newsgroups | linux.kernel |
| Subject | [PATCH] exec: clarify reasoning for euid/egid reset |
| Date | 2016-04-12 18:50 +0200 |
| Message-ID | <rn9FM-22N-17@gated-at.bofh.it> (permalink) |
| Organization | linux.* mail to news gateway |
This section of code initially looks redundant, but is required. This improves the comment to explain more clearly why the reset is needed. Signed-off-by: Kees Cook <keescook@chromium.org> --- fs/exec.c | 7 ++++++- 1 file changed, 6 insertions(+), 1 deletion(-) diff --git a/fs/exec.c b/fs/exec.c index c4010b8207a1..889221bbfdb3 100644 --- a/fs/exec.c +++ b/fs/exec.c @@ -1387,7 +1387,12 @@ static void bprm_fill_uid(struct linux_binprm *bprm) kuid_t uid; kgid_t gid; - /* clear any previous set[ug]id data from a previous binary */ + /* + * Since this can be called multiple times (via prepare_binprm), + * we must clear any previous work done when setting set[ug]id + * bits from any earlier bprm->file uses (for example when run + * first for a script then for its interpreter). + */ bprm->cred->euid = current_euid(); bprm->cred->egid = current_egid(); -- 2.6.3 -- Kees Cook Chrome OS & Brillo Security
Back to linux.kernel | Previous | Next — Next in thread | Find similar | Unroll thread
[PATCH] exec: clarify reasoning for euid/egid reset Kees Cook <keescook@chromium.org> - 2016-04-12 18:50 +0200 Re: [PATCH] exec: clarify reasoning for euid/egid reset Serge Hallyn <serge.hallyn@ubuntu.com> - 2016-04-12 19:00 +0200 Re: [PATCH] exec: clarify reasoning for euid/egid reset David Howells <dhowells@redhat.com> - 2016-04-12 19:20 +0200
csiph-web