Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1402539

[PATCH v2] exec: clarify reasoning for euid/egid reset

Path csiph.com!aioe.org!bofh.it!news.nic.it!robomod
From Kees Cook <keescook@chromium.org>
Newsgroups linux.kernel
Subject [PATCH v2] exec: clarify reasoning for euid/egid reset
Date Tue, 17 May 2016 21:20:01 +0200
Message-ID <rzSH7-aP-5@gated-at.bofh.it> (permalink)
X-Original-To Jonathan Corbet <corbet@lwn.net>
Dkim-Signature v=1; a=rsa-sha256; c=relaxed/relaxed; d=chromium.org; s=google; h=date:from:to:cc:subject:message-id:mime-version:content-disposition; bh=AXYaGsqe+mSfOXJsZj6AsHCNDXaPncr71BHto9GUEKI=; b=QlbEIZnXCcamjXfL0htK/SwEeZN3xRcT/BFnzLQnIxQrrADAmty/s9epqjvPrB+wrn KPNxdZhFKkFLz5anDRO3eLCus9ptxXloIiCCaDk2EpvsS9/8Xz3H4XuUiNGA2nVOPWZu 3Olek4p3fIANanQVic132JMngdNYfYf+IPjW0=
X-Google-Dkim-Signature v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20130820; h=x-gm-message-state:date:from:to:cc:subject:message-id:mime-version :content-disposition; bh=AXYaGsqe+mSfOXJsZj6AsHCNDXaPncr71BHto9GUEKI=; b=bJFMKnjk33e0qXSGWZPWY9dNVP/BQvFIQu66TmWOWnUvR/egXmc0eak3zThWjSJKlC Az1Jd3xc1a1Fdhp5ffzNBKkZWTswrCnoTmySqZxWN8Pbb4/oEl8dirgroFdK7ebGfrOu YCWSPZPRNtqgxHIAJMwpMRj4GLOpJfVXWB4myvNTspgjJHs5gFbXKDkGam6gzr4ZgLN6 CSaTuGbOZwyb9v9bz6JuO8RSm8gWwKme+v8mqw3e73EYWj4YTHaKLDTXDEsBLVUaQqh7 Wj8HBKvyhlTAbUoefm0SDaMIJOVKt4EfUG3eDL5Me98qvl+93mJg55HVfR4zuxGr0rdw w0mg==
X-Gm-Message-State AOPr4FWCqNwZoORtD1q5gTOZbW3LH9+Cc0oE1nTUOHnJSI2QZA2Lf401nXVN4hutw8zM7w==
X-Received by 10.98.29.16 with SMTP id d16mr4478209pfd.142.1463512481633; Tue, 17 May 2016 12:14:41 -0700 (PDT)
MIME-Version 1.0
Content-Type text/plain; charset=us-ascii
Content-Disposition inline
Sender robomod@news.nic.it
List-ID <linux-kernel.vger.kernel.org>
X-Mailing-List linux-kernel@vger.kernel.org
Approved robomod@news.nic.it
Lines 37
Organization linux.* mail to news gateway
X-Original-Cc David Howells <dhowells@redhat.com>, Linus Torvalds <torvalds@linux-foundation.org>, Serge Hallyn <serge.hallyn@ubuntu.com>, Willy Tarreau <w@1wt.eu>, linux-doc@vger.kernel.org, Alexander Viro <viro@zeniv.linux.org.uk>, linux-fsdevel@vger.kernel.org, linux-kernel@vger.kernel.org
X-Original-Date Tue, 17 May 2016 12:14:39 -0700
X-Original-Message-ID <20160517191439.GA29657@www.outflux.net>
X-Original-Sender linux-kernel-owner@vger.kernel.org
Xref csiph.com linux.kernel:1402539

Show key headers only | View raw


This section of code initially looks redundant, but is required. This
improves the comment to explain more clearly why the reset is needed.

Signed-off-by: Kees Cook <keescook@chromium.org>
Acked-by: Serge E. Hallyn <serge.hallyn@ubuntu.com>
---
v2:
- clarified example as a setuid script, dhowells
---
 fs/exec.c | 7 ++++++-
 1 file changed, 6 insertions(+), 1 deletion(-)

diff --git a/fs/exec.c b/fs/exec.c
index c4010b8207a1..a98b21d47385 100644
--- a/fs/exec.c
+++ b/fs/exec.c
@@ -1387,7 +1387,12 @@ static void bprm_fill_uid(struct linux_binprm *bprm)
 	kuid_t uid;
 	kgid_t gid;
 
-	/* clear any previous set[ug]id data from a previous binary */
+	/*
+	 * Since this can be called multiple times (via prepare_binprm),
+	 * we must clear any previous work done when setting set[ug]id
+	 * bits from any earlier bprm->file uses (for example when run
+	 * first for a setuid script then again for its interpreter).
+	 */
 	bprm->cred->euid = current_euid();
 	bprm->cred->egid = current_egid();
 
-- 
2.6.3


-- 
Kees Cook
Chrome OS & Brillo Security

Back to linux.kernel | Previous | Next — Next in thread | Find similar | Unroll thread


Thread

[PATCH v2] exec: clarify reasoning for euid/egid reset Kees Cook <keescook@chromium.org> - 2016-05-17 21:20 +0200
  Re: [PATCH v2] exec: clarify reasoning for euid/egid reset Linus Torvalds <torvalds@linux-foundation.org> - 2016-05-17 23:00 +0200

csiph-web