Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1554805

Re: SELinux lead to soft lockup when pid 1 proceess reap child

From Paul Moore <paul@paul-moore.com>
Newsgroups linux.kernel
Subject Re: SELinux lead to soft lockup when pid 1 proceess reap child
Date 2017-01-10 00:50 +0100
Message-ID <sXRRn-26v-5@gated-at.bofh.it> (permalink)
References (2 earlier) <sXMI2-7zO-21@gated-at.bofh.it> <sXMI2-7zO-23@gated-at.bofh.it> <sXMI2-7zO-15@gated-at.bofh.it> <sXMRI-7CY-13@gated-at.bofh.it> <sXNkK-7O3-27@gated-at.bofh.it>
Organization linux.* mail to news gateway

Show all headers | View raw


On Mon, Jan 9, 2017 at 1:43 PM, Stephen Smalley <sds@tycho.nsa.gov> wrote:
> On Mon, 2017-01-09 at 19:29 +0100, Oleg Nesterov wrote:
>> Seriously, could someone explain why do we need the
>> security_task_wait()
>> hook at all?
>
> I would be ok with killing it.
> IIRC, the original motivation was to block an unauthorized data flow
> from child to parent when the child context differs, but part of that
> original design was also to reparent the child automatically, and that
> was never implemented.  I don't think there is a real use case for it
> in practice and it just breaks things, so let's get rid of it unless
> someone objects.

Patches are always welcome, plenty of time to get things in for 4.11 :)

-- 
paul moore
www.paul-moore.com

Back to linux.kernel | Previous | NextPrevious in thread | Next in thread | Find similar | Unroll thread


Thread

Re: SELinux lead to soft lockup when pid 1 proceess reap child Oleg Nesterov <oleg@redhat.com> - 2017-01-09 19:20 +0100
  Re: SELinux lead to soft lockup when pid 1 proceess reap child Oleg Nesterov <oleg@redhat.com> - 2017-01-09 19:30 +0100
    Re: SELinux lead to soft lockup when pid 1 proceess reap child Stephen Smalley <sds@tycho.nsa.gov> - 2017-01-09 20:00 +0100
      Re: SELinux lead to soft lockup when pid 1 proceess reap child Paul Moore <paul@paul-moore.com> - 2017-01-10 00:50 +0100
      Re: SELinux lead to soft lockup when pid 1 proceess reap child Casey Schaufler <casey@schaufler-ca.com> - 2017-01-10 01:30 +0100

csiph-web