Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1514762

Re: [PATCH 2/2] procfs/tasks: add a simple per-task procfs hidepid= field

Path csiph.com!1.us.feeder.erje.net!feeder.erje.net!2.eu.feeder.erje.net!news.roellig-ltd.de!open-news-network.org!weretis.net!feeder4.news.weretis.net!news.mixmin.net!aioe.org!gothmog.csi.it!bofh.it!news.nic.it!robomod
From Kees Cook <keescook@chromium.org>
Newsgroups linux.kernel
Subject Re: [PATCH 2/2] procfs/tasks: add a simple per-task procfs hidepid= field
Date Thu, 03 Nov 2016 19:10:02 +0100
Message-ID <szuCC-7nG-29@gated-at.bofh.it> (permalink)
References <szshs-5Fc-15@gated-at.bofh.it> <szshs-5Fc-13@gated-at.bofh.it> <szsU9-6ct-11@gated-at.bofh.it> <szusW-742-31@gated-at.bofh.it>
Dkim-Signature v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20120113; h=mime-version:sender:in-reply-to:references:from:date:message-id :subject:to:cc; bh=PvXfztLbO2jUgrIMW5acGsUzhJKgmDMo0nmlBXQo4fE=; b=ekClObdMgRFQff68zvo8EWK6A2v9/rVKE8dB8gFDELyAqdTuEHUn2zTIVfr7yusyc7 S50GLVKNUnPfH1pKZ828Hv5kXt7+zT1BXwdwaVmofC5bb9M7Et9917ayuqprsCg+Mx6M 0xfg7gyBHfrPPvOqkc10j2W4yzfAo4Vxt4eI1rL5cgdq/WmasMe7Vlix0dwuU0JFfFJp LndiDd7sf9raltMmS88pEfyDzh6rdtYjcm/MuaHtQUGDRays1nu6ZGtSn5Kvff4GJTC/ lwbfLv2y0bdsh0p6U072sVOF2u8MYgo2kk50vxw0sfboflaOsvpuKgr1ESDXarGH7nBH O12Q==
Dkim-Signature v=1; a=rsa-sha256; c=relaxed/relaxed; d=chromium.org; s=google; h=mime-version:sender:in-reply-to:references:from:date:message-id :subject:to:cc; bh=PvXfztLbO2jUgrIMW5acGsUzhJKgmDMo0nmlBXQo4fE=; b=MDlPirGx+f4P/sPW3Hanls0/PZIoyo5tNKymRlYt07Ja5tuJmpqkocybeV6r4wUO2c nPaEt7RZt+PoncT1wKZhcgpY9NDsTuTBXPmQdrsxjR4bue3sXO1qLkOIIJl58+hF+7oX pWHu47g/l59vfkrTTP2D7EQYWSRY9EyOKf8aU=
X-Google-Dkim-Signature v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20130820; h=x-gm-message-state:mime-version:sender:in-reply-to:references:from :date:message-id:subject:to:cc; bh=PvXfztLbO2jUgrIMW5acGsUzhJKgmDMo0nmlBXQo4fE=; b=Taag0VD1BAGcf4BDEhjxbeBOp6tJo06/AEJdqZFiCl4+/48KURXYjokF3Ax6MAWjnp H2TgjbrPIoPK6jQwPwR6H24d1Ubn5umlrahqQ3pbK7VXDORcqBFGAhyGIivpiAPMJTth uTSDGPgIBJd6nbHSR2TNM/zTiN+BogPJJ5RAE4H+J6m3uiP9o82koz89CT7p2ct3iAbT 5+UmIVH2ACUGkqx9oFvF51xlwEEdGR0bAqHJ3IfcGpXHfvLLBRZ+gGSi1hyvgM4QQKtV lcaIJjVHbC+2+g8nAtvXxHMBCZBX6HEKzajlvmb0h48NXvIHOduwzayCDnxCGBAawvz0 PWHA==
X-Gm-Message-State ABUngvfXnM/IbMvSVmxqXmlvAtsb1bekXKvcupLB6leBz71mebibYp8MhlxLKif8iuCNrvkJVApifMPIqsfGlvgw
X-Received by 10.28.49.85 with SMTP id x82mr3460543wmx.129.1478196323412; Thu, 03 Nov 2016 11:05:23 -0700 (PDT)
MIME-Version 1.0
X-Google-Sender-Auth dKHaAsskSwFmt1mExv8yR3paokw
Content-Type text/plain; charset=UTF-8
Sender robomod@news.nic.it
List-ID <linux-kernel.vger.kernel.org>
X-Mailing-List linux-kernel@vger.kernel.org
Approved robomod@news.nic.it
Lines 27
Organization linux.* mail to news gateway
X-Original-Cc Lafcadio Wluiki <wluikil@gmail.com>, LKML <linux-kernel@vger.kernel.org>, Andrew Morton <akpm@linux-foundation.org>, "kernel-hardening@lists.openwall.com" <kernel-hardening@lists.openwall.com>, linux-arch <linux-arch@vger.kernel.org>
X-Original-Date Thu, 3 Nov 2016 12:05:22 -0600
X-Original-Message-ID <CAGXu5j+FBu1mnbiPa=fMB8Hgq0iUCdoWGhJKJcBukE4n-iF1+Q@mail.gmail.com>
X-Original-References <1478187038-19954-1-git-send-email-wluikil@gmail.com> <1478187038-19954-2-git-send-email-wluikil@gmail.com> <CAGXu5jLZnkwK3NRV7qy=fi51_W4rP4-jGzeYSwceuvSz7_Ht8g@mail.gmail.com> <20161103175558.GA1177@laptop.thejh.net>
X-Original-Sender linux-kernel-owner@vger.kernel.org
Xref csiph.com linux.kernel:1514762

Show key headers only | View raw


On Thu, Nov 3, 2016 at 11:55 AM, Jann Horn <jann@thejh.net> wrote:
> On Thu, Nov 03, 2016 at 10:12:55AM -0600, Kees Cook wrote:
>> On Thu, Nov 3, 2016 at 9:30 AM, Lafcadio Wluiki <wluikil@gmail.com> wrote:
>> > (Third, rebased submission, since first two submissions yielded no replies.)
>> >
>> > This adds a new per-task hidepid= flag that is honored by procfs when
>> > presenting /proc to the user, in addition to the existing hidepid= mount
>> > option. So far, hidepid= was exclusively a per-pidns setting. Locking
>> > down a set of processes so that they cannot see other user's processes
>> > without affecting the rest of the system thus currently requires
>> > creation of a private PID namespace, with all the complexity it brings,
>> > including maintaining a stub init process as PID 1 and losing the
>> > ability to see processes of the same user on the rest of the system.
> [...]
>> Since this adds a new prctl interface, it's best to Cc linux-arch
>> (which I added now).
>
> Please also CC linux-api for the next iteration, since this is a new
> userspace-facing API.

Oops, thank you. I meant linux-api, not linux-arch. :P

-Kees

-- 
Kees Cook
Nexus Security

Back to linux.kernel | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread


Thread

[PATCH 2/2] procfs/tasks: add a simple per-task procfs hidepid= field Lafcadio Wluiki <wluikil@gmail.com> - 2016-11-03 16:40 +0100
  Re: [PATCH 2/2] procfs/tasks: add a simple per-task procfs hidepid= field Kees Cook <keescook@chromium.org> - 2016-11-03 17:20 +0100
    Re: [PATCH 2/2] procfs/tasks: add a simple per-task procfs hidepid=  field Jann Horn <jann@thejh.net> - 2016-11-03 19:00 +0100
      Re: [PATCH 2/2] procfs/tasks: add a simple per-task procfs hidepid= field Kees Cook <keescook@chromium.org> - 2016-11-03 19:10 +0100
  Re: [2/2] procfs/tasks: add a simple per-task procfs hidepid= field Jann Horn <jann@thejh.net> - 2016-11-03 19:30 +0100
    Re: [2/2] procfs/tasks: add a simple per-task procfs hidepid= field Lafcadio Wluiki <wluikil@gmail.com> - 2016-11-03 21:30 +0100
    Re: [2/2] procfs/tasks: add a simple per-task procfs hidepid= field Kees Cook <keescook@chromium.org> - 2016-11-03 21:40 +0100
      Re: [kernel-hardening] Re: [2/2] procfs/tasks: add a simple per-task  procfs hidepid= field Jann Horn <jann@thejh.net> - 2016-11-03 21:50 +0100

csiph-web