Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1693902

Re: [PATCH v3 04/15] selinux: Refactor to remove bprm_secureexec hook

Path csiph.com!aioe.org!bofh.it!news.nic.it!robomod
From Kees Cook <keescook@chromium.org>
Newsgroups linux.kernel
Subject Re: [PATCH v3 04/15] selinux: Refactor to remove bprm_secureexec hook
Date Fri, 21 Jul 2017 19:40:01 +0200
Message-ID <u5K49-7JS-3@gated-at.bofh.it> (permalink)
References <u4Ja9-8f4-3@gated-at.bofh.it> <u4JjP-8ii-3@gated-at.bofh.it> <u57ct-7FH-7@gated-at.bofh.it> <u57ma-7KQ-1@gated-at.bofh.it> <u58BA-51-1@gated-at.bofh.it> <u5k02-8cN-27@gated-at.bofh.it> <u5n7A-1TV-7@gated-at.bofh.it> <u5qyu-3Q5-9@gated-at.bofh.it> <u5IlH-6Ek-15@gated-at.bofh.it>
Dkim-Signature v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20161025; h=mime-version:sender:in-reply-to:references:from:date:message-id :subject:to:cc; bh=yG4GiorpTaVMYoFX2VfL1iX+b+glC9SFOltYIEJjsHY=; b=fQ/OlARexKt0nhWksXA8Z/b094F3il8y6tLf5NGH4rjdgpxyKOYefxp0AbjwXXdEzR Kya32vmJyn+2ZYzeKs+SWihfQQuJlJGdj8y83TAQEdtA56mL3locGlDRnIsV031wRilb kAq4HYTzldxadWsxzMJQAwAxqBM+lg8Ph8yqfA5VuPvAHWnlpLZiCDYwT5JaKkWEW9Hy e3ZTs2XRDucIRW0PgUmACwNzdWEdUXjeb3/s71XYrJTOkg0bKyUr9XCLVLg0Z/lTNBVf fJzDAoTHhcSuRKsiDMeN9gVXwlUP7zBOICYfXvOYjWRN2BmA3gzk4u2IV2917TUxs0WC ioZg==
Dkim-Signature v=1; a=rsa-sha256; c=relaxed/relaxed; d=chromium.org; s=google; h=mime-version:sender:in-reply-to:references:from:date:message-id :subject:to:cc; bh=yG4GiorpTaVMYoFX2VfL1iX+b+glC9SFOltYIEJjsHY=; b=Ujn8Y7LU05GZ3s+clUkVT/zmm0N9vu76AEWrvsXQD/rWJupTljDSO5Y6adhf8inAJJ FPW/YKi0IGKIWbuoOdY0ci7ibasT0Bf8YuBIiijmue3NP9KI94j3kfWn8G0X7X44TXIo ouOKeLl+EwU7QNTFXfdS81f3dZwdJWcb0FjX4=
X-Google-Dkim-Signature v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:sender:in-reply-to:references:from :date:message-id:subject:to:cc; bh=yG4GiorpTaVMYoFX2VfL1iX+b+glC9SFOltYIEJjsHY=; b=Fm/5cx07NcUSmR8IQNNuPDp0DfClaKA4kdVTsJ7Pd0bY2zPyavavotz+Ptc63q2/+o endkTMvns+E6491qP32czLTgwbS5tgCySqHIqwK0t+9igTe/wqY/7Rdo0QQcntFV9Fsm PVlkPyMrOKFqLJBbV1lmqaNODcNQu9dLtNPZ7NlyJN7gf+ZGe6FVjcvWCWtl7ef8H4Ea DERR37mApBXP4QZ3wKy41bLeWRWrOls/87MOxIG9pJaikBRW8Vv+wuMNuKvgtaGn8vcw dweEv9M7NHxt2p/S/I+ikhJnp/9t2snJKQBBD51/nFV7ea0rosuATCs//IDcK2TgGeN8 MWXg==
X-Gm-Message-State AIVw112uyUp6z3k4UQQ3rc+NR89ZrmNKt+37rrTmd/bBm47UvgmFgL3N +2IAQFFheELWZ78h37fveTUQBmm0575W
X-Received by 10.107.156.20 with SMTP id f20mr7742501ioe.239.1500658644798; Fri, 21 Jul 2017 10:37:24 -0700 (PDT)
MIME-Version 1.0
X-Google-Sender-Auth NX86CxgvSpW5o4-YsA50mrvnkuA
Content-Type text/plain; charset="UTF-8"
Sender robomod@news.nic.it
List-ID <linux-kernel.vger.kernel.org>
X-Mailing-List linux-kernel@vger.kernel.org
Approved robomod@news.nic.it
Lines 30
Organization linux.* mail to news gateway
X-Original-Cc Stephen Smalley <sds@tycho.nsa.gov>, Andrew Morton <akpm@linux-foundation.org>, David Howells <dhowells@redhat.com>, "Eric W. Biederman" <ebiederm@xmission.com>, John Johansen <john.johansen@canonical.com>, "Serge E. Hallyn" <serge@hallyn.com>, Casey Schaufler <casey@schaufler-ca.com>, Tetsuo Handa <penguin-kernel@i-love.sakura.ne.jp>, James Morris <james.l.morris@oracle.com>, Andy Lutomirski <luto@kernel.org>, Linus Torvalds <torvalds@linux-foundation.org>, "linux-fsdevel@vger.kernel.org" <linux-fsdevel@vger.kernel.org>, linux-security-module <linux-security-module@vger.kernel.org>, LKML <linux-kernel@vger.kernel.org>
X-Original-Date Fri, 21 Jul 2017 10:37:24 -0700
X-Original-Message-ID <CAGXu5jLT1V_=9Hh-DDJJqvf9Z7ZeaCpLbXnLLZ-e+JTQb2u99w@mail.gmail.com>
X-Original-References <1500416736-49829-1-git-send-email-keescook@chromium.org> <1500416736-49829-5-git-send-email-keescook@chromium.org> <CAHC9VhTLP7kpJW65y_csgnc9hvp8ouB36U2WPyHGYgGtq8M4hg@mail.gmail.com> <CAHC9VhQJxyRF4f1vX6+00uVHbn8DJDBRLPyRFhU4SBQKGcgQMw@mail.gmail.com> <CAGXu5j+ayWRKxn5EneOAJO-XXTo2qsxo-nwKLtjoM60_H6PFOA@mail.gmail.com> <CAHC9VhQRhQAbH4c5ZjdEJy-fcMz=oUrd5F4Q755AHVFZVmFR+w@mail.gmail.com> <CAGXu5j+mFMRKhjSwkzYZ1qMDCoD44g42wYpLBPm3m2Zjq5BwNA@mail.gmail.com> <CAHC9VhQoLxRFFuVSoDPqCS3Gy5fHx5uXxFTcEGCi9d=UWmZkEg@mail.gmail.com> <CAHC9VhTeU3cH3E+SgW+F4sYm6zxdEip0LYR_Ht0O9TDFQrzGMw@mail.gmail.com>
X-Original-Sender linux-kernel-owner@vger.kernel.org
Xref csiph.com linux.kernel:1693902

Show key headers only | View raw


On Fri, Jul 21, 2017 at 8:40 AM, Paul Moore <paul@paul-moore.com> wrote:
> On Thu, Jul 20, 2017 at 4:42 PM, Paul Moore <paul@paul-moore.com> wrote:
>> On Thu, Jul 20, 2017 at 1:06 PM, Kees Cook <keescook@chromium.org> wrote:
>>> On Thu, Jul 20, 2017 at 6:42 AM, Paul Moore <paul@paul-moore.com> wrote:
>>>> Alternatively, if you've got a fairly recent git repo with all the
>>>> patches merged I can build a test kernel and give it a shot for you,
>>>> although fair warning it may take a day or two for me to get to it.
>>>
>>> Hurm, I think this will take quite a bit of time for me to set up. :P
>>> If you have a chance, I'd appreciate it if you could test the series.
>>> It's currently based on v4.12:
>>> https://git.kernel.org/pub/scm/linux/kernel/git/kees/linux.git/log/?h=kspp/setuid-rlimits/secureexec-no-hook
>>>
>>> If it doesn't work out or takes too much time I can work on setting up
>>> the test environment next week (travelling at the moment).
>>
>> Building a kernel now, in case anyone on Fedora wants to play with it,
>> you can find it here (when it finishes):
>>
>> * https://copr.fedorainfracloud.org/coprs/pcmoore/kernel-testing/build/581947
>
> Quick follow up, the kernel above passes the selinux-testsuite atsecure test.

Awesome, thanks for taking the time to test it. :) Can I add your Tested-by?

-Kees

-- 
Kees Cook
Pixel Security

Back to linux.kernel | Previous | NextPrevious in thread | Next in thread | Find similar | Unroll thread


Thread

[PATCH v3 00/15] exec: Use sane stack rlimit under secureexec Kees Cook <keescook@chromium.org> - 2017-07-19 00:30 +0200
  [PATCH v3 05/15] smack: Refactor to remove bprm_secureexec hook Kees Cook <keescook@chromium.org> - 2017-07-19 00:30 +0200
    Re: [PATCH v3 05/15] smack: Refactor to remove bprm_secureexec hook Kees Cook <keescook@chromium.org> - 2017-07-26 06:00 +0200
      Re: [PATCH v3 05/15] smack: Refactor to remove bprm_secureexec hook Casey Schaufler <casey@schaufler-ca.com> - 2017-07-26 20:00 +0200
  [PATCH v3 12/15] smack: Remove redundant pdeath_signal clearing Kees Cook <keescook@chromium.org> - 2017-07-19 00:30 +0200
  [PATCH v3 14/15] exec: Use sane stack rlimit under secureexec Kees Cook <keescook@chromium.org> - 2017-07-19 00:30 +0200
    Re: [PATCH v3 14/15] exec: Use sane stack rlimit under secureexec James Morris <jmorris@namei.org> - 2017-07-19 11:50 +0200
  [PATCH v3 11/15] exec: Use secureexec for clearing pdeath_signal Kees Cook <keescook@chromium.org> - 2017-07-19 00:30 +0200
  [PATCH v3 06/15] commoncap: Refactor to remove bprm_secureexec hook Kees Cook <keescook@chromium.org> - 2017-07-19 00:30 +0200
    Re: [PATCH v3 06/15] commoncap: Refactor to remove bprm_secureexec hook Andy Lutomirski <luto@kernel.org> - 2017-07-19 03:20 +0200
      Re: [PATCH v3 06/15] commoncap: Refactor to remove bprm_secureexec hook Kees Cook <keescook@chromium.org> - 2017-07-19 06:50 +0200
      Re: [PATCH v3 06/15] commoncap: Refactor to remove bprm_secureexec hook Andy Lutomirski <luto@kernel.org> - 2017-07-20 07:00 +0200
    Re: [PATCH v3 06/15] commoncap: Refactor to remove bprm_secureexec  hook James Morris <jmorris@namei.org> - 2017-07-19 11:30 +0200
  [PATCH v3 01/15] binfmt: Introduce secureexec flag Kees Cook <keescook@chromium.org> - 2017-07-19 00:30 +0200
    Re: [PATCH v3 01/15] binfmt: Introduce secureexec flag John Johansen <john.johansen@canonical.com> - 2017-07-19 02:10 +0200
    Re: [PATCH v3 01/15] binfmt: Introduce secureexec flag Andy Lutomirski <luto@kernel.org> - 2017-07-19 03:10 +0200
  [PATCH v3 15/15] exec: Consolidate pdeath_signal clearing Kees Cook <keescook@chromium.org> - 2017-07-19 00:30 +0200
  [PATCH v3 13/15] exec: Consolidate dumpability logic Kees Cook <keescook@chromium.org> - 2017-07-19 00:30 +0200
  [PATCH v3 07/15] commoncap: Move cap_elevated calculation into bprm_set_creds Kees Cook <keescook@chromium.org> - 2017-07-19 00:30 +0200
    Re: [PATCH v3 07/15] commoncap: Move cap_elevated calculation into bprm_set_creds Andy Lutomirski <luto@kernel.org> - 2017-07-19 04:00 +0200
    Re: [PATCH v3 07/15] commoncap: Move cap_elevated calculation into  bprm_set_creds James Morris <jmorris@namei.org> - 2017-07-19 11:30 +0200
  [PATCH v3 10/15] exec: Use secureexec for setting dumpability Kees Cook <keescook@chromium.org> - 2017-07-19 00:30 +0200
    Re: [PATCH v3 10/15] exec: Use secureexec for setting dumpability Kees Cook <keescook@chromium.org> - 2017-07-26 06:00 +0200
  [PATCH v3 04/15] selinux: Refactor to remove bprm_secureexec hook Kees Cook <keescook@chromium.org> - 2017-07-19 00:40 +0200
    Re: [PATCH v3 04/15] selinux: Refactor to remove bprm_secureexec hook Paul Moore <paul@paul-moore.com> - 2017-07-20 02:10 +0200
      Re: [PATCH v3 04/15] selinux: Refactor to remove bprm_secureexec hook Paul Moore <paul@paul-moore.com> - 2017-07-20 02:20 +0200
        Re: [PATCH v3 04/15] selinux: Refactor to remove bprm_secureexec hook Kees Cook <keescook@chromium.org> - 2017-07-20 03:40 +0200
          Re: [PATCH v3 04/15] selinux: Refactor to remove bprm_secureexec hook Paul Moore <paul@paul-moore.com> - 2017-07-20 15:50 +0200
            Re: [PATCH v3 04/15] selinux: Refactor to remove bprm_secureexec hook Kees Cook <keescook@chromium.org> - 2017-07-20 19:10 +0200
              Re: [PATCH v3 04/15] selinux: Refactor to remove bprm_secureexec hook Paul Moore <paul@paul-moore.com> - 2017-07-20 22:50 +0200
                Re: [PATCH v3 04/15] selinux: Refactor to remove bprm_secureexec hook Paul Moore <paul@paul-moore.com> - 2017-07-21 17:50 +0200
                Re: [PATCH v3 04/15] selinux: Refactor to remove bprm_secureexec hook Kees Cook <keescook@chromium.org> - 2017-07-21 19:40 +0200
                Re: [PATCH v3 04/15] selinux: Refactor to remove bprm_secureexec hook Paul Moore <paul@paul-moore.com> - 2017-07-21 21:20 +0200
  [PATCH v3 02/15] exec: Rename bprm->cred_prepared to called_set_creds Kees Cook <keescook@chromium.org> - 2017-07-19 00:40 +0200
    Re: [PATCH v3 02/15] exec: Rename bprm->cred_prepared to  called_set_creds John Johansen <john.johansen@canonical.com> - 2017-07-19 02:10 +0200
    Re: [PATCH v3 02/15] exec: Rename bprm->cred_prepared to called_set_creds Andy Lutomirski <luto@kernel.org> - 2017-07-19 03:10 +0200
      Re: [PATCH v3 02/15] exec: Rename bprm->cred_prepared to called_set_creds Kees Cook <keescook@chromium.org> - 2017-07-19 06:50 +0200
    Re: [PATCH v3 02/15] exec: Rename bprm->cred_prepared to  called_set_creds James Morris <jmorris@namei.org> - 2017-07-19 11:30 +0200
    Re: [PATCH v3 02/15] exec: Rename bprm->cred_prepared to called_set_creds Paul Moore <paul@paul-moore.com> - 2017-07-20 02:00 +0200
  Re: [PATCH v3 00/15] exec: Use sane stack rlimit under secureexec Linus Torvalds <torvalds@linux-foundation.org> - 2017-07-19 01:10 +0200
  Re: [PATCH v3 00/15] exec: Use sane stack rlimit under secureexec "Serge E. Hallyn" <serge@hallyn.com> - 2017-07-19 05:30 +0200
    Re: [PATCH v3 00/15] exec: Use sane stack rlimit under secureexec Kees Cook <keescook@chromium.org> - 2017-07-19 07:30 +0200

csiph-web