Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1624397 > unrolled thread

[RESEND PATCH] tools/power/x86/intel_pstate_tracer: Adjust directory permissions

Started byDoug Smythies <doug.smythies@gmail.com>
First post2017-04-16 17:20 +0200
Last post2017-04-18 02:20 +0200
Articles 3 — 3 participants

Back to article view | Back to linux.kernel


Contents

  [RESEND PATCH] tools/power/x86/intel_pstate_tracer: Adjust directory permissions Doug Smythies <doug.smythies@gmail.com> - 2017-04-16 17:20 +0200
    Re: [RESEND PATCH] tools/power/x86/intel_pstate_tracer: Adjust  directory permissions "Rafael J. Wysocki" <rafael@kernel.org> - 2017-04-17 01:00 +0200
    RE: [RESEND PATCH] tools/power/x86/intel_pstate_tracer: Adjust directory permissions "Doug Smythies" <dsmythies@telus.net> - 2017-04-18 02:20 +0200

#1624397 — [RESEND PATCH] tools/power/x86/intel_pstate_tracer: Adjust directory permissions

FromDoug Smythies <doug.smythies@gmail.com>
Date2017-04-16 17:20 +0200
Subject[RESEND PATCH] tools/power/x86/intel_pstate_tracer: Adjust directory permissions
Message-ID<twU82-5dS-3@gated-at.bofh.it>
Depending on what is being done, the intel_pstate_tracer.py script
needs to be run as root, or can be run as a regular user.
If run the first time as root the results directory will be
incorrect for any subsequent run as a regular user. For any run
as root the specific testname subdirectory will not allow any
subsequent file saves by a regular user. Typically, and for example,
the regular user might be attempting to save a .csv file converted to
a spreadsheet with added calculations or graphs.

Override the default folder permissions.

Signed-off-by: Doug Smythies <dsmythies@telus.net>
---
 tools/power/x86/intel_pstate_tracer/intel_pstate_tracer.py | 6 ++++++
 1 file changed, 6 insertions(+)

diff --git a/tools/power/x86/intel_pstate_tracer/intel_pstate_tracer.py b/tools/power/x86/intel_pstate_tracer/intel_pstate_tracer.py
index fd706ac..7c855508 100755
--- a/tools/power/x86/intel_pstate_tracer/intel_pstate_tracer.py
+++ b/tools/power/x86/intel_pstate_tracer/intel_pstate_tracer.py
@@ -517,13 +517,19 @@ else:
         cpu_mask[i] = 1
 
 if not os.path.exists('results'):
+    # Setting permissions with the mode option doesn't work on all platforms
     os.mkdir('results')
+    # so use chmod to set them. Needed because user may or may not be root.
+    os.chmod('results', 0777)
 
 os.chdir('results')
 if os.path.exists(testname):
     print('The test name directory already exists. Please provide a unique test name. Test re-run not supported, yet.')
     sys.exit()
+# Setting permissions with the mode option doesn't work on all platforms
 os.mkdir(testname)
+os.chmod(testname, 0777)
+# so use chmod to set them. Needed because user may or may not be root.
 os.chdir(testname)
 
 # Temporary (or perhaps not)
-- 
2.7.4

[toc] | [next] | [standalone]


#1624481 — Re: [RESEND PATCH] tools/power/x86/intel_pstate_tracer: Adjust directory permissions

From"Rafael J. Wysocki" <rafael@kernel.org>
Date2017-04-17 01:00 +0200
SubjectRe: [RESEND PATCH] tools/power/x86/intel_pstate_tracer: Adjust directory permissions
Message-ID<tx1jb-12F-5@gated-at.bofh.it>
In reply to#1624397
On Sun, Apr 16, 2017 at 5:17 PM, Doug Smythies <doug.smythies@gmail.com> wrote:
> Depending on what is being done, the intel_pstate_tracer.py script
> needs to be run as root, or can be run as a regular user.
> If run the first time as root the results directory will be
> incorrect for any subsequent run as a regular user.

Which is OK.

For security reasons, non-root should not be able to modify root-owned
directories.

Thanks,
Rafael

[toc] | [prev] | [next] | [standalone]


#1624969

From"Doug Smythies" <dsmythies@telus.net>
Date2017-04-18 02:20 +0200
Message-ID<txp2a-7y8-1@gated-at.bofh.it>
In reply to#1624397
On 2107.04.16 15:57 Rafael J. Wysocki wrote:
> On Sun, Apr 16, 2017 at 5:17 PM, Doug Smythies <doug.smythies@gmail.com> wrote:
>> Depending on what is being done, the intel_pstate_tracer.py script
>> needs to be run as root, or can be run as a regular user.
>> If run the first time as root the results directory will be
>> incorrect for any subsequent run as a regular user.
>
> Which is OK.
>
> For security reasons, non-root should not be able to modify root-owned
> directories.

Hi Rafael,

I do not see a security issue here.

The objective was to merge what used to be
two steps (with the old, never released, post processing tools)
into one step. The only reason "root" was ever needed was for
the actual trace step. In the past everything else could be
done as a regular user. Even when the two step method is used
and we are processing a previously acquired (as "root"), it is
preferred to do so as a regular user.

Anyway, in a minute I will send a version 2 of the patch, where
the user and group IDs are changed to regular user, rather than
changing permissions.

... Doug

[toc] | [prev] | [standalone]


Back to top | Article view | linux.kernel


csiph-web