Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1712544 > unrolled thread

Re: [PATCH 2/2] Revert "pstore: Honor dmesg_restrict sysctl on dmesg dumps"

Started bySteven Rostedt <rostedt@goodmis.org>
First post2017-08-16 02:30 +0200
Last post2017-08-16 02:40 +0200
Articles 3 — 2 participants

Back to article view | Back to linux.kernel

This discussion starts older than the indexed window; earlier articles aren't shown. The article labeled Started by below is the oldest one visible, not the original post.


Contents

  Re: [PATCH 2/2] Revert "pstore: Honor dmesg_restrict sysctl on  dmesg dumps" Steven Rostedt <rostedt@goodmis.org> - 2017-08-16 02:30 +0200
    Re: [PATCH 2/2] Revert "pstore: Honor dmesg_restrict sysctl on dmesg dumps" Kees Cook <keescook@chromium.org> - 2017-08-16 02:30 +0200
      Re: [PATCH 2/2] Revert "pstore: Honor dmesg_restrict sysctl on  dmesg dumps" Steven Rostedt <rostedt@goodmis.org> - 2017-08-16 02:40 +0200

#1712544 — Re: [PATCH 2/2] Revert "pstore: Honor dmesg_restrict sysctl on dmesg dumps"

FromSteven Rostedt <rostedt@goodmis.org>
Date2017-08-16 02:30 +0200
SubjectRe: [PATCH 2/2] Revert "pstore: Honor dmesg_restrict sysctl on dmesg dumps"
Message-ID<ueUnE-8n1-19@gated-at.bofh.it>
On Thu, 10 Aug 2017 13:36:35 -0700
Kees Cook <keescook@chromium.org> wrote:

> This reverts commit 68c4a4f8abc60c9440ede9cd123d48b78325f7a3, with
> various conflict clean-ups.
> 
> With the default root directory mode set to 0750 now, the capability
> check was redundant.

What's wrong with redundancy?

-- Steve


> 
> Suggested-by: Nick Kralevich <nnk@google.com>
> Signed-off-by: Kees Cook <keescook@chromium.org>
> ---

[toc] | [next] | [standalone]


#1712548 — Re: [PATCH 2/2] Revert "pstore: Honor dmesg_restrict sysctl on dmesg dumps"

FromKees Cook <keescook@chromium.org>
Date2017-08-16 02:30 +0200
SubjectRe: [PATCH 2/2] Revert "pstore: Honor dmesg_restrict sysctl on dmesg dumps"
Message-ID<ueUnE-8n1-27@gated-at.bofh.it>
In reply to#1712544
On Tue, Aug 15, 2017 at 5:21 PM, Steven Rostedt <rostedt@goodmis.org> wrote:
> On Thu, 10 Aug 2017 13:36:35 -0700
> Kees Cook <keescook@chromium.org> wrote:
>
>> This reverts commit 68c4a4f8abc60c9440ede9cd123d48b78325f7a3, with
>> various conflict clean-ups.
>>
>> With the default root directory mode set to 0750 now, the capability
>> check was redundant.
>
> What's wrong with redundancy?

In this case, it actually _blocks_ system builders from being able to
define the access controls on pstore. :(

-Kees

-- 
Kees Cook
Pixel Security

[toc] | [prev] | [next] | [standalone]


#1712550

FromSteven Rostedt <rostedt@goodmis.org>
Date2017-08-16 02:40 +0200
Message-ID<ueUxj-8pZ-1@gated-at.bofh.it>
In reply to#1712548
On Tue, 15 Aug 2017 17:29:38 -0700
Kees Cook <keescook@chromium.org> wrote:

> On Tue, Aug 15, 2017 at 5:21 PM, Steven Rostedt <rostedt@goodmis.org> wrote:
> > On Thu, 10 Aug 2017 13:36:35 -0700
> > Kees Cook <keescook@chromium.org> wrote:
> >  
> >> This reverts commit 68c4a4f8abc60c9440ede9cd123d48b78325f7a3, with
> >> various conflict clean-ups.
> >>
> >> With the default root directory mode set to 0750 now, the capability
> >> check was redundant.  
> >
> > What's wrong with redundancy?  
> 
> In this case, it actually _blocks_ system builders from being able to
> define the access controls on pstore. :(

Then that should be stated in the change log, as it is the real reason
to revert, not just the fact that it is redundant.

Thanks,

-- Steve

[toc] | [prev] | [standalone]


Back to top | Article view | linux.kernel


csiph-web