Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.devel > #106721

Re: setting sysctl net.ipv4.ping_group_range

From Noah Meyerhans <noahm@debian.org>
Newsgroups linux.debian.devel, linux.debian.bugs.dist
Subject Re: setting sysctl net.ipv4.ping_group_range
Date 2023-01-02 23:00 +0100
Message-ID <FJB0B-f8Rk-5@gated-at.bofh.it> (permalink)
References <FJzBv-f88q-7@gated-at.bofh.it> <FJAnT-f8El-1@gated-at.bofh.it>
Organization linux.* mail to news gateway

Cross-posted to 2 groups.

Show all headers | View raw


On Mon, Jan 02, 2023 at 10:09:44PM +0100, Marco d'Itri wrote:
> > With that in place, unprivileged users are able to excute ping for both
> > IPv4 and IPv6 targets without cap_net_raw (currently set as either a
> > file-based attribute on the ping binary or acquired via setuid).  But
> > since that applies system-wide, not just to the ping binary, there may
> > be objections.
> I do not think that the submitter made clear why this would be 
> preferable, so I had to research it myself. See:
> 
> https://fedoraproject.org/wiki/Changes/EnableSysctlPingGroupRange
> https://github.com/systemd/systemd/pull/13141
> 
> Since this is one of the systemd sysctl defaults (of which I think that 
> we should adopt more, especially the network-related ones!) I agree with 
> changing this.
> I would just do it in the systemd package package to allow all packages 
> to benefit from it without having to care if ping is installed.

I'm entirely happy to reassign this request to systemd and have the
setting applied more broadly.  The question that arises then is what to
do about the file-level capabilities on the ping binary.  Ideally we
drop them entirely (including the setuid fallback), but when?

I could leave things completely decoupled, and simply wait until systemd
makes the change and then upload iputils and assume that anybody
upgrading iputils is also upgrading systemd.  That seems to be what
Fedora did, according to the fedoraproject.org wiki cited above.
Alternatives would seem to involve some level of versioned dependency,
which doesn't feel right.

noah

Back to linux.debian.devel | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread


Thread

setting sysctl net.ipv4.ping_group_range Noah Meyerhans <noahm@debian.org> - 2023-01-02 21:30 +0100
  Re: setting sysctl net.ipv4.ping_group_range Peter Pentchev <roam@ringlet.net> - 2023-01-02 21:50 +0100
    Re: setting sysctl net.ipv4.ping_group_range Marco d'Itri <md@Linux.IT> - 2023-01-02 22:20 +0100
      Re: setting sysctl net.ipv4.ping_group_range Noah Meyerhans <noahm@debian.org> - 2023-01-02 22:50 +0100
  Re: setting sysctl net.ipv4.ping_group_range Marco d'Itri <md@Linux.IT> - 2023-01-02 22:20 +0100
    Re: setting sysctl net.ipv4.ping_group_range Noah Meyerhans <noahm@debian.org> - 2023-01-02 23:00 +0100
      Re: setting sysctl net.ipv4.ping_group_range Marco d'Itri <md@Linux.IT> - 2023-01-03 00:50 +0100
        Re: setting sysctl net.ipv4.ping_group_range Adam Borowski <kilobyte@angband.pl> - 2023-01-03 01:40 +0100
          Re: setting sysctl net.ipv4.ping_group_range Marco d'Itri <md@Linux.IT> - 2023-01-03 03:30 +0100
            Re: setting sysctl net.ipv4.ping_group_range Steve Langasek <vorlon@debian.org> - 2023-01-08 02:10 +0100
              Re: setting sysctl net.ipv4.ping_group_range Ansgar <ansgar@43-1.org> - 2023-01-08 13:40 +0100
      Re: setting sysctl net.ipv4.ping_group_range Ángel <debian-devel@debian.16bits.net> - 2023-01-15 02:40 +0100
        Re: setting sysctl net.ipv4.ping_group_range Bastian Blank <waldi@debian.org> - 2023-01-15 11:40 +0100
  Re: setting sysctl net.ipv4.ping_group_range Helmut Grohne <helmut@subdivi.de> - 2023-04-12 18:10 +0200
    Re: setting sysctl net.ipv4.ping_group_range Marco d'Itri <md@Linux.IT> - 2023-04-12 21:40 +0200

csiph-web