Re: [PATCH 6/7] Add /sys/kernel/notes

!MAILaRCHIVE_VOTE_RePLACE
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
To: Linus Torvalds <torvalds@...>
Cc: Andrew Morton <akpm@...>, <linux-kernel@...>
Date: Wednesday, July 11, 2007 - 6:04 pm

> Yeah, we've made that mistake before, and I'm not saying we are perfect 

It will give them at least as reliable an identification of the kernel
binary as the "uname -rv" info if they have access to a set of candidate
known binaries to select from.  It's of no direct help at all in getting
anything like kernel addresses.  In practice, it is probably no easier for
a rootkit to use than "uname -rv" to pick an exploit for a particular known
distro kernel binary, just easier for legitimate debugging tools.  I think
it's not only more harmless than what you might call "past mistakes", but
is actually just plain harmless.  But I'm not really one to talk a man out
of his paranoia.


I have no special opinions about that, but I haven't seen an install where
the /boot files were not readable anyway.  But certainly in a chroot or
such, you won't have /boot at all but might have /proc and /sys.

All in all, this seems like a question of local policy.  Ideally the modes
would be flexibly chosen by admins, or else constrained more precisely by
SELinux policy or suchlike.  But I have no axe to grind on the subject with
this particular change.  I care more that the feature gets in and at least
root can use it, than about the permissions question.


Thanks,
Roland
-
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
[PATCH 6/7] Add /sys/kernel/notes, Roland McGrath, (Wed Jul 11, 3:04 pm)
Re: [PATCH 6/7] Add /sys/kernel/notes, Andrew Morton, (Wed Jul 11, 7:45 pm)
Re: [PATCH 6/7] Add /sys/kernel/notes, Roland McGrath, (Wed Jul 11, 8:37 pm)
Re: [PATCH 6/7] Add /sys/kernel/notes, Jeremy Fitzhardinge, (Wed Jul 11, 7:57 pm)
Re: [PATCH 6/7] Add /sys/kernel/notes, Roland McGrath, (Wed Jul 11, 8:42 pm)
Re: [PATCH 6/7] Add /sys/kernel/notes, Jeremy Fitzhardinge, (Wed Jul 11, 10:41 pm)
Re: [PATCH 6/7] Add /sys/kernel/notes, Linus Torvalds, (Wed Jul 11, 3:16 pm)
Re: [PATCH 6/7] Add /sys/kernel/notes, Roland McGrath, (Wed Jul 11, 4:51 pm)
Re: [PATCH 6/7] Add /sys/kernel/notes, Linus Torvalds, (Wed Jul 11, 5:45 pm)
Re: [PATCH 6/7] Add /sys/kernel/notes, Roland McGrath, (Wed Jul 11, 6:04 pm)
Re: [PATCH 6/7] Add /sys/kernel/notes, Linus Torvalds, (Wed Jul 11, 6:17 pm)
Re: [PATCH 6/7] Add /sys/kernel/notes, Roland McGrath, (Wed Jul 11, 6:42 pm)
Re: [PATCH 6/7] Add /sys/kernel/notes, Linus Torvalds, (Wed Jul 11, 6:48 pm)