Re: [PATCH] Security: Implement and document RLIMIT_NETWORK.

Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
From: Evgeniy Polyakov
Date: Wednesday, January 7, 2009 - 10:48 am

On Wed, Jan 07, 2009 at 06:52:27PM +0200, Rémi Denis-Courmont (rdenis@simphalempin.com) wrote:

If setting that rlimit does not require admin priviledges, then it does
not require to drop this. So it is superuser or admin who does this.
And exactly the same can be achieved with 'owner' iptables module.

If process itself changes own rlimit, then it is not a rlimit, but a
hint to how it is supposed to work.

Plus I did not see how fork is protected, i.e. does children get the
same rlimit, it looks like it does not.


Security and unpriveledged setup are mutually impossible cases.

-- 
	Evgeniy Polyakov
--
To unsubscribe from this list: send the line "unsubscribe netdev" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
RFC: Network privilege separation., Michael Stone, (Tue Jan 6, 10:48 pm)
[PATCH] Security: Implement and document RLIMIT_NETWORK., Michael Stone, (Tue Jan 6, 10:48 pm)
Re: [PATCH] Security: Implement and document RLIMIT_NETWORK., Evgeniy Polyakov, (Wed Jan 7, 4:47 am)
Re: [PATCH] Security: Implement and document RLIMIT_NETWORK., Rémi Denis-Courmont, (Wed Jan 7, 9:52 am)
Re: [PATCH] Security: Implement and document RLIMIT_NETWORK., Evgeniy Polyakov, (Wed Jan 7, 10:48 am)
Re: [PATCH] Security: Implement and document RLIMIT_NETWORK., C. Scott Ananian, (Wed Jan 7, 11:35 am)
Re: [PATCH] Security: Implement and document RLIMIT_NETWORK., Evgeniy Polyakov, (Wed Jan 7, 12:02 pm)
Re: [PATCH] Security: Implement and document RLIMIT_NETWORK., Evgeniy Polyakov, (Wed Jan 7, 12:39 pm)
Re: [PATCH] Security: Implement and document RLIMIT_NETWORK., Rémi Denis-Courmont, (Wed Jan 7, 1:54 pm)
Re: RFC: Network privilege separation., Andi Kleen, (Wed Jan 7, 2:10 pm)
Re: [PATCH] Security: Implement and document RLIMIT_NETWORK., Evgeniy Polyakov, (Wed Jan 7, 2:42 pm)
Re: [PATCH] Security: Implement and document RLIMIT_NETWORK., Evgeniy Polyakov, (Wed Jan 7, 2:59 pm)
Re: RFC: Network privilege separation., Michael Stone, (Wed Jan 7, 7:31 pm)
Re: RFC: Network privilege separation., Andi Kleen, (Wed Jan 7, 8:10 pm)
Re: [PATCH] Security: Implement and document RLIMIT_NETWORK., Evgeniy Polyakov, (Wed Jan 7, 9:27 pm)
Re: RFC: Network privilege separation., Michael Stone, (Wed Jan 7, 9:51 pm)
Re: RFC: Network privilege separation., Andi Kleen, (Wed Jan 7, 10:41 pm)
Re: RFC: Network privilege separation., Oliver Hartkopp, (Thu Jan 8, 12:05 am)
Re: RFC: Network privilege separation., david, (Thu Jan 8, 12:52 am)
Re: RFC: Network privilege separation., Alan Cox, (Thu Jan 8, 3:43 am)
Re: RFC: Network privilege separation., Valdis.Kletnieks, (Mon Jan 12, 11:44 am)
Re: RFC: Network privilege separation., Bryan Donlan, (Mon Jan 12, 12:09 pm)
Re: RFC: Network privilege separation., Andi Kleen, (Mon Jan 12, 12:43 pm)
Re: RFC: Network privilege separation., Rémi Denis-Courmont, (Mon Jan 12, 12:47 pm)
Re: RFC: Network privilege separation., Andi Kleen, (Mon Jan 12, 1:14 pm)
Re: RFC: Network privilege separation., Rémi Denis-Courmont, (Mon Jan 12, 1:15 pm)
Re: RFC: Network privilege separation., Evgeniy Polyakov, (Mon Jan 12, 1:27 pm)
Re: RFC: Network privilege separation., Rémi Denis-Courmont, (Mon Jan 12, 1:30 pm)
Re: RFC: Network privilege separation., Andi Kleen, (Mon Jan 12, 1:39 pm)
Re: RFC: Network privilege separation., Rémi Denis-Courmont, (Mon Jan 12, 1:47 pm)
Re: RFC: Network privilege separation., Andi Kleen, (Mon Jan 12, 1:55 pm)
Re: RFC: Network privilege separation., Andi Kleen, (Mon Jan 12, 2:50 pm)