Re: [PATCH v6] fs: allow protected cross-uid sticky symlinks

From: Kees Cook
Date: Thu Jun 03 2010 - 14:42:14 EST


On Thu, Jun 03, 2010 at 10:41:49AM +0100, Alan Cox wrote:
> > Past objections and rebuttals could be summarized as:
>
> You've forgotten to update this with the list of the objections from your
> last few days postings.

I didn't think the recent discussions added anything thematically new.
"It changes how symlinks work" is a variation on "breaks POSIX", and
"should be done with per-user /tmp" is a variabtion on "userspace should
fix it". I can certainly reword the commit log, though.

> You've forgotten to update it as suggested so its a security policy

It is a sysctl with a CONFIG, which is what Eric Paris was asking for.
I apologize if I missed something, but if there are further improvements
desired, I'm happy to add patches.

> Do you plan to post this daily until we get fed up of seeing it ?

I plan on getting this functionality into the kernel. As such, whenever
I've been directed to improve it before it will be accepted, I will send
an updated version. Having the lifecycle of this patch blocking on me
seems counter-productive and slightly rude.

At this point, I believe I've addressed the specific concerns that Al Viro,
Eric Paris, and a few others pointed out. What else needs fixing?

Thanks,

-Kees

--
Kees Cook
Ubuntu Security Team
--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at http://vger.kernel.org/majordomo-info.html
Please read the FAQ at http://www.tux.org/lkml/