linux-kernel March 2009 archive
Main Archive Page > Month Archives  > linux-kernel archives
linux-kernel: Re: [PATCH] CRED: Fix check_unsafe_exec()

Re: [PATCH] CRED: Fix check_unsafe_exec()

From: Hugh Dickins <hugh_at_nospam>
Date: Thu Mar 19 2009 - 18:44:12 GMT
To: Joe Malicki <jmalicki@metacarta.com>


On Tue, 17 Mar 2009, Joe Malicki wrote:
> ----- "Joe Malicki" <jmalicki@metacarta.com> wrote:
> > ----- "Hugh Dickins" <hugh@veritas.com> wrote:
> > > Yes, I'm inclined to go with that, and removing the files->count
> > > check from exec.c. Joe, did you manage to try your testing with
> > > my original patch plus that files->count check removed from 2.6.28's
> > > unsafe_exec()?
> >
> > Sorry for not responding earlier.
> >
> > I still got one failure with this new patch. I added some printks
> > to illuminate exactly why it's failing when it fails to setuid, but
> > of course, since adding the printks I haven't reproduced yet.
>
> My tests were accidentally run without removing the files->count check.

Oh good, thanks Joe, I was hoping that would be the case.

> The printks confirmed the failure case was the files->count check,
> and removing the files->check has worked thus far (though I can't be
> sure until after a day or two has gone by given how infrequent it is).

Okay, unless we hear bad news from you later, I'll post the set of three patches (removing the files->count check, then my original fs->count one, plus David's comment) in a day or two, adding a few more Ccs.

Hugh -- To unsubscribe from this list: send the line "unsubscribe linux-security-module" in the body of a message to majordomo@vger.kernel.org More majordomo info at http://vger.kernel.org/majordomo-info.html