| From: |
| Mickaël Salaün <mic-AT-digikod.net> |
| To: |
| Al Viro <viro-AT-zeniv.linux.org.uk>, James Morris <jmorris-AT-namei.org>, Serge Hallyn <serge-AT-hallyn.com> |
| Subject: |
| [PATCH v4 0/1] Unprivileged chroot |
| Date: |
| Tue, 16 Mar 2021 18:01:34 +0100 |
| Message-ID: |
| <20210316170135.226381-1-mic@digikod.net> |
| Cc: |
| Mickaël Salaün <mic-AT-digikod.net>, Andy Lutomirski <luto-AT-amacapital.net>, Casey Schaufler <casey-AT-schaufler-ca.com>, Christian Brauner <christian.brauner-AT-ubuntu.com>, Christoph Hellwig <hch-AT-lst.de>, David Howells <dhowells-AT-redhat.com>, Dominik Brodowski <linux-AT-dominikbrodowski.net>, "Eric W . Biederman" <ebiederm-AT-xmission.com>, John Johansen <john.johansen-AT-canonical.com>, Kees Cook <keescook-AT-chromium.org>, Kentaro Takeda <takedakn-AT-nttdata.co.jp>, Tetsuo Handa <penguin-kernel-AT-i-love.sakura.ne.jp>, kernel-hardening-AT-lists.openwall.com, linux-fsdevel-AT-vger.kernel.org, linux-kernel-AT-vger.kernel.org, linux-security-module-AT-vger.kernel.org |
| Archive-link: |
| Article |
Hi,
This new patch group the current task security checks in a dedicated
helper current_chroot_allowed() and extend the patch description.
The chroot system call is currently limited to be used by processes with
the CAP_SYS_CHROOT capability. This protects against malicious
procesess willing to trick SUID-like binaries. The following patch
allows unprivileged users to safely use chroot(2), which may be
complementary to the use of user namespaces.
This patch is a follow-up of a previous one sent by Andy Lutomirski some
time ago:
https://lore.kernel.org/lkml/0e2f0f54e19bff53a3739ecfddb4...
This patch can be applied on top of v5.12-rc3 . I would really
appreciate constructive reviews.
Previous versions:
v3: https://lore.kernel.org/r/20210311105242.874506-1-mic@dig...
v2: https://lore.kernel.org/r/20210310181857.401675-1-mic@dig...
v1: https://lore.kernel.org/r/20210310161000.382796-1-mic@dig...
Regards,
Mickaël Salaün (1):
fs: Allow no_new_privs tasks to call chroot(2)
fs/open.c | 23 +++++++++++++++++++++--
1 file changed, 21 insertions(+), 2 deletions(-)
base-commit: 1e28eed17697bcf343c6743f0028cc3b5dd88bf0
--
2.30.2