[kernel-hardening] Re: [PATCH v5 next 5/5] net: modules: use	request_module_cap() to load 'netdev-%s' modules
    Linus Torvalds 
    torvalds at linux-foundation.org
       
    Wed Nov 29 18:53:41 UTC 2017
    
    
  
On Wed, Nov 29, 2017 at 10:46 AM, Linus Torvalds
<torvalds at linux-foundation.org> wrote:
>
> So the module flag is technically easy to add, and it's technically
> easy to read at module loading time, but I suspect that it's actually
> annoyingly hard to pass the original request_module() capability
> information around to where we actually read the module.
One possibly interesting approach would be to run the usermode helper
not as root, but with the credentials of the request_module() caller.
That's arguably the right thing to do (in that request_module() would
never do anything that the user wouldn't be able to do on their own)
and probably what we should have done originally, but while it feels
like a nice solution I suspect it would break pretty much every distro
out there.
Because they all expect modprobe/kmod to be called as root in the
original init-namespace.
                 Linus
--
To unsubscribe from this list: send the line "unsubscribe linux-security-module" in
the body of a message to majordomo at vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
    
    
More information about the Linux-security-module-archive
mailing list