From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from mail202.messagelabs.com (mail202.messagelabs.com [216.82.254.227]) by kanga.kvack.org (Postfix) with SMTP id 0CA5B5F0019 for ; Wed, 3 Jun 2009 12:32:08 -0400 (EDT) Received: by wf-out-1314.google.com with SMTP id 25so48244wfa.11 for ; Wed, 03 Jun 2009 09:32:07 -0700 (PDT) MIME-Version: 1.0 In-Reply-To: References: <20090530192829.GK6535@oblivion.subreption.com> <20090531022158.GA9033@oblivion.subreption.com> <20090602203405.GC6701@oblivion.subreption.com> <7e0fb38c0906030922u3af8c2abi8a2cfdcd66151a5a@mail.gmail.com> Date: Wed, 3 Jun 2009 12:32:07 -0400 Message-ID: <7e0fb38c0906030932o28d5c963y8059672e5c2c7ecf@mail.gmail.com> Subject: Re: Security fix for remapping of page 0 (was [PATCH] Change ZERO_SIZE_PTR to point at unmapped space) From: Eric Paris Content-Type: text/plain; charset=ISO-8859-1 Content-Transfer-Encoding: 7bit Sender: owner-linux-mm@kvack.org To: Linus Torvalds Cc: Christoph Lameter , "Larry H." , linux-mm@kvack.org, Alan Cox , Rik van Riel , linux-kernel@vger.kernel.org, pageexec@freemail.hu List-ID: On Wed, Jun 3, 2009 at 12:28 PM, Linus Torvalds wrote: > > > On Wed, 3 Jun 2009, Eric Paris wrote: >> >> As I recall the only need for CONFIG_SECURITY is for the ability to >> override the check. > > No, if you have SECURITY disabled entirely, the check goes away. I meant 'need' as in the reason I wrapped it in CONFIG_SECURITY, not that you were wrong when you said it disapeared. >> I think I could probably pretty cleanly change it to use >> CAP_SYS_RAWIO/SELinux permissions if CONFIG_SECURITY and just allow it >> for uid=0 in the non-security case? > > We probably should, since the "capability" security version should > generally essentially emulate the regular non-SECURITY case for root. Will poke/patch this afternoon. -Eric -- To unsubscribe, send a message with 'unsubscribe linux-mm' in the body to majordomo@kvack.org. For more info on Linux MM, see: http://www.linux-mm.org/ . Don't email: email@kvack.org