From: Sam James <sam@gentoo.org>
To: David Hildenbrand <david@redhat.com>
Cc: Michael McCracken <michael.mccracken@gmail.com>,
linux-kernel@vger.kernel.org, serge@hallyn.com,
tycho@tycho.pizza, Luis Chamberlain <mcgrof@kernel.org>,
Kees Cook <keescook@chromium.org>,
Iurii Zaikin <yzaikin@google.com>,
Andrew Morton <akpm@linux-foundation.org>,
linux-fsdevel@vger.kernel.org, linux-mm@kvack.org,
kernel-hardening@lists.openwall.com
Subject: Re: [PATCH] sysctl: add config to make randomize_va_space RO
Date: Fri, 05 May 2023 08:46:41 +0100 [thread overview]
Message-ID: <87pm7f9q3q.fsf@gentoo.org> (raw)
In-Reply-To: <fbf37518-328d-c08c-7140-5d09d7a2674f@redhat.com>
[-- Attachment #1: Type: text/plain, Size: 842 bytes --]
David Hildenbrand <david@redhat.com> writes:
> On 04.05.23 23:30, Michael McCracken wrote:
>> Add config RO_RANDMAP_SYSCTL to set the mode of the randomize_va_space
>> sysctl to 0444 to disallow all runtime changes. This will prevent
>> accidental changing of this value by a root service.
>> The config is disabled by default to avoid surprises.
>
> Can you elaborate why we care about "accidental changing of this value
> by a root service"?
>
> We cannot really stop root from doing a lot of stupid things (e.g.,
> erase the root fs), so why do we particularly care here?
(I'm really not defending the utility of this, fwiw).
In the past, I've seen fuzzing tools and other debuggers try to set
it, and it might be that an admin doesn't realise that. But they could
easily set other dangerous settings unsuitable for production, so...
[-- Attachment #2: signature.asc --]
[-- Type: application/pgp-signature, Size: 377 bytes --]
next prev parent reply other threads:[~2023-05-05 7:47 UTC|newest]
Thread overview: 10+ messages / expand[flat|nested] mbox.gz Atom feed top
2023-05-04 21:30 Michael McCracken
2023-05-05 7:35 ` David Hildenbrand
2023-05-05 7:46 ` Sam James [this message]
2023-05-05 15:15 ` David Hildenbrand
2023-05-05 15:16 ` David Hildenbrand
2023-05-05 15:23 ` Paul Moore
2023-05-06 7:04 ` Kaiwan N Billimoria
2023-05-07 19:53 ` Paul Moore
2023-05-15 21:43 ` Serge Hallyn
2023-05-16 20:17 ` Kees Cook
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=87pm7f9q3q.fsf@gentoo.org \
--to=sam@gentoo.org \
--cc=akpm@linux-foundation.org \
--cc=david@redhat.com \
--cc=keescook@chromium.org \
--cc=kernel-hardening@lists.openwall.com \
--cc=linux-fsdevel@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-mm@kvack.org \
--cc=mcgrof@kernel.org \
--cc=michael.mccracken@gmail.com \
--cc=serge@hallyn.com \
--cc=tycho@tycho.pizza \
--cc=yzaikin@google.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox