From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from mail-ua0-f198.google.com (mail-ua0-f198.google.com [209.85.217.198]) by kanga.kvack.org (Postfix) with ESMTP id 1E8F46B0003 for ; Sun, 27 May 2018 10:41:37 -0400 (EDT) Received: by mail-ua0-f198.google.com with SMTP id u23-v6so6956005ual.4 for ; Sun, 27 May 2018 07:41:37 -0700 (PDT) Received: from mail-sor-f65.google.com (mail-sor-f65.google.com. [209.85.220.65]) by mx.google.com with SMTPS id g62-v6sor1992800vkc.155.2018.05.27.07.41.35 for (Google Transport Security); Sun, 27 May 2018 07:41:35 -0700 (PDT) MIME-Version: 1.0 In-Reply-To: References: <1527346246-1334-1-git-send-email-s.mesoraca16@gmail.com> From: Kees Cook Date: Sun, 27 May 2018 07:41:34 -0700 Message-ID: Subject: Re: [PATCH] proc: prevent a task from writing on its own /proc/*/mem Content-Type: text/plain; charset="UTF-8" Sender: owner-linux-mm@kvack.org List-ID: To: Linus Torvalds Cc: Salvatore Mesoraca , Jann Horn , Kernel Hardening , LSM List , Linux Kernel Mailing List , linux-mm , Andrew Morton , Alexey Dobriyan , Akinobu Mita , Dmitry Vyukov , Arnd Bergmann , Davidlohr Bueso On Sat, May 26, 2018 at 6:33 PM, Linus Torvalds wrote: > Thus commit f511c0b17b08 "Yes, people use FOLL_FORCE ;)" > > Side note, that very sam ecommit f511c0b17b08 is also the explanation for > why the patch under discussion now seems broken. > > People really do use "write to /proc/self/mem" as a way to keep the > mappings read-only, but have a way to change them when required. Ah! Yes, that is the commit I was trying to find. Thanks! -Kees -- Kees Cook Pixel Security