lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Message-ID: <20061007103714.GD30034@elf.ucw.cz>
Date:	Sat, 7 Oct 2006 12:37:14 +0200
From:	Pavel Machek <pavel@....cz>
To:	koos vriezen <koos.vriezen@...il.com>
Cc:	linux-kernel@...r.kernel.org
Subject: Re: Linux 2.6.18 break scratchbox

On Fri 2006-10-06 08:41:56, koos vriezen wrote:
> 2006/10/4, Pavel Machek <pavel@....cz>:
> >Hi!
> >
> >> Hit by http://bugzilla.scratchbox.org/bugzilla/show_bug.cgi?id=279 I
> >> wondered why such
> >> a change that could break existing setups entered 2.6.18.
> >> Now I can peek through '/proc/<pid of process outside chroot env w/ my
> >> UID>/root' into the
> >> box's root (and that's why scratchbox is broken now).
> >
> >File bug at bugzilla.kernel.org :-).
> >
> >I'm afraid we did not know about this ABI change, and noone using
> >scratchbox tested 2.6.18-rcX...
> 
> Well I did google for this before this report and eg.
> http://nchip.livejournal.com/ already mentioned it (but probably
> didn't report it at lkml) and there where some other links.
> But since I couldn't find any info on this new feature, that one can
> now read and write file through the /proc/xx/root link, I ask it here.
> And hopefully, if it's a regression, would be fixed in the stable tree
> ASAP. (Somehow I almost can't believe this change wouldn't show
> immediately in a regression test setup, and there must be a reason for
> opening this door w/o using an axe).

You probably want to do that bugzilla.kernel.org... and yes, this is
kind of bug I can imageine goes in without anyone noticing.
								Pavel
-- 
(english) http://www.livejournal.com/~pavelmachek
(cesky, pictures) http://atrey.karlin.mff.cuni.cz/~pavel/picture/horses/blog.html
-
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@...r.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ