Re: PATCH: cdrecord: avoiding scsi device numbering for ide devices

From: Adam Sampson (azz_at_us-lot.org)
Date: 08/22/04

  • Next message: Horst von Brand: "Re: PATCH: cdrecord: avoiding scsi device numbering for ide devices"
    To: Alan Cox <alan@lxorguk.ukuu.org.uk>
    Date:	Sun, 22 Aug 2004 18:09:17 +0100
    
    

    Alan Cox <alan@lxorguk.ukuu.org.uk> writes:

    > It requires CAP_SYS_RAWIO, because that is the level of access it gives.

    That seems like a reasonable requirement, but would it be possible to
    do the capability check at open() time, rather than when the operation
    is performed? That would be more consistent with how conventional
    permissions checks on files/devices work, and would avoid breaking
    privilege-dropping applications.

    I don't really want to run my CD-writing tool with CAP_SYS_RAWIO all
    the time -- if it's got a security hole that a malicious CD image can
    exploit, then I'd rather it were just able to damage the CD drive than
    the rest of the system...

    Thanks,

    -- 
    Adam Sampson <azz@us-lot.org>                        <http://offog.org/>
    -
    To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
    the body of a message to majordomo@vger.kernel.org
    More majordomo info at  http://vger.kernel.org/majordomo-info.html
    Please read the FAQ at  http://www.tux.org/lkml/
    

  • Next message: Horst von Brand: "Re: PATCH: cdrecord: avoiding scsi device numbering for ide devices"

    Relevant Pages

    • Re: [RFC] IDE/ATA/SATA controller hotplug
      ... > 1) be first class modules, where all controllers/adapters are ... > certainly do not care about having this capability. ... Not in a arch specific dir please. ... send the line "unsubscribe linux-kernel" in ...
      (Linux-Kernel)
    • RE: RFD: Kernel release numbering
      ... What I have in mind is that we have a ... real 2.6 stable release maintainer. ... Alan Cox ... send the line "unsubscribe linux-kernel" in ...
      (Linux-Kernel)
    • Re: [PATCH] [request for inclusion] Realtime LSM
      ... >> capability everywhere without potential scheduling DoS. ... Thankfully a buffer underrun is no more fatal for pro audio than a ... send the line "unsubscribe linux-kernel" in ...
      (Linux-Kernel)
    • Re: [PATCH 2.4.28-pre4-bk6] delkin_cb: new driver for Cardbus IDE CF adaptor
      ... Alan Cox wrote: ... ide-cs does seem to be reliable, ... (hdparm keeper & the original "Linux IDE Guy") ... send the line "unsubscribe linux-kernel" in ...
      (Linux-Kernel)
    • Re: Linux Incompatibility List
      ... Alan Cox wrote: ... extend our testing into the ISV space, and how to supply useful data. ... especially if we could capture software info also. ... To unsubscribe from this list: send the line "unsubscribe linux-kernel" in the body of a message to majordomo@vger.kernel.org More majordomo info at http://vger.kernel.org/majordomo-info.html Please read the FAQ at http://www.tux.org/lkml/ ...
      (Linux-Kernel)