On Thu, 22 Nov 2007 19:17:14 +0100 Jan Kara <[EMAIL PROTECTED]> wrote:
> Hi, > > I guess subject says it all - why is FIBMAP ioctl restricted only to > root (CAP_SYS_RAWIO)? Corresponding ioctl for XFS is allowed without > any special capabilities so we are inconsistent here too... > Would anyone mind if the check is removed? probably principle of least privilege; the location on physical media for a file is clearly something internal to the OS, and non-trusted users normally don't have any business knowing that. I can't think of any immediate exploitable thing with it, but I'm sure attackers would find a way to use it to increase their privilege once they can do something like "write 512 bytes to a disk address of my choice".. (but then again it's game over mostly already) > > Honza -- If you want to reach me at my work email, use [EMAIL PROTECTED] For development, discussion and tips for power savings, visit http://www.lesswatts.org - To unsubscribe from this list: send the line "unsubscribe linux-kernel" in the body of a message to [EMAIL PROTECTED] More majordomo info at http://vger.kernel.org/majordomo-info.html Please read the FAQ at http://www.tux.org/lkml/