Re: taskstats root only breaking iotop

From: Vasiliy Kulikov
Date: Sun Oct 02 2011 - 06:56:16 EST

(cc'ed kernel-hardening)

On Sun, Oct 02, 2011 at 12:22 +0200, Guillaume Chazarain wrote:
> On Sun, Oct 2, 2011 at 2:20 AM, Linus Torvalds
> <torvalds@xxxxxxxxxxxxxxxxxxxx> wrote:
> > So I don't see why you ask for it. What could possibly be a valid use-case?
> Right, kbyte granularity is enough.

It is not enough. In some border cases an attacker may still learn
private information given the counters with _arbitrary_ granularity:

> And that's consistent with
> /proc/vmstat, which nobody is complaining about.

<jumping with a raised hand>Me, me, it was me!</jumping with a raised hand>

Seriously, most of procfs files were created with relaxed permissions in
old days when nobody thought about such infoleaks. Now it is much
harder to close all of them without breaking existing users.


