Re: [PATCH] mm/madvise: process_madvise() drop capability check if same mm
From: David Rientjes
Date: Sun Sep 15 2024 - 03:50:20 EST
On Fri, 13 Sep 2024, Lorenzo Stoakes wrote:
> In commit 96cfe2c0fd23 ("mm/madvise: replace ptrace attach requirement for
> process_madvise") process_madvise() was updated to require the caller to
> possess the CAP_SYS_NICE capability to perform the operation, in addition
> to a check against PTRACE_MODE_READ performed by mm_access().
>
> The mm_access() function explicitly checks to see if the address space of
> the process being referenced is the current one, in which case no check is
> performed.
>
> We, however, do not do this when checking the CAP_SYS_NICE capability. This
> means that we insist on the caller possessing this capability in order to
> perform madvise() operations on its own address space, which seems
> nonsensical.
>
> Simply add a check to allow for an invocation of this function with pidfd
> set to the current process without elevation.
>
> Signed-off-by: Lorenzo Stoakes <lorenzo.stoakes@xxxxxxxxxx>
Acked-by: David Rientjes <rientjes@xxxxxxxxxx>