Re: [Qemu-devel] [PATCH 0/3] Fix qemu-bridge-helper with SUID

2017-07-14 Thread Jason Wang
On 2017年07月14日 15:31, Jason Wang wrote: On 2017年07月11日 22:54, Daniel P. Berrange wrote: On Tue, Jul 11, 2017 at 03:10:43PM +0200, Michal Privoznik wrote: On 06/22/2017 05:58 PM, Michal Privoznik wrote: On 05/30/2017 10:23 AM, Michal Privoznik wrote: For more description see patch 3. Long s

Re: [Qemu-devel] [PATCH 0/3] Fix qemu-bridge-helper with SUID

2017-07-14 Thread Jason Wang
On 2017年07月11日 22:54, Daniel P. Berrange wrote: On Tue, Jul 11, 2017 at 03:10:43PM +0200, Michal Privoznik wrote: On 06/22/2017 05:58 PM, Michal Privoznik wrote: On 05/30/2017 10:23 AM, Michal Privoznik wrote: For more description see patch 3. Long story short, if the bridge helper runs with

Re: [Qemu-devel] [PATCH 0/3] Fix qemu-bridge-helper with SUID

2017-07-11 Thread Daniel P. Berrange
On Tue, Jul 11, 2017 at 03:10:43PM +0200, Michal Privoznik wrote: > On 06/22/2017 05:58 PM, Michal Privoznik wrote: > > On 05/30/2017 10:23 AM, Michal Privoznik wrote: > >> For more description see patch 3. Long story short, if the bridge helper > >> runs > >> with SUID, the mechanism we rely on (

Re: [Qemu-devel] [PATCH 0/3] Fix qemu-bridge-helper with SUID

2017-07-11 Thread Michal Privoznik
On 06/22/2017 05:58 PM, Michal Privoznik wrote: > On 05/30/2017 10:23 AM, Michal Privoznik wrote: >> For more description see patch 3. Long story short, if the bridge helper runs >> with SUID, the mechanism we rely on (DAC denying access to ACL files) does >> not >> work. >> >> Michal Privoznik (3

Re: [Qemu-devel] [PATCH 0/3] Fix qemu-bridge-helper with SUID

2017-06-22 Thread Michal Privoznik
On 05/30/2017 10:23 AM, Michal Privoznik wrote: > For more description see patch 3. Long story short, if the bridge helper runs > with SUID, the mechanism we rely on (DAC denying access to ACL files) does not > work. > > Michal Privoznik (3): > qemu-bridge-helper: Reverse return value setting lo

[Qemu-devel] [PATCH 0/3] Fix qemu-bridge-helper with SUID

2017-05-30 Thread Michal Privoznik
For more description see patch 3. Long story short, if the bridge helper runs with SUID, the mechanism we rely on (DAC denying access to ACL files) does not work. Michal Privoznik (3): qemu-bridge-helper: Reverse return value setting logic qemu-bridge-helper: Reverse return value setting logic