From: Pedro Alves <palves@redhat.com>
To: Jon Ringle <jon@ringle.org>
Cc: gdb-patches@sourceware.org, Jon Ringle <jringle@gridpoint.com>
Subject: Re: [PATCH v2] gdbserver: linux_low: elf_64_file_p cache results
Date: Thu, 24 Aug 2017 14:53:00 -0000 [thread overview]
Message-ID: <a275bbe0-cf6c-e9be-e398-7419fd6fc413@redhat.com> (raw)
In-Reply-To: <b0b54d2c-49d4-a8a9-dd6a-458a48039332@redhat.com>
On 08/24/2017 03:42 PM, Pedro Alves wrote:
> I'm still mystified about why can't gdbserver read
> the file after "droproot" has changed user.
> I assume gdbserver is running as root? Why wouldn't
> a gdbserver running as root be able to read "jringle"'s
> /proc file?
>
> Does CAP_PTRACE make a difference?
FAOD, I meant CAP_SYS_PTRACE.
See for example here:
http://man7.org/linux/man-pages/man5/proc.5.html
~~~
/proc/[pid]/exe
...
Permission to dereference or read (readlink(2)) this symbolic
link is governed by a ptrace access mode
PTRACE_MODE_READ_FSCREDS check; see ptrace(2).
~~~
[and follow on to ptrace(2).]
>
> I have to wonder whether there's a better way to do this..
> gdbserver needs to read other /proc files, some not cacheable.
> I fear that you may have run into just one case so far, and
> that we may run into problems if we take this route.
Thanks,
Pedro Alves
next prev parent reply other threads:[~2017-08-24 14:53 UTC|newest]
Thread overview: 6+ messages / expand[flat|nested] mbox.gz Atom feed top
2017-08-24 4:45 jon
2017-08-24 9:27 ` Pedro Alves
2017-08-24 14:15 ` Jon Ringle
2017-08-24 14:42 ` Pedro Alves
2017-08-24 14:53 ` Pedro Alves [this message]
2017-08-24 15:00 ` Jon Ringle
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=a275bbe0-cf6c-e9be-e398-7419fd6fc413@redhat.com \
--to=palves@redhat.com \
--cc=gdb-patches@sourceware.org \
--cc=jon@ringle.org \
--cc=jringle@gridpoint.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox