unofficial mirror of bug-guix@gnu.org 
 help / color / mirror / code / Atom feed
* bug#50193: guix: shepherd pid 1 holds /dev/console
@ 2021-08-24 18:37 muradm
  0 siblings, 0 replies; only message in thread
From: muradm @ 2021-08-24 18:37 UTC (permalink / raw)
  To: 50193


On IRC chat we identified an issue related to linux SAK, which
is explained here 
https://www.kernel.org/doc/html/latest/security/sak.html

Following the check what processes will be SAK'ed:

~# ls -l /proc/[0-9]*/fd/* | grep console
lrwx------ 1 root   root   64 Aug 24 21:22 /proc/1/fd/1 -> 
/dev/console
lrwx------ 1 root   root   64 Aug 24 21:22 /proc/1/fd/2 -> 
/dev/console
l-wx------ 1 root   root   64 Aug 24 21:22 /proc/578/fd/4 -> 
/dev/console
lrwx------ 1 root   root   64 Aug 24 21:22 /proc/593/fd/1 -> 
/dev/console
lrwx------ 1 root   root   64 Aug 24 21:22 /proc/593/fd/2 -> 
/dev/console
lrwx------ 1 root   root   64 Aug 24 20:03 /proc/705/fd/1 -> 
/dev/console
lrwx------ 1 root   root   64 Aug 24 20:03 /proc/705/fd/2 -> 
/dev/console
lrwx------ 1 root   root   64 Aug 24 21:22 /proc/909/fd/1 -> 
/dev/console
lrwx------ 1 root   root   64 Aug 24 21:22 /proc/909/fd/2 -> 
/dev/console

As it is seen from above output, pid 1 which is shepherd holds 
/dev/console
making linux SAK feature useless. When SAK command issued by 
shortcut keys,
all above proceses gets killed including pid 1 which is shepherd, 
causing
system to stall.




^ permalink raw reply	[flat|nested] only message in thread

only message in thread, other threads:[~2021-08-24 18:43 UTC | newest]

Thread overview: (only message) (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2021-08-24 18:37 bug#50193: guix: shepherd pid 1 holds /dev/console muradm

Code repositories for project(s) associated with this public inbox

	https://git.savannah.gnu.org/cgit/guix.git

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for read-only IMAP folder(s) and NNTP newsgroup(s).