From timh@spidey.Central.Sun.COM Fri May  1 12:58:53 2009
Received: from sunmail5.uk.sun.com (sunmail5.UK.Sun.COM [129.156.85.165])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n41JwqYj009088
	for <psarc-ext@sac.sfbay.sun.com>; Fri, 1 May 2009 12:58:53 -0700 (PDT)
Received: from nwk-avmta-1.SFBay.Sun.COM (nwk-avmta-1.SFBay.Sun.COM [129.146.11.74])
	by sunmail5.uk.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2) with ESMTP id n41Jwkd1007654
	for <@sunmail2sca.sfbay.sun.com:PSARC-ext@sun.com>; Fri, 1 May 2009 20:58:52 +0100 (BST)
Received: from pmxchannel-daemon.nwk-avmta-1.sfbay.Sun.COM by
 nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KIZ00C05E629M00@nwk-avmta-1.sfbay.Sun.COM> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Fri, 01 May 2009 12:58:50 -0700 (PDT)
Received: from dm-central-01.central.sun.com ([129.147.62.4])
 by nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KIZ007E0E61ZG20@nwk-avmta-1.sfbay.Sun.COM> for
 PSARC-ext@sun.com (ORCPT PSARC-ext@sun.com); Fri,
 01 May 2009 12:58:50 -0700 (PDT)
Received: from spidey.Central.Sun.COM (spidey.Central.Sun.COM [172.20.25.27])
	by dm-central-01.central.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2)
 with ESMTP id n41Jwm2q016956; Fri, 01 May 2009 13:58:48 -0600 (MDT)
Received: from spidey.Central.Sun.COM (localhost [127.0.0.1])
	by spidey.Central.Sun.COM (8.14.3+Sun/8.14.3) with ESMTP id n41JpI2w012633;
 Fri, 01 May 2009 13:51:18 -0600 (MDT)
Received: (from timh@localhost)	by spidey.Central.Sun.COM
 (8.14.3+Sun/8.14.3/Submit) id n41JpIKT012631; Fri,
 01 May 2009 13:51:18 -0600 (MDT)
Date: Fri, 01 May 2009 13:51:18 -0600 (MDT)
From: Tim Haley <timh@spidey.Central.Sun.COM>
Subject: Amendments to pconsole fast-track [PSARC/2009/275 FastTrack timeout
 05/08/2009]
To: PSARC-ext@sun.com
Cc: leland.chen@sun.com, norm.jacobs@sun.com
Message-id: <200905011951.n41JpIKT012631@spidey.Central.Sun.COM>
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
Status: RO
Content-Length: 1287

I am sponsoring this case on behalf of Leland Chen.  The case covers a
couple of small changes to the original pconsole ARC case
(PSARC/2008/606).  The requested binding is micro/patch.

Template Version: @(#)sac_nextcase 1.68 02/23/09 SMI
This information is Copyright 2009 Sun Microsystems
1. Introduction
    1.1. Project/Component Working Name:
	 Amendments to pconsole fast-track
    1.2. Name of Document Author/Supplier:
	 Author:  Leland Chen
    1.3  Date of This Document:
	01 May, 2009

4. Technical Description

Amendments to PSARC/2008/606 pconsole - parallel console

Amendment 1:

The pconsole-bin binary requires elevated privilege to be useful.  We
request to move the binary from the originally stated /usr/bin to
/usr/sbin, in line with where other binaries requiring privilege
usually exist.

Amendment 2:

A new execution profile and attribute will be defined.  The specific
RBAC additions are:

/etc/security/prof_attr:
Parallel Console Access:::Connect to remote consoles with pconsole:

/etc/security/exec_attr:
Parallel Console Access:suser:cmd:::/usr/sbin/pconsole-bin:euid=0

6. Resources and Schedule
    6.4. Steering Committee requested information
   	6.4.1. Consolidation C-team Name:
		SFW
    6.5. ARC review type: FastTrack
    6.6. ARC Exposure: open

From gww@eng.sun.com Fri May  1 13:30:41 2009
Received: from sunmail4.singapore.sun.com (sunmail4.Singapore.Sun.COM [129.158.71.19])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n41KUeQ0009974
	for <psarc-ext@sac.sfbay.sun.com>; Fri, 1 May 2009 13:30:41 -0700 (PDT)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.145.155.6])
	by sunmail4.singapore.sun.com (8.13.4+Sun/8.13.3/ENSMAIL,v2.2) with ESMTP id n41KURBS010329
	for <@sunmail2sca.sfbay.sun.com:PSARC-ext@sun.com>; Sat, 2 May 2009 04:30:39 +0800 (SGT)
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KIZ00801FN2BR00@nwk-avmta-2.sfbay.sun.com> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Fri, 01 May 2009 13:30:38 -0700 (PDT)
Received: from dm-eng-02.sfbay.sun.com ([129.146.11.32])
 by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KIZ005Z3FN2FO40@nwk-avmta-2.sfbay.sun.com> for
 PSARC-ext@sun.com (ORCPT PSARC-ext@sun.com); Fri,
 01 May 2009 13:30:38 -0700 (PDT)
Received: from marduk.eng.sun.com (marduk.SFBay.Sun.COM [129.146.108.224])
	by dm-eng-02.sfbay.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2)
 with ESMTP id n41KUbf3048246; Fri, 01 May 2009 13:30:37 -0700 (PDT)
Received: from marduk.eng.sun.com (localhost [127.0.0.1])
	by marduk.eng.sun.com (8.13.6+Sun/8.12.11) with ESMTP id n41KTlph016883; Fri,
 01 May 2009 13:29:47 -0700 (PDT)
Received: (from gww@localhost)
	by marduk.eng.sun.com (8.13.6+Sun/8.12.11/Submit) id n41KTl1V016882; Fri,
 01 May 2009 13:29:47 -0700 (PDT)
Date: Fri, 01 May 2009 13:29:47 -0700 (PDT)
From: Gary Winiger <gww@eng.sun.com>
Subject: Re: Amendments to pconsole fast-track [PSARC/2009/275 FastTrack
 timeout 05/08/2009]
To: PSARC-ext@sun.com, timh@spidey.central.sun.com
Cc: leland.chen@sun.com, norm.jacobs@sun.com
Message-id: <200905012029.n41KTl1V016882@marduk.eng.sun.com>
Content-transfer-encoding: 7BIT
X-Sun-Charset: US-ASCII
X-PMX-Version: 5.4.1.325704
Status: RO
Content-Length: 1875

> Amendment 1:
> 
> The pconsole-bin binary requires elevated privilege to be useful.  We
> request to move the binary from the originally stated /usr/bin to
> /usr/sbin, in line with where other binaries requiring privilege
> usually exist.
> 
> Amendment 2:
> 
> A new execution profile and attribute will be defined.  The specific
> RBAC additions are:
> 
> /etc/security/prof_attr:
> Parallel Console Access:::Connect to remote consoles with pconsole:
> 
> /etc/security/exec_attr:
> Parallel Console Access:suser:cmd:::/usr/sbin/pconsole-bin:euid=0
                          ^^^^^                              ^^^^^^
	This is fine for S7-S9, but not for S10 forward.
	exec_attr(4):
     policy    The security policy that is  associated  with  the
               profile entry. The valid policies are suser (stan-
               dard Solaris superuser) and solaris.  The  solaris
               policy  recognizes privileges (see privileges(5));
               the suser policy does not.

               The solaris and suser policies can coexist in  the
               same  exec_attr database, so that Solaris releases
               prior to the current release  can  use  the  suser
               policy  and  the current Solaris release can use a
               solaris policy. solaris is a superset of suser; it
               allows  you  to  specify privileges in addition to
               UIDs. Policies that are specific  to  the  current
               release  of  Solaris  or  that  contain privileges
               should use solaris. Policies that use UIDs only or
               that  are  not  specific  to  the  current Solaris
               release should use suser.
	
	What are the elevated privileges and why are they required?
	Just those privileges should be specified in the privs= attribute.
	Why is there a need to specify a uid?

Gary..
	

From tim.haley@sun.com Fri May  1 15:16:11 2009
Received: from newsunmail1brm.central.sun.com (newsunmail1brm.Central.Sun.COM [129.147.62.245])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n41MGBbJ012339
	for <psarc-ext@sac.sfbay.sun.com>; Fri, 1 May 2009 15:16:11 -0700 (PDT)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by newsunmail1brm.central.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id n41MG93l043384
	for <@sunmail2sca.sfbay.sun.com:PSARC-ext@sun.com>; Fri, 1 May 2009 16:16:11 -0600 (MDT)
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KIZ00609KIQ7A00@brm-avmta-1.central.sun.com> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Fri, 01 May 2009 16:16:02 -0600 (MDT)
Received: from brmea-mail-2.sun.com ([192.18.98.43])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KIZ001C6KIQHJ20@brm-avmta-1.central.sun.com> for
 PSARC-ext@sun.com (ORCPT PSARC-ext@sun.com); Fri,
 01 May 2009 16:16:02 -0600 (MDT)
Received: from fe-amer-10.sun.com ([192.18.109.80])
	by brmea-mail-2.sun.com (8.13.6+Sun/8.12.9) with ESMTP id n41MG1cW028355	for
 <PSARC-ext@sun.com>; Fri, 01 May 2009 22:16:01 +0000 (GMT)
Received: from conversion-daemon.mail-amer.sun.com by mail-amer.sun.com
 (Sun Java(tm) System Messaging Server 7.0-5.01 64bit (built Feb 19 2009))
 id <0KIZ00M00K9XHR00@mail-amer.sun.com> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Fri, 01 May 2009 16:16:01 -0600 (MDT)
Received: from [172.20.25.27] ([unknown] [172.20.25.27])
 by mail-amer.sun.com (Sun Java(tm) System Messaging Server 7.0-5.01 64bit
 (built Feb 19 2009)) with ESMTPSA id <0KIZ00K5PKI7WE20@mail-amer.sun.com>; Fri,
 01 May 2009 16:15:44 -0600 (MDT)
Date: Fri, 01 May 2009 16:15:43 -0600
From: Tim Haley <tim.haley@sun.com>
Subject: Re: Amendments to pconsole fast-track [PSARC/2009/275 FastTrack
	timeout 05/08/2009]
In-reply-to: <200905012029.n41KTl1V016882@marduk.eng.sun.com>
Sender: Timothy.Haley@sun.com
To: Gary Winiger <gww@eng.sun.com>, Leland.Chen@sun.com
Cc: PSARC-ext@sun.com, Norm.Jacobs@sun.com
Message-id: <49FB748F.2060902@sun.com>
MIME-version: 1.0
Content-type: text/plain; format=flowed; charset=ISO-8859-1
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200905012029.n41KTl1V016882@marduk.eng.sun.com>
User-Agent: Thunderbird 2.0.0.21 (X11/20090323)
Status: RO
Content-Length: 2155

Gary Winiger wrote:
>> Amendment 1:
>>
>> The pconsole-bin binary requires elevated privilege to be useful.  We
>> request to move the binary from the originally stated /usr/bin to
>> /usr/sbin, in line with where other binaries requiring privilege
>> usually exist.
>>
>> Amendment 2:
>>
>> A new execution profile and attribute will be defined.  The specific
>> RBAC additions are:
>>
>> /etc/security/prof_attr:
>> Parallel Console Access:::Connect to remote consoles with pconsole:
>>
>> /etc/security/exec_attr:
>> Parallel Console Access:suser:cmd:::/usr/sbin/pconsole-bin:euid=0
>                           ^^^^^                              ^^^^^^
> 	This is fine for S7-S9, but not for S10 forward.
> 	exec_attr(4):
>      policy    The security policy that is  associated  with  the
>                profile entry. The valid policies are suser (stan-
>                dard Solaris superuser) and solaris.  The  solaris
>                policy  recognizes privileges (see privileges(5));
>                the suser policy does not.
> 
>                The solaris and suser policies can coexist in  the
>                same  exec_attr database, so that Solaris releases
>                prior to the current release  can  use  the  suser
>                policy  and  the current Solaris release can use a
>                solaris policy. solaris is a superset of suser; it
>                allows  you  to  specify privileges in addition to
>                UIDs. Policies that are specific  to  the  current
>                release  of  Solaris  or  that  contain privileges
>                should use solaris. Policies that use UIDs only or
>                that  are  not  specific  to  the  current Solaris
>                release should use suser.
> 	
> 	What are the elevated privileges and why are they required?
> 	Just those privileges should be specified in the privs= attribute.
> 	Why is there a need to specify a uid?
> 
> Gary..
> 	
> _______________________________________________
> opensolaris-arc mailing list
> opensolaris-arc@opensolaris.org
Thanks Gary,

We'll work on narrowing the privilege and send an update.

-tim


From Norm.Jacobs@sun.com Fri May  1 15:45:43 2009
Received: from sunmail4.singapore.sun.com (sunmail4.Singapore.Sun.COM [129.158.71.19])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n41Mjgnn012564
	for <psarc-ext@sac.sfbay.sun.com>; Fri, 1 May 2009 15:45:43 -0700 (PDT)
Received: from nwk-avmta-1.SFBay.Sun.COM (nwk-avmta-1.SFBay.Sun.COM [129.146.11.74])
	by sunmail4.singapore.sun.com (8.13.4+Sun/8.13.3/ENSMAIL,v2.2) with ESMTP id n41Mjdtq013155
	for <@sunmail2sca.sfbay.sun.com:PSARC-ext@Sun.COM>; Sat, 2 May 2009 06:45:41 +0800 (SGT)
Received: from pmxchannel-daemon.nwk-avmta-1.sfbay.Sun.COM by
 nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KIZ00B01LW4J500@nwk-avmta-1.sfbay.Sun.COM> for PSARC-ext@Sun.COM
 (ORCPT PSARC-ext@Sun.COM); Fri, 01 May 2009 15:45:40 -0700 (PDT)
Received: from dm-sfbay-02.sfbay.sun.com ([129.146.11.31])
 by nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KIZ007GILW3ZME0@nwk-avmta-1.sfbay.Sun.COM> for
 PSARC-ext@Sun.COM (ORCPT PSARC-ext@Sun.COM); Fri,
 01 May 2009 15:45:39 -0700 (PDT)
Received: from printing.eng.sun.com (printing.SFBay.Sun.COM [129.146.178.26])
	by dm-sfbay-02.sfbay.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2)
 with ESMTP id n41MjcSS002000; Fri, 01 May 2009 15:45:38 -0700 (PDT)
Received: from [10.7.251.237] (punchin-jacobs.SFBay.Sun.COM [10.7.251.237])
	by printing.eng.sun.com (8.14.3+Sun/8.14.3) with ESMTP id n41MmM1k021050; Fri,
 01 May 2009 15:48:23 -0700 (PDT)
Date: Fri, 01 May 2009 17:45:37 -0500
From: Norm Jacobs <Norm.Jacobs@sun.com>
Subject: Re: Amendments to pconsole fast-track [PSARC/2009/275 FastTrack
 timeout 05/08/2009]
In-reply-to: <200905012029.n41KTl1V016882@marduk.eng.sun.com>
To: Gary Winiger <gww@eng.sun.com>
Cc: PSARC-ext@sun.com, timh@spidey.central.sun.com, leland.chen@sun.com
Message-id: <49FB7B91.10305@Sun.COM>
MIME-version: 1.0
Content-type: text/plain; charset=ISO-8859-1; format=flowed
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200905012029.n41KTl1V016882@marduk.eng.sun.com>
User-Agent: Thunderbird 2.0.0.21 (X11/20090323)
Status: RO
Content-Length: 2912

Gary Winiger wrote:
>> Amendment 1:
>>
>> The pconsole-bin binary requires elevated privilege to be useful.  We
>> request to move the binary from the originally stated /usr/bin to
>> /usr/sbin, in line with where other binaries requiring privilege
>> usually exist.
>>
>> Amendment 2:
>>
>> A new execution profile and attribute will be defined.  The specific
>> RBAC additions are:
>>
>> /etc/security/prof_attr:
>> Parallel Console Access:::Connect to remote consoles with pconsole:
>>
>> /etc/security/exec_attr:
>> Parallel Console Access:suser:cmd:::/usr/sbin/pconsole-bin:euid=0
>>     
>                           ^^^^^                              ^^^^^^
> 	This is fine for S7-S9, but not for S10 forward.
> 	exec_attr(4):
>      policy    The security policy that is  associated  with  the
>                profile entry. The valid policies are suser (stan-
>                dard Solaris superuser) and solaris.  The  solaris
>                policy  recognizes privileges (see privileges(5));
>                the suser policy does not.
>
>                The solaris and suser policies can coexist in  the
>                same  exec_attr database, so that Solaris releases
>                prior to the current release  can  use  the  suser
>                policy  and  the current Solaris release can use a
>                solaris policy. solaris is a superset of suser; it
>                allows  you  to  specify privileges in addition to
>                UIDs. Policies that are specific  to  the  current
>                release  of  Solaris  or  that  contain privileges
>                should use solaris. Policies that use UIDs only or
>                that  are  not  specific  to  the  current Solaris
>                release should use suser.
> 	
> 	What are the elevated privileges and why are they required?
> 	Just those privileges should be specified in the privs= attribute.
> 	Why is there a need to specify a uid?
>   
I guess that since I filed the bug that caused these amendments to be 
filed, I will chime in.

pconsole appear to do the typical seteuid(getuid()) at startup, then 
elevates it's euid when it needs to to use ioctl(c->fd, TIOCSTI, &kar).

TIOCSTI appears to require  elevated privilege.  streamio.c appears to 
do the auth checking in the kernel using secpolicy_sti(), which equates 
to* return* (secpolicy_require_set 
<http://src.opensolaris.org/source/xref/onnv/onnv-gate/usr/src/uts/common/os/policy.c#secpolicy_require_set>(cr 
<http://src.opensolaris.org/source/s?defs=cr&project=/onnv>, 
PRIV_FULLSET 
<http://src.opensolaris.org/source/s?defs=PRIV_FULLSET&project=/onnv>, 
NULL <http://src.opensolaris.org/source/s?defs=NULL&project=/onnv>));

It looks like euid=0 is the smallest hammer that we have to get you 
there, but if you have a smaller hammer than euid=0 that gets you there, 
than that would be the appropriate thing to do.

    -Norm


From carlsonj@phorcys.east.sun.com Mon May  4 04:45:56 2009
Received: from sunmail4.singapore.sun.com (sunmail4.Singapore.Sun.COM [129.158.71.19])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n44Bjs7Y015552
	for <psarc-ext@sac.sfbay.sun.com>; Mon, 4 May 2009 04:45:55 -0700 (PDT)
Received: from nwk-avmta-1.SFBay.Sun.COM (nwk-avmta-1.SFBay.Sun.COM [129.146.11.74])
	by sunmail4.singapore.sun.com (8.13.4+Sun/8.13.3/ENSMAIL,v2.2) with ESMTP id n44Bjof3026452
	for <@sunmail2sca.sfbay.sun.com:PSARC-ext@Sun.COM>; Mon, 4 May 2009 19:45:54 +0800 (SGT)
Received: from pmxchannel-daemon.nwk-avmta-1.sfbay.Sun.COM by
 nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KJ40040BBCHH600@nwk-avmta-1.sfbay.Sun.COM> for PSARC-ext@Sun.COM
 (ORCPT PSARC-ext@Sun.COM); Mon, 04 May 2009 04:45:53 -0700 (PDT)
Received: from dm-east-01.east.sun.com ([129.148.9.192])
 by nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KJ400AIWBCF6790@nwk-avmta-1.sfbay.Sun.COM> for
 PSARC-ext@Sun.COM (ORCPT PSARC-ext@Sun.COM); Mon,
 04 May 2009 04:45:51 -0700 (PDT)
Received: from phorcys.east.sun.com (phorcys.East.Sun.COM [129.148.174.143])
	by dm-east-01.east.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2)
 with ESMTP id n44BjlUE019089; Mon, 04 May 2009 07:45:47 -0400 (EDT)
Received: from phorcys.east.sun.com (phorcys.local [127.0.0.1])
	by phorcys.east.sun.com (8.14.3+Sun/8.14.3) with ESMTP id n44Bj245014453; Mon,
 04 May 2009 07:45:02 -0400 (EDT)
Received: (from carlsonj@localhost)
	by phorcys.east.sun.com (8.14.3+Sun/8.14.3/Submit) id n44Bj2Eg014450; Mon,
 04 May 2009 07:45:02 -0400 (EDT)
Date: Mon, 04 May 2009 07:45:02 -0400
From: James Carlson <james.d.carlson@sun.com>
Subject: Re: Amendments to pconsole fast-track [PSARC/2009/275 FastTrack
	timeout 05/08/2009]
In-reply-to: <49FB7B91.10305@Sun.COM>
To: Norm Jacobs <Norm.Jacobs@sun.com>
Cc: Gary Winiger <gww@eng.sun.com>, Leland.Chen@sun.com, PSARC-ext@sun.com,
        timh@spidey.central.sun.com
Message-id: <18942.54590.914768.767788@gargle.gargle.HOWL>
MIME-version: 1.0
X-Mailer: VM 7.01 under Emacs 21.3.1
Content-type: text/plain; charset=us-ascii
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200905012029.n41KTl1V016882@marduk.eng.sun.com>
 <49FB7B91.10305@Sun.COM>
Status: RO
Content-Length: 864

Norm Jacobs writes:
> TIOCSTI appears to require  elevated privilege.  streamio.c appears to 
> do the auth checking in the kernel using secpolicy_sti(), which equates 

If you issue it on the controlling tty for this process and you have
at least read access, then you won't need extra privileges.  But, yes,
if you want to do it on someone else's tty, then you'll need all
privileges, as it's an escalation threat.

I think the safer way to do this (rather than having to hand out all
privileges, and assuming I understand the original pconsole case
correctly) would be to insert characters by just writing on the master
side of the pty.

-- 
James Carlson, Solaris Networking              <james.d.carlson@sun.com>
Sun Microsystems / 35 Network Drive        71.232W   Vox +1 781 442 2084
MS UBUR02-212 / Burlington MA 01803-2757   42.496N   Fax +1 781 442 1677

From Norm.Jacobs@sun.com Mon May  4 10:34:34 2009
Received: from newsunmail1brm.central.sun.com (newsunmail1brm.Central.Sun.COM [129.147.62.245])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n44HYXdB020160
	for <psarc-ext@sac.sfbay.sun.com>; Mon, 4 May 2009 10:34:33 -0700 (PDT)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by newsunmail1brm.central.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id n44HYX0f048170
	for <@sunmail2sca.sfbay.sun.com:PSARC-ext@Sun.COM>; Mon, 4 May 2009 11:34:33 -0600 (MDT)
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KJ400G0FRHKOL00@brm-avmta-1.central.sun.com> for PSARC-ext@Sun.COM
 (ORCPT PSARC-ext@Sun.COM); Mon, 04 May 2009 11:34:32 -0600 (MDT)
Received: from dm-sfbay-02.sfbay.sun.com ([129.146.11.31])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KJ400G7ORHJIA00@brm-avmta-1.central.sun.com> for
 PSARC-ext@Sun.COM (ORCPT PSARC-ext@Sun.COM); Mon,
 04 May 2009 11:34:31 -0600 (MDT)
Received: from printing.eng.sun.com (printing.SFBay.Sun.COM [129.146.178.26])
	by dm-sfbay-02.sfbay.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2)
 with ESMTP id n44HYUJI060544; Mon, 04 May 2009 10:34:30 -0700 (PDT)
Received: from [10.7.251.237] (punchin-jacobs.SFBay.Sun.COM [10.7.251.237])
	by printing.eng.sun.com (8.14.3+Sun/8.14.3) with ESMTP id n44HbFUQ021863; Mon,
 04 May 2009 10:37:15 -0700 (PDT)
Date: Mon, 04 May 2009 12:34:29 -0500
From: Norm Jacobs <Norm.Jacobs@sun.com>
Subject: Re: Amendments to pconsole fast-track [PSARC/2009/275 FastTrack
	timeout 05/08/2009]
In-reply-to: <18942.54590.914768.767788@gargle.gargle.HOWL>
To: James Carlson <james.d.carlson@sun.com>
Cc: Gary Winiger <gww@eng.sun.com>, Leland.Chen@sun.com, PSARC-ext@sun.com,
        timh@spidey.central.sun.com
Message-id: <49FF2725.5000607@Sun.COM>
MIME-version: 1.0
Content-type: text/plain; charset=ISO-8859-1; format=flowed
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200905012029.n41KTl1V016882@marduk.eng.sun.com>
 <49FB7B91.10305@Sun.COM> <18942.54590.914768.767788@gargle.gargle.HOWL>
User-Agent: Thunderbird 2.0.0.21 (X11/20090323)
Status: RO
Content-Length: 521

James Carlson wrote:
> Norm Jacobs writes:
>   
>> TIOCSTI appears to require  elevated privilege.  streamio.c appears to 
>> do the auth checking in the kernel using secpolicy_sti(), which equates 
>>     
>
> If you issue it on the controlling tty for this process and you have
> at least read access, then you won't need extra privileges.  But, yes,
> if you want to do it on someone else's tty, then you'll need all
> privileges, as it's an escalation threat.
>   
It appears to want to use other's ttys.

    -Norm


From tim.haley@sun.com Tue May  5 08:48:53 2009
Received: from newsunmail1brm.central.sun.com (newsunmail1brm.Central.Sun.COM [129.147.62.245])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n45Fmr8q005147
	for <psarc-ext@sac.sfbay.sun.com>; Tue, 5 May 2009 08:48:53 -0700 (PDT)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.145.155.6])
	by newsunmail1brm.central.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id n45FmrRo030385
	for <@sunmail2sca.sfbay.sun.com:psarc-ext@sun.com>; Tue, 5 May 2009 09:48:53 -0600 (MDT)
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KJ600405H9FK000@nwk-avmta-2.sfbay.sun.com> for psarc-ext@sun.com
 (ORCPT psarc-ext@sun.com); Tue, 05 May 2009 08:48:51 -0700 (PDT)
Received: from brmea-mail-4.sun.com ([192.18.98.36])
 by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KJ600G9WH9EL0F0@nwk-avmta-2.sfbay.sun.com> for
 psarc-ext@sun.com (ORCPT psarc-ext@sun.com); Tue,
 05 May 2009 08:48:51 -0700 (PDT)
Received: from fe-amer-09.sun.com ([192.18.109.79])
	by brmea-mail-4.sun.com (8.13.6+Sun/8.12.9) with ESMTP id n45Fmo0G008357	for
 <psarc-ext@sun.com>; Tue, 05 May 2009 15:48:50 +0000 (GMT)
Received: from conversion-daemon.mail-amer.sun.com by mail-amer.sun.com
 (Sun Java(tm) System Messaging Server 7.0-5.01 64bit (built Feb 19 2009))
 id <0KJ600100GFZ6L00@mail-amer.sun.com> for psarc-ext@sun.com
 (ORCPT psarc-ext@sun.com); Tue, 05 May 2009 09:48:50 -0600 (MDT)
Received: from dhcp-umpk17-229-99.SFBay.Sun.COM ([unknown] [129.146.229.99])
 by mail-amer.sun.com
 (Sun Java(tm) System Messaging Server 7.0-5.01 64bit (built Feb 19 2009))
 with ESMTPSA id <0KJ600C9UH8UF6C0@mail-amer.sun.com>; Tue,
 05 May 2009 09:48:35 -0600 (MDT)
Date: Tue, 05 May 2009 09:48:29 -0600
From: Tim Haley <tim.haley@sun.com>
Subject: Re: Amendments to pconsole fast-track [PSARC/2009/275 FastTrack
	timeout 05/08/2009]
In-reply-to: <49FF2725.5000607@Sun.COM>
Sender: Timothy.Haley@sun.com
To: Norm Jacobs <Norm.Jacobs@sun.com>
Cc: James Carlson <James.D.Carlson@sun.com>, Leland.Chen@sun.com,
        psarc-ext@sun.com, Gary Winiger <gww@eng.sun.com>
Message-id: <4A005FCD.2000006@sun.com>
MIME-version: 1.0
Content-type: text/plain; format=flowed; charset=ISO-8859-1
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200905012029.n41KTl1V016882@marduk.eng.sun.com>
 <49FB7B91.10305@Sun.COM> <18942.54590.914768.767788@gargle.gargle.HOWL>
 <49FF2725.5000607@Sun.COM>
User-Agent: Thunderbird 2.0.0.21 (Macintosh/20090302)
Status: RO
Content-Length: 751

Norm Jacobs wrote:
> James Carlson wrote:
>> Norm Jacobs writes:
>>  
>>> TIOCSTI appears to require  elevated privilege.  streamio.c appears 
>>> to do the auth checking in the kernel using secpolicy_sti(), which 
>>> equates     
>>
>> If you issue it on the controlling tty for this process and you have
>> at least read access, then you won't need extra privileges.  But, yes,
>> if you want to do it on someone else's tty, then you'll need all
>> privileges, as it's an escalation threat.
>>   
> It appears to want to use other's ttys.
> 
>    -Norm
> 
> _______________________________________________
> opensolaris-arc mailing list
> opensolaris-arc@opensolaris.org

So are we back, perhaps regrettably, to the original proposal then?

-tim



From Nicolas.Williams@sun.com Tue May  5 08:59:36 2009
Received: from sunmail5.uk.sun.com (sunmail5.UK.Sun.COM [129.156.85.165])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n45FxZrW005671
	for <psarc-ext@sac.sfbay.sun.com>; Tue, 5 May 2009 08:59:36 -0700 (PDT)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.145.155.6])
	by sunmail5.uk.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2) with ESMTP id n45FxQlC017955;
	Tue, 5 May 2009 16:59:31 +0100 (BST)
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KJ600513HR40O00@nwk-avmta-2.sfbay.sun.com>; Tue,
 05 May 2009 08:59:28 -0700 (PDT)
Received: from binky.Central.Sun.COM ([129.153.128.104])
 by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KJ6004Q5HR3OL00@nwk-avmta-2.sfbay.sun.com>; Tue,
 05 May 2009 08:59:27 -0700 (PDT)
Received: from binky.Central.Sun.COM (localhost [127.0.0.1])
	by binky.Central.Sun.COM (8.14.3+Sun/8.14.3) with ESMTP id n45FvDnE025412;
 Tue, 05 May 2009 10:57:13 -0500 (CDT)
Received: (from nw141292@localhost)
	by binky.Central.Sun.COM (8.14.3+Sun/8.14.3/Submit) id n45FvCnc025411; Tue,
 05 May 2009 10:57:12 -0500 (CDT)
Date: Tue, 05 May 2009 10:57:12 -0500
From: Nicolas Williams <Nicolas.Williams@sun.com>
Subject: Re: Amendments to pconsole fast-track [PSARC/2009/275 FastTrack
 timeout 05/08/2009]
In-reply-to: <49FF2725.5000607@Sun.COM>
To: Norm Jacobs <Norm.Jacobs@sun.com>
Cc: James Carlson <James.D.Carlson@sun.com>, Gary Winiger <gww@eng.sun.com>,
        Leland.Chen@sun.com, psarc-ext@sun.com, timh@spidey.central.sun.com
Message-id: <20090505155712.GY1500@Sun.COM>
MIME-version: 1.0
Content-type: text/plain; charset=us-ascii
Content-transfer-encoding: 7BIT
Content-disposition: inline
X-PMX-Version: 5.4.1.325704
References: <200905012029.n41KTl1V016882@marduk.eng.sun.com>
 <49FB7B91.10305@Sun.COM> <18942.54590.914768.767788@gargle.gargle.HOWL>
 <49FF2725.5000607@Sun.COM>
X-Authentication-warning: binky.Central.Sun.COM: nw141292 set sender to
 Nicolas.Williams@sun.com using -f
User-Agent: Mutt/1.5.7i
Status: RO
Content-Length: 596

On Mon, May 04, 2009 at 12:34:29PM -0500, Norm Jacobs wrote:
> James Carlson wrote:
> >Norm Jacobs writes:
> >  
> >>TIOCSTI appears to require  elevated privilege.  streamio.c appears to 
> >>do the auth checking in the kernel using secpolicy_sti(), which equates 
> >>    
> >
> >If you issue it on the controlling tty for this process and you have
> >at least read access, then you won't need extra privileges.  But, yes,
> >if you want to do it on someone else's tty, then you'll need all
> >privileges, as it's an escalation threat.
> >  
> It appears to want to use other's ttys.

Er, why?

From Norm.Jacobs@sun.com Tue May  5 09:07:50 2009
Received: from sunmail2sca.sfbay.sun.com (sunmail2sca.SFBay.Sun.COM [129.145.155.234])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n45G7nHQ006254
	for <psarc-ext@sac.sfbay.sun.com>; Tue, 5 May 2009 09:07:49 -0700 (PDT)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.145.155.6])
	by sunmail2sca.sfbay.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id n45G7nsD001303
	for <@sunmail2sca.sfbay.sun.com:psarc-ext@Sun.COM>; Tue, 5 May 2009 09:07:49 -0700 (PDT)
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KJ60050ZI50F500@nwk-avmta-2.sfbay.sun.com> for psarc-ext@Sun.COM
 (ORCPT psarc-ext@Sun.COM); Tue, 05 May 2009 09:07:48 -0700 (PDT)
Received: from dm-sfbay-01.sfbay.sun.com ([129.145.155.118])
 by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KJ6004R5I50OB10@nwk-avmta-2.sfbay.sun.com> for
 psarc-ext@Sun.COM (ORCPT psarc-ext@Sun.COM); Tue,
 05 May 2009 09:07:48 -0700 (PDT)
Received: from printing.eng.sun.com (printing.SFBay.Sun.COM [129.146.178.26])
	by dm-sfbay-01.sfbay.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2)
 with ESMTP id n45G7lZ1039302; Tue, 05 May 2009 09:07:47 -0700 (PDT)
Received: from [10.7.251.237] (punchin-jacobs.SFBay.Sun.COM [10.7.251.237])
	by printing.eng.sun.com (8.14.3+Sun/8.14.3) with ESMTP id n45GAWNC022160; Tue,
 05 May 2009 09:10:32 -0700 (PDT)
Date: Tue, 05 May 2009 11:07:46 -0500
From: Norm Jacobs <Norm.Jacobs@sun.com>
Subject: Re: Amendments to pconsole fast-track [PSARC/2009/275 FastTrack
 timeout 05/08/2009]
In-reply-to: <20090505155712.GY1500@Sun.COM>
To: Nicolas Williams <Nicolas.Williams@sun.com>
Cc: James Carlson <James.D.Carlson@sun.com>, Gary Winiger <gww@eng.sun.com>,
        Leland.Chen@sun.com, psarc-ext@sun.com, timh@spidey.central.sun.com
Message-id: <4A006452.3020702@Sun.COM>
MIME-version: 1.0
Content-type: text/plain; charset=us-ascii; format=flowed
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200905012029.n41KTl1V016882@marduk.eng.sun.com>
 <49FB7B91.10305@Sun.COM> <18942.54590.914768.767788@gargle.gargle.HOWL>
 <49FF2725.5000607@Sun.COM> <20090505155712.GY1500@Sun.COM>
User-Agent: Thunderbird 2.0.0.21 (X11/20090323)
Status: RO
Content-Length: 1006

Nicolas Williams wrote:
> On Mon, May 04, 2009 at 12:34:29PM -0500, Norm Jacobs wrote:
>   
>> James Carlson wrote:
>>     
>>> Norm Jacobs writes:
>>>  
>>>       
>>>> TIOCSTI appears to require  elevated privilege.  streamio.c appears to 
>>>> do the auth checking in the kernel using secpolicy_sti(), which equates 
>>>>    
>>>>         
>>> If you issue it on the controlling tty for this process and you have
>>> at least read access, then you won't need extra privileges.  But, yes,
>>> if you want to do it on someone else's tty, then you'll need all
>>> privileges, as it's an escalation threat.
>>>  
>>>       
>> It appears to want to use other's ttys.
>>     
>
> Er, why?
>   
Because that's what it does. It connects to a bunch of ttys, allows you 
to type in it's "shell", and stuffs a copy of what you type out to all 
of the ttys it's connected to. It monitors each "connection" through 
individual xterms. Near as I can tell, it's for people that are too lazy 
to cut/paste. :-)

-Norm

From Nicolas.Williams@Sun.COM Tue May  5 09:11:32 2009
Received: from sunmail3mpk.sfbay.sun.com (sunmail3mpk.SFBay.Sun.COM [129.146.11.52])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n45GBV8F006295
	for <psarc-ext@sac.sfbay.sun.com>; Tue, 5 May 2009 09:11:31 -0700 (PDT)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by sunmail3mpk.sfbay.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id n45GBTv7012018;
	Tue, 5 May 2009 09:11:29 -0700 (PDT)
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KJ600H07IB4RU00@brm-avmta-1.central.sun.com>; Tue,
 05 May 2009 10:11:28 -0600 (MDT)
Received: from binky.Central.Sun.COM ([129.153.128.104])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KJ60034VIB367B0@brm-avmta-1.central.sun.com>; Tue,
 05 May 2009 10:11:27 -0600 (MDT)
Received: from binky.Central.Sun.COM (localhost [127.0.0.1])
	by binky.Central.Sun.COM (8.14.3+Sun/8.14.3) with ESMTP id n45G9IE1025420;
 Tue, 05 May 2009 11:09:18 -0500 (CDT)
Received: (from nw141292@localhost)
	by binky.Central.Sun.COM (8.14.3+Sun/8.14.3/Submit) id n45G9I5n025419; Tue,
 05 May 2009 11:09:18 -0500 (CDT)
Date: Tue, 05 May 2009 11:09:18 -0500
From: Nicolas Williams <Nicolas.Williams@Sun.COM>
Subject: Re: Amendments to pconsole fast-track [PSARC/2009/275 FastTrack
 timeout 05/08/2009]
In-reply-to: <4A006452.3020702@Sun.COM>
To: Norm Jacobs <Norm.Jacobs@Sun.COM>
Cc: James Carlson <James.D.Carlson@Sun.COM>, Gary Winiger <gww@eng.sun.com>,
        Leland.Chen@Sun.COM, psarc-ext@Sun.COM, timh@spidey.central.sun.com
Message-id: <20090505160918.GZ1500@Sun.COM>
MIME-version: 1.0
Content-type: text/plain; charset=us-ascii
Content-transfer-encoding: 7BIT
Content-disposition: inline
X-PMX-Version: 5.4.1.325704
References: <200905012029.n41KTl1V016882@marduk.eng.sun.com>
 <49FB7B91.10305@Sun.COM> <18942.54590.914768.767788@gargle.gargle.HOWL>
 <49FF2725.5000607@Sun.COM> <20090505155712.GY1500@Sun.COM>
 <4A006452.3020702@Sun.COM>
X-Authentication-warning: binky.Central.Sun.COM: nw141292 set sender to
 Nicolas.Williams@sun.com using -f
User-Agent: Mutt/1.5.7i
Status: RO
Content-Length: 1417

On Tue, May 05, 2009 at 11:07:46AM -0500, Norm Jacobs wrote:
> Nicolas Williams wrote:
> >On Mon, May 04, 2009 at 12:34:29PM -0500, Norm Jacobs wrote:
> >  
> >>James Carlson wrote:
> >>    
> >>>Norm Jacobs writes:
> >>> 
> >>>      
> >>>>TIOCSTI appears to require  elevated privilege.  streamio.c appears to 
> >>>>do the auth checking in the kernel using secpolicy_sti(), which equates 
> >>>>   
> >>>>        
> >>>If you issue it on the controlling tty for this process and you have
> >>>at least read access, then you won't need extra privileges.  But, yes,
> >>>if you want to do it on someone else's tty, then you'll need all
> >>>privileges, as it's an escalation threat.
> >>> 
> >>>      
> >>It appears to want to use other's ttys.
> >>    
> >
> >Er, why?
> >  
> Because that's what it does. It connects to a bunch of ttys, allows you 
> to type in it's "shell", and stuffs a copy of what you type out to all 
> of the ttys it's connected to. It monitors each "connection" through 
> individual xterms. Near as I can tell, it's for people that are too lazy 
> to cut/paste. :-)

Yes, but as has been pointed out, it could just master those ptys.
Sounds like pconsole's architecture is broken, not necessarily fatally
so since you can manage the privilege issue, but I now think of pconsole
as toxic.  Here's a question: can you cause pconsole to accidentally
clobber some other user's pty?

Nico
-- 

From Nicolas.Williams@sun.com Tue May  5 09:33:57 2009
Received: from newsunmail1brm.central.sun.com (newsunmail1brm.Central.Sun.COM [129.147.62.245])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n45GXv40006805
	for <psarc-ext@sac.sfbay.sun.com>; Tue, 5 May 2009 09:33:57 -0700 (PDT)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.145.155.6])
	by newsunmail1brm.central.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id n45GXiP6061443;
	Tue, 5 May 2009 10:33:55 -0600 (MDT)
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KJ60071ZJCI0N00@nwk-avmta-2.sfbay.sun.com>; Tue,
 05 May 2009 09:33:55 -0700 (PDT)
Received: from binky.Central.Sun.COM ([129.153.128.104])
 by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KJ6004L3JCHON30@nwk-avmta-2.sfbay.sun.com>; Tue,
 05 May 2009 09:33:53 -0700 (PDT)
Received: from binky.Central.Sun.COM (localhost [127.0.0.1])
	by binky.Central.Sun.COM (8.14.3+Sun/8.14.3) with ESMTP id n45GVjpE025495;
 Tue, 05 May 2009 11:31:45 -0500 (CDT)
Received: (from nw141292@localhost)
	by binky.Central.Sun.COM (8.14.3+Sun/8.14.3/Submit) id n45GVjQq025494; Tue,
 05 May 2009 11:31:45 -0500 (CDT)
Date: Tue, 05 May 2009 11:31:45 -0500
From: Nicolas Williams <Nicolas.Williams@sun.com>
Subject: Re: Amendments to pconsole fast-track [PSARC/2009/275 FastTrack
 timeout 05/08/2009]
In-reply-to: <20090505160918.GZ1500@Sun.COM>
To: Norm Jacobs <Norm.Jacobs@sun.com>
Cc: James Carlson <James.D.Carlson@sun.com>, Gary Winiger <gww@eng.sun.com>,
        Leland.Chen@sun.com, psarc-ext@sun.com, timh@spidey.central.sun.com
Message-id: <20090505163144.GA1500@Sun.COM>
MIME-version: 1.0
Content-type: text/plain; charset=us-ascii
Content-transfer-encoding: 7BIT
Content-disposition: inline
X-PMX-Version: 5.4.1.325704
References: <200905012029.n41KTl1V016882@marduk.eng.sun.com>
 <49FB7B91.10305@Sun.COM> <18942.54590.914768.767788@gargle.gargle.HOWL>
 <49FF2725.5000607@Sun.COM> <20090505155712.GY1500@Sun.COM>
 <4A006452.3020702@Sun.COM> <20090505160918.GZ1500@Sun.COM>
X-Authentication-warning: binky.Central.Sun.COM: nw141292 set sender to
 Nicolas.Williams@sun.com using -f
User-Agent: Mutt/1.5.7i
Status: RO
Content-Length: 1257

On Tue, May 05, 2009 at 11:09:18AM -0500, Nicolas Williams wrote:
>            Here's a question: can you cause pconsole to accidentally
> clobber some other user's pty?

I've looked at the source.  pconsole does an open() of a given device
with O_RDWR and adds it to its list only if that succeeds, and it does
not re-open the device.  So I _think_ it's safe.  Note that if you give
pconsole a privilege rather than letting it run as root then you'll need
to change pconsole to be privilege aware and to use setppriv(2) to
switch between having privileges and not.

Still, one ought to look at classic tools like xkibitz for how to do
this the right way.  The fundamental problem here is that pconsole wants
to let you start each connection in a terminal of your choosing (xterm,
rxvt, whatever), and those terminals will manage a pty entirely on their
own, which cuts pconsole out of the loop, which is why it wants that
privilege.

Now, one possibility is that pconsole ought not need any privilege at
all -- that strioctl()/secpolicy_sti() should allow this ioctl when the
caller a) owns the pty and b) has PRIV_PROC_SESSION.  After all, the
caller could just debug the terminal process to insert the desired
characters into the pty master...

Nico
-- 

From Nicolas.Williams@sun.com Tue May  5 09:38:44 2009
Received: from sunmail5.uk.sun.com (sunmail5.UK.Sun.COM [129.156.85.165])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n45Gch2f007106
	for <psarc-ext@sac.sfbay.sun.com>; Tue, 5 May 2009 09:38:44 -0700 (PDT)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by sunmail5.uk.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2) with ESMTP id n45GcbZO010879;
	Tue, 5 May 2009 17:38:39 +0100 (BST)
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KJ600K2NJKFMF00@brm-avmta-1.central.sun.com>; Tue,
 05 May 2009 10:38:39 -0600 (MDT)
Received: from binky.Central.Sun.COM ([129.153.128.104])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KJ6003WEJKE6LE0@brm-avmta-1.central.sun.com>; Tue,
 05 May 2009 10:38:38 -0600 (MDT)
Received: from binky.Central.Sun.COM (localhost [127.0.0.1])
	by binky.Central.Sun.COM (8.14.3+Sun/8.14.3) with ESMTP id n45GaTo3025510;
 Tue, 05 May 2009 11:36:29 -0500 (CDT)
Received: (from nw141292@localhost)
	by binky.Central.Sun.COM (8.14.3+Sun/8.14.3/Submit) id n45GaTYE025509; Tue,
 05 May 2009 11:36:29 -0500 (CDT)
Date: Tue, 05 May 2009 11:36:29 -0500
From: Nicolas Williams <Nicolas.Williams@sun.com>
Subject: Re: Amendments to pconsole fast-track [PSARC/2009/275 FastTrack
 timeout 05/08/2009]
In-reply-to: <20090505163144.GA1500@Sun.COM>
To: Norm Jacobs <Norm.Jacobs@sun.com>
Cc: James Carlson <James.D.Carlson@sun.com>, Gary Winiger <gww@eng.sun.com>,
        Leland.Chen@sun.com, psarc-ext@sun.com, timh@spidey.central.sun.com
Message-id: <20090505163629.GB1500@Sun.COM>
MIME-version: 1.0
Content-type: text/plain; charset=us-ascii
Content-transfer-encoding: 7BIT
Content-disposition: inline
X-PMX-Version: 5.4.1.325704
References: <200905012029.n41KTl1V016882@marduk.eng.sun.com>
 <49FB7B91.10305@Sun.COM> <18942.54590.914768.767788@gargle.gargle.HOWL>
 <49FF2725.5000607@Sun.COM> <20090505155712.GY1500@Sun.COM>
 <4A006452.3020702@Sun.COM> <20090505160918.GZ1500@Sun.COM>
 <20090505163144.GA1500@Sun.COM>
X-Authentication-warning: binky.Central.Sun.COM: nw141292 set sender to
 Nicolas.Williams@sun.com using -f
User-Agent: Mutt/1.5.7i
Status: RO
Content-Length: 592

On Tue, May 05, 2009 at 11:31:45AM -0500, Nicolas Williams wrote:
> Now, one possibility is that pconsole ought not need any privilege at
> all -- that strioctl()/secpolicy_sti() should allow this ioctl when the
> caller a) owns the pty and b) has PRIV_PROC_SESSION.  After all, the
> caller could just debug the terminal process to insert the desired
> characters into the pty master...

Incidentally, if strioctl()/secpolicy_sti() were changed as suggested
then pconsole wouldn't need any changes since it ignores the results of
seteuid(2), and wouldn't need any non-basic privs.

Nico
-- 

From gww@sac.sfbay.sun.com Tue May  5 15:18:07 2009
Received: from newsunmail1brm.central.sun.com (newsunmail1brm.Central.Sun.COM [129.147.62.245])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n45MI7hp013528
	for <psarc-ext@sac.sfbay.sun.com>; Tue, 5 May 2009 15:18:07 -0700 (PDT)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by newsunmail1brm.central.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id n45MI3K4051345
	for <@sunmail2sca.sfbay.sun.com:PSARC-ext@sun.com>; Tue, 5 May 2009 16:18:06 -0600 (MDT)
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KJ600703Z97RO00@brm-avmta-1.central.sun.com> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Tue, 05 May 2009 16:17:31 -0600 (MDT)
Received: from dm-sfbay-01.sfbay.sun.com ([129.145.155.118])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KJ600MN5Z96WB50@brm-avmta-1.central.sun.com> for
 PSARC-ext@sun.com (ORCPT PSARC-ext@sun.com); Tue,
 05 May 2009 16:17:30 -0600 (MDT)
Received: from sac.sfbay.sun.com (sac.SFBay.Sun.COM [129.146.226.132])
	by dm-sfbay-01.sfbay.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2)
 with ESMTP id n45MHT4A004177; Tue, 05 May 2009 15:17:29 -0700 (PDT)
Received: from sac.sfbay.sun.com (localhost [127.0.0.1])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n45MHTeG013520; Tue,
 05 May 2009 15:17:29 -0700 (PDT)
Received: (from gww@localhost)	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8/Submit)
 id n45MHTiK013519; Tue, 05 May 2009 15:17:29 -0700 (PDT)
Date: Tue, 05 May 2009 15:17:29 -0700 (PDT)
From: Gary Winiger <gww@sac.sfbay.sun.com>
Subject: Re: Amendments to pconsole fast-track [PSARC/2009/275 FastTrack
 timeout 05/08/2009]
To: PSARC-ext@sun.com, timh@spidey.Central.Sun.COM
Cc: leland.chen@sun.com, norm.jacobs@sun.com
Message-id: <200905052217.n45MHTiK013519@sac.sfbay.sun.com>
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
Status: RO
Content-Length: 454

> /etc/security/prof_attr:
> Parallel Console Access:::Connect to remote consoles with pconsole:

	To whom/how is this Rights Profile granted?
	Also note that a help file needs to come with the addition of
	a Rights Profile.  See:
	http://opensolaris.org/os/community/arc/bestpractices/rbac-profiles/

> /etc/security/exec_attr:
> Parallel Console Access:suser:cmd:::/usr/sbin/pconsole-bin:euid=0

	I've not seen a conclusion on privileges/uids.

Gary..

From Norm.Jacobs@Sun.COM Wed May  6 00:50:56 2009
Received: from sunmail3mpk.sfbay.sun.com (sunmail3mpk.SFBay.Sun.COM [129.146.11.52])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n467ou1f014513
	for <psarc-ext@sac.sfbay.sun.com>; Wed, 6 May 2009 00:50:56 -0700 (PDT)
Received: from nwk-avmta-1.SFBay.Sun.COM (nwk-avmta-1.SFBay.Sun.COM [129.146.11.74])
	by sunmail3mpk.sfbay.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id n467otKh022298
	for <@sunmail2sca.sfbay.sun.com:PSARC-ext@Sun.COM>; Wed, 6 May 2009 00:50:55 -0700 (PDT)
Received: from pmxchannel-daemon.nwk-avmta-1.sfbay.Sun.COM by
 nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KJ70010BPSTG600@nwk-avmta-1.sfbay.Sun.COM> for PSARC-ext@Sun.COM
 (ORCPT PSARC-ext@Sun.COM); Wed, 06 May 2009 00:50:53 -0700 (PDT)
Received: from dm-sfbay-01.sfbay.sun.com ([129.145.155.118])
 by nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KJ700L9IPSSO2A0@nwk-avmta-1.sfbay.Sun.COM> for
 PSARC-ext@Sun.COM (ORCPT PSARC-ext@Sun.COM); Wed,
 06 May 2009 00:50:52 -0700 (PDT)
Received: from printing.eng.sun.com (printing.SFBay.Sun.COM [129.146.178.26])
	by dm-sfbay-01.sfbay.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2)
 with ESMTP id n467om55016960; Wed, 06 May 2009 00:50:48 -0700 (PDT)
Received: from [10.7.251.237] (punchin-jacobs.SFBay.Sun.COM [10.7.251.237])
	by printing.eng.sun.com (8.14.3+Sun/8.14.3) with ESMTP id n467rYBm022353; Wed,
 06 May 2009 00:53:34 -0700 (PDT)
Date: Wed, 06 May 2009 02:50:47 -0500
From: Norm Jacobs <Norm.Jacobs@Sun.COM>
Subject: Re: Amendments to pconsole fast-track [PSARC/2009/275 FastTrack
 timeout 05/08/2009]
In-reply-to: <200905052217.n45MHTiK013519@sac.sfbay.sun.com>
To: Gary Winiger <gww@sac.sfbay.sun.com>
Cc: psarc-ext@Sun.COM, timh@spidey.Central.Sun.COM, leland.chen@Sun.COM
Message-id: <4A014157.9020406@Sun.COM>
MIME-version: 1.0
Content-type: text/plain; charset=ISO-8859-1; format=flowed
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200905052217.n45MHTiK013519@sac.sfbay.sun.com>
User-Agent: Thunderbird 2.0.0.21 (X11/20090323)
Status: RO
Content-Length: 1331

Gary Winiger wrote:
>> /etc/security/prof_attr:
>> Parallel Console Access:::Connect to remote consoles with pconsole:
>>     
>
> 	To whom/how is this Rights Profile granted?
>   
> 	Also note that a help file needs to come with the addition of
> 	a Rights Profile.  See:
> 	http://opensolaris.org/os/community/arc/bestpractices/rbac-profiles/
>
>   
>> /etc/security/exec_attr:
>> Parallel Console Access:suser:cmd:::/usr/sbin/pconsole-bin:euid=0
>>     
>
> 	I've not seen a conclusion on privileges/uids.
>   
It appears that unless the policy around TIOCSTI changes to allow the 
device owner to use it, then pconsole-bin needs to run with euid=0 to be 
useful.  It seemed like creating a rights profile for this and allowing 
assignment of that rights profile to a select set of users made more 
sense than making pconsole-bin suid root.  With a rights profile, our 
customers can control access to it by assigning this profile to users 
that have a need for pconsole.  With it suid root, anyone can use it and 
potentially use it to effectively hijack someone else's session.  With 
no rights profile and no suid root, you have to become root to use it.

As for who is most likely to use it and therefore need access to the 
profile, I expect, based on the original case, it will be sysadmins 
managing clusters.

    -Norm

From gww@sac.sfbay.sun.com Wed May  6 14:13:56 2009
Received: from sunmail4.singapore.sun.com (sunmail4.Singapore.Sun.COM [129.158.71.19])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n46LDsBm001252
	for <psarc-ext@sac.sfbay.sun.com>; Wed, 6 May 2009 14:13:55 -0700 (PDT)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.145.155.6])
	by sunmail4.singapore.sun.com (8.13.4+Sun/8.13.3/ENSMAIL,v2.2) with ESMTP id n46LDoPd023189
	for <@sunmail2sca.sfbay.sun.com:psarc-ext@Sun.COM>; Thu, 7 May 2009 05:13:54 +0800 (SGT)
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KJ800G0TQZ2OL00@nwk-avmta-2.sfbay.sun.com> for psarc-ext@Sun.COM
 (ORCPT psarc-ext@Sun.COM); Wed, 06 May 2009 14:13:50 -0700 (PDT)
Received: from dm-sfbay-02.sfbay.sun.com ([129.146.11.31])
 by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KJ800D72QZ2IE30@nwk-avmta-2.sfbay.sun.com> for
 psarc-ext@Sun.COM (ORCPT psarc-ext@Sun.COM); Wed,
 06 May 2009 14:13:50 -0700 (PDT)
Received: from sac.sfbay.sun.com (sac.SFBay.Sun.COM [129.146.226.132])
	by dm-sfbay-02.sfbay.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2)
 with ESMTP id n46LDkuF054359; Wed, 06 May 2009 14:13:46 -0700 (PDT)
Received: from sac.sfbay.sun.com (localhost [127.0.0.1])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n46LDiIB001249; Wed,
 06 May 2009 14:13:44 -0700 (PDT)
Received: (from gww@localhost)	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8/Submit)
 id n46LDhM8001248; Wed, 06 May 2009 14:13:43 -0700 (PDT)
Date: Wed, 06 May 2009 14:13:43 -0700 (PDT)
From: Gary Winiger <gww@sac.sfbay.sun.com>
Subject: Re: Amendments to pconsole fast-track [PSARC/2009/275 FastTrack
 timeout 05/08/2009]
To: Norm.Jacobs@sun.com, gww@sac.sfbay.sun.com
Cc: leland.chen@sun.com, psarc-ext@sun.com, timh@spidey.Central.Sun.COM
Message-id: <200905062113.n46LDhM8001248@sac.sfbay.sun.com>
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
Status: RO
Content-Length: 2453

Norm,

	Sorry I didn't number my questions.  I agree a Rights Profile
	is far more in keeping with minimizing the attack surface of
	programs than making them suid.  Any how:
	1) To whom is the "Parallel Console Access" Rights Profile granted?
	2) How is the  "Parallel Console Access" Rights Profile granted to
	   users?
	   What I'm trying to get at here is:  Is Parallel Console Access
	   automatically granted and if so to whom?

	3) A help file needs to be part of creating this Rights Profile.
	   See:
 	   http://opensolaris.org/os/community/arc/bestpractices/rbac-profiles/

	4) Conclusion on privs/uids.
	   Nit: the exec_attr entry s/suser/solaris/
	   Is it really the euid that matters, or is it that euid=0 gives
	   privs=all?  I don't know how to answer the tiocsti question.
	   I'm not sure that's this case (though it would be nice if
	   the policy was revisited and this case dependent on that revisit),
	   but I'm not suggesting that be the a case requirement.

	Perhaps an offline email if I've not been clear.

Thankx,
Gary..
> Gary Winiger wrote:
> >> /etc/security/prof_attr:
> >> Parallel Console Access:::Connect to remote consoles with pconsole:
> >>     
> >
> > 	To whom/how is this Rights Profile granted?
> >   
> > 	Also note that a help file needs to come with the addition of
> > 	a Rights Profile.  See:
> > 	http://opensolaris.org/os/community/arc/bestpractices/rbac-profiles/
> >
> >   
> >> /etc/security/exec_attr:
> >> Parallel Console Access:suser:cmd:::/usr/sbin/pconsole-bin:euid=0
> >>     
> >
> > 	I've not seen a conclusion on privileges/uids.
> >   
> It appears that unless the policy around TIOCSTI changes to allow the 
> device owner to use it, then pconsole-bin needs to run with euid=0 to be 
> useful.  It seemed like creating a rights profile for this and allowing 
> assignment of that rights profile to a select set of users made more 
> sense than making pconsole-bin suid root.  With a rights profile, our 
> customers can control access to it by assigning this profile to users 
> that have a need for pconsole.  With it suid root, anyone can use it and 
> potentially use it to effectively hijack someone else's session.  With 
> no rights profile and no suid root, you have to become root to use it.
> 
> As for who is most likely to use it and therefore need access to the 
> profile, I expect, based on the original case, it will be sysadmins 
> managing clusters.
> 
>     -Norm
> 

From gww@sac.sfbay.sun.com Wed May  6 15:54:22 2009
Received: from sunmail5.uk.sun.com (sunmail5.UK.Sun.COM [129.156.85.165])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n46MsLEw003810
	for <psarc-ext@sac.sfbay.sun.com>; Wed, 6 May 2009 15:54:22 -0700 (PDT)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.145.155.6])
	by sunmail5.uk.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2) with ESMTP id n46MsHlo001680
	for <@sunmail2sca.sfbay.sun.com:psarc-ext@sun.com>; Wed, 6 May 2009 23:54:21 +0100 (BST)
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KJ800M05VMK9E00@nwk-avmta-2.sfbay.sun.com> for psarc-ext@sun.com
 (ORCPT psarc-ext@sun.com); Wed, 06 May 2009 15:54:20 -0700 (PDT)
Received: from dm-sfbay-02.sfbay.sun.com ([129.146.11.31])
 by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KJ800DMZVMKI490@nwk-avmta-2.sfbay.sun.com> for
 psarc-ext@sun.com (ORCPT psarc-ext@sun.com); Wed,
 06 May 2009 15:54:20 -0700 (PDT)
Received: from sac.sfbay.sun.com (sac.SFBay.Sun.COM [129.146.226.132])
	by dm-sfbay-02.sfbay.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2)
 with ESMTP id n46MsHCO054340; Wed, 06 May 2009 15:54:17 -0700 (PDT)
Received: from sac.sfbay.sun.com (localhost [127.0.0.1])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n46MsHxf003808; Wed,
 06 May 2009 15:54:17 -0700 (PDT)
Received: (from gww@localhost)	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8/Submit)
 id n46MsHqH003807; Wed, 06 May 2009 15:54:17 -0700 (PDT)
Date: Wed, 06 May 2009 15:54:17 -0700 (PDT)
From: Gary Winiger <gww@sac.sfbay.sun.com>
Subject: Re: Amendments to pconsole fast-track [PSARC/2009/275 FastTrack
 timeout 05/08/2009]
To: Norm.Jacobs@sun.com, gww@sac.sfbay.sun.com
Cc: leland.chen@sun.com, nicolas.williams@sun.com, psarc-ext@sun.com,
        timh@spidey.Central.Sun.COM
Message-id: <200905062254.n46MsHqH003807@sac.sfbay.sun.com>
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
Status: RO
Content-Length: 1827

> Norm,

> 	4) Conclusion on privs/uids.
> 	   Nit: the exec_attr entry s/suser/solaris/
> 	   Is it really the euid that matters, or is it that euid=0 gives
> 	   privs=all?  I don't know how to answer the tiocsti question.
> 	   I'm not sure that's this case (though it would be nice if
> 	   the policy was revisited and this case dependent on that revisit),
> 	   but I'm not suggesting that be the a case requirement.
> 
> 	Perhaps an offline email if I've not been clear.

	Talking to Nico off line about something else, he said he'd looked
	some at tiocsti and felt it was a bug that you couldn't control
	the tty/pty that you own.  I don't find TIOCSTI adequately
	documented by Sun.  But google did it.  

	From my understanding of what it does, feeds input to a tty,
	I would say privs=all is quite extreme.  The secpolicy_sti()
	comment says: "Simulate terminal input; another escalation of
	privileges avenue"
	I can see that if you're writing to a tty that you don't own.
	But if you own it, IMO this shouldn't be the policy and it is
	a bug.  IMO, the correct architectural thing to do here is
	to fix the bug.  I'd guess the policy to be, if you have write
	access to the tty, you should be able to issue a TIOCSTI.
	And to stop privilege escalation, the if owned by uid 0 policy
	also comes into play (file_dac_write is insufficient, privs=all
	is required).

	IMO, this case should be withdrawn and the bug should be fixed.
	If I'm wrong about the bug, then the case should be reintroduced
	with rational as to why there isn't a bug and what the policy really
	should be for TIOCSTI.

	I'll give the project team a while to answer this before considering
	further steps, such as withdrawn, waiting need spec or even derail
	for a meeting.

Trying to stomp out bugs (that lead to unnecssary privileges),
Gary..

From Leland.Chen@Sun.COM Wed May  6 16:15:31 2009
Received: from sunmail3mpk.sfbay.sun.com (sunmail3mpk.SFBay.Sun.COM [129.146.11.52])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n46NFVGf004126
	for <psarc-ext@sac.sfbay.sun.com>; Wed, 6 May 2009 16:15:31 -0700 (PDT)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.145.155.6])
	by sunmail3mpk.sfbay.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id n46NFUel012098
	for <@sunmail2sca.sfbay.sun.com:psarc-ext@sun.com>; Wed, 6 May 2009 16:15:30 -0700 (PDT)
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KJ800001WLUER00@nwk-avmta-2.sfbay.sun.com> for psarc-ext@sun.com
 (ORCPT psarc-ext@Sun.COM); Wed, 06 May 2009 16:15:30 -0700 (PDT)
Received: from sca-es-mail-2.sun.com ([192.18.43.133])
 by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KJ800DPWWLUI4A0@nwk-avmta-2.sfbay.sun.com> for
 psarc-ext@sun.com (ORCPT psarc-ext@Sun.COM); Wed,
 06 May 2009 16:15:30 -0700 (PDT)
Received: from fe-sfbay-09.sun.com ([192.18.43.129])
	by sca-es-mail-2.sun.com (8.13.7+Sun/8.12.9) with ESMTP id n46NFU3r015205	for
 <psarc-ext@Sun.COM>; Wed, 06 May 2009 16:15:30 -0700 (PDT)
Received: from conversion-daemon.fe-sfbay-09.sun.com by fe-sfbay-09.sun.com
 (Sun Java(tm) System Messaging Server 7.0-5.01 64bit (built Feb 19 2009))
 id <0KJ800700VW8GB00@fe-sfbay-09.sun.com> for psarc-ext@Sun.COM
 (ORCPT psarc-ext@Sun.COM); Wed, 06 May 2009 16:15:30 -0700 (PDT)
Received: from [129.146.104.15] ([unknown] [129.146.104.15])
 by fe-sfbay-09.sun.com
 (Sun Java(tm) System Messaging Server 7.0-5.01 64bit (built Feb 19 2009))
 with ESMTPSA id <0KJ8007FHWLFODB0@fe-sfbay-09.sun.com>; Wed,
 06 May 2009 16:15:16 -0700 (PDT)
Date: Wed, 06 May 2009 16:26:53 -0700
From: Leland Chen <Leland.Chen@Sun.COM>
Subject: Re: Amendments to pconsole fast-track [PSARC/2009/275 FastTrack
 timeout 05/08/2009]
In-reply-to: <200905062113.n46LDhM8001248@sac.sfbay.sun.com>
Sender: Leland.Chen@Sun.COM
To: Gary Winiger <gww@sac.sfbay.sun.com>
Cc: Norm.Jacobs@Sun.COM, PSARC-ext@Sun.COM, timh@spidey.Central.Sun.COM
Message-id: <4A021CBD.1050207@sun.com>
MIME-version: 1.0
Content-type: text/plain; format=flowed; charset=ISO-8859-1
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200905062113.n46LDhM8001248@sac.sfbay.sun.com>
User-Agent: Thunderbird 2.0.0.4 (X11/20070622)
Status: RO
Content-Length: 3905

Gary,

    Please find my answers below.

    Thanks,

   Leland

> Norm,
>
> 	Sorry I didn't number my questions.  I agree a Rights Profile
> 	is far more in keeping with minimizing the attack surface of
> 	programs than making them suid.  Any how:
> 	1) To whom is the "Parallel Console Access" Rights Profile granted?
> 	2) How is the  "Parallel Console Access" Rights Profile granted to
> 	   users?
> 	   What I'm trying to get at here is:  Is Parallel Console Access
> 	   automatically granted and if so to whom?
>   
We, SunCluster added pconsole to OpenSolaris because the feedback from 
customers
and fields indicate that they prefer pconsole than cconsole, which is 
also a parallel remote
access console shipped along with Cluster bits.

The typical use case is a system admin uses pconsole/cconsole to do 
system level
configuration(such as shared disk and mount point), cluster software 
installation
and installation for the applications using the cluster. Usually these 
tasks are
same operations on multiple systems, and users are system admins who have
the root account privilege.  Actually, some of the application 
installation/configuration
type of tasks really don't have to have root privilege. For example, 
oracle DB
or Web/App server installation/configuration on multiple systems for the
cluster failover/scalable services.

For the 2nd question. I guess we expect system admins to assign 
"Parallel Console Access" profile
to the user accounts. For example, system admin could assign the profile 
to to oracle dba
account, so oracle DB admins with dba account can do the oracle 
configuration on a set of
systems.

> 	3) A help file needs to be part of creating this Rights Profile.
> 	   See:
>  	   http://opensolaris.org/os/community/arc/bestpractices/rbac-profiles/
>
>   
I will look at other examples to come up a help file.
> 	4) Conclusion on privs/uids.
> 	   Nit: the exec_attr entry s/suser/solaris/
> 	   Is it really the euid that matters, or is it that euid=0 gives
> 	   privs=all?  I don't know how to answer the tiocsti question.
> 	   I'm not sure that's this case (though it would be nice if
> 	   the policy was revisited and this case dependent on that revisit),
> 	   but I'm not suggesting that be the a case requirement.
>
>   
I am not familiar with this area. Hopefully, Norm/Tim can help on this.


> 	Perhaps an offline email if I've not been clear.
>
> Thankx,
> Gary..
>   
>> Gary Winiger wrote:
>>     
>>>> /etc/security/prof_attr:
>>>> Parallel Console Access:::Connect to remote consoles with pconsole:
>>>>     
>>>>         
>>> 	To whom/how is this Rights Profile granted?
>>>   
>>> 	Also note that a help file needs to come with the addition of
>>> 	a Rights Profile.  See:
>>> 	http://opensolaris.org/os/community/arc/bestpractices/rbac-profiles/
>>>
>>>   
>>>       
>>>> /etc/security/exec_attr:
>>>> Parallel Console Access:suser:cmd:::/usr/sbin/pconsole-bin:euid=0
>>>>     
>>>>         
>>> 	I've not seen a conclusion on privileges/uids.
>>>   
>>>       
>> It appears that unless the policy around TIOCSTI changes to allow the 
>> device owner to use it, then pconsole-bin needs to run with euid=0 to be 
>> useful.  It seemed like creating a rights profile for this and allowing 
>> assignment of that rights profile to a select set of users made more 
>> sense than making pconsole-bin suid root.  With a rights profile, our 
>> customers can control access to it by assigning this profile to users 
>> that have a need for pconsole.  With it suid root, anyone can use it and 
>> potentially use it to effectively hijack someone else's session.  With 
>> no rights profile and no suid root, you have to become root to use it.
>>
>> As for who is most likely to use it and therefore need access to the 
>> profile, I expect, based on the original case, it will be sysadmins 
>> managing clusters.
>>
>>     -Norm
>>
>>     


From gww@eng.sun.com Wed May  6 16:25:48 2009
Received: from sunmail5.uk.sun.com (sunmail5.UK.Sun.COM [129.156.85.165])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n46NPmow004196
	for <psarc-ext@sac.sfbay.sun.com>; Wed, 6 May 2009 16:25:48 -0700 (PDT)
Received: from nwk-avmta-1.SFBay.Sun.COM (nwk-avmta-1.SFBay.Sun.COM [129.146.11.74])
	by sunmail5.uk.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2) with ESMTP id n46NPg9g020366
	for <@sunmail2sca.sfbay.sun.com:psarc-ext@sun.com>; Thu, 7 May 2009 00:25:47 +0100 (BST)
Received: from pmxchannel-daemon.nwk-avmta-1.sfbay.Sun.COM by
 nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KJ800205X2XIL00@nwk-avmta-1.sfbay.Sun.COM> for psarc-ext@sun.com
 (ORCPT psarc-ext@sun.com); Wed, 06 May 2009 16:25:45 -0700 (PDT)
Received: from dm-eng-02.sfbay.sun.com ([129.146.11.32])
 by nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KJ800KQ8X2WE5C0@nwk-avmta-1.sfbay.Sun.COM> for
 psarc-ext@sun.com (ORCPT psarc-ext@sun.com); Wed,
 06 May 2009 16:25:44 -0700 (PDT)
Received: from marduk.eng.sun.com (marduk.SFBay.Sun.COM [129.146.108.224])
	by dm-eng-02.sfbay.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2)
 with ESMTP id n46NPglU006900; Wed, 06 May 2009 16:25:42 -0700 (PDT)
Received: from marduk.eng.sun.com (localhost [127.0.0.1])
	by marduk.eng.sun.com (8.13.6+Sun/8.12.11) with ESMTP id n46NOjXo021249; Wed,
 06 May 2009 16:24:45 -0700 (PDT)
Received: (from gww@localhost)
	by marduk.eng.sun.com (8.13.6+Sun/8.12.11/Submit) id n46NOjVY021248; Wed,
 06 May 2009 16:24:45 -0700 (PDT)
Date: Wed, 06 May 2009 16:24:45 -0700 (PDT)
From: Gary Winiger <gww@eng.sun.com>
Subject: Re: Amendments to pconsole fast-track [PSARC/2009/275 FastTrack
 timeout 05/08/2009]
To: Norm.Jacobs@sun.com, gww@sac.sfbay.sun.com
Cc: leland.chen@sun.com, nicolas.williams@sun.com, psarc-ext@sun.com,
        timh@spidey.central.sun.com
Message-id: <200905062324.n46NOjVY021248@marduk.eng.sun.com>
Content-transfer-encoding: 7BIT
X-Sun-Charset: US-ASCII
X-PMX-Version: 5.4.1.325704
Status: RO
Content-Length: 487

> 
> 	IMO, this case should be withdrawn and the bug should be fixed.
> 	If I'm wrong about the bug, then the case should be reintroduced
> 	with rational as to why there isn't a bug and what the policy really
> 	should be for TIOCSTI.
> 
> 	I'll give the project team a while to answer this before considering
> 	further steps, such as withdrawn, waiting need spec or even derail
> 	for a meeting.

	Filed:
	P3, 6838249 The TIOCSTI policy appears to require too many privileges

Gary..

From Norm.Jacobs@sun.com Wed May  6 22:07:44 2009
Received: from sunmail2sca.sfbay.sun.com (sunmail2sca.SFBay.Sun.COM [129.145.155.234])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n4757igR007021
	for <psarc-ext@sac.sfbay.sun.com>; Wed, 6 May 2009 22:07:44 -0700 (PDT)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.145.155.6])
	by sunmail2sca.sfbay.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id n4757hhj014093
	for <@sunmail2sca.sfbay.sun.com:psarc-ext@Sun.COM>; Wed, 6 May 2009 22:07:44 -0700 (PDT)
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KJ900005CWVPB00@nwk-avmta-2.sfbay.sun.com> for psarc-ext@Sun.COM
 (ORCPT psarc-ext@Sun.COM); Wed, 06 May 2009 22:07:43 -0700 (PDT)
Received: from dm-sfbay-01.sfbay.sun.com ([129.145.155.118])
 by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KJ900JN7CWUDW20@nwk-avmta-2.sfbay.sun.com> for
 psarc-ext@Sun.COM (ORCPT psarc-ext@Sun.COM); Wed,
 06 May 2009 22:07:42 -0700 (PDT)
Received: from printing.eng.sun.com (printing.SFBay.Sun.COM [129.146.178.26])
	by dm-sfbay-01.sfbay.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2)
 with ESMTP id n4757fpj053849; Wed, 06 May 2009 22:07:41 -0700 (PDT)
Received: from [10.7.251.237] (punchin-jacobs.SFBay.Sun.COM [10.7.251.237])
	by printing.eng.sun.com (8.14.3+Sun/8.14.3) with ESMTP id n475AQvY022647; Wed,
 06 May 2009 22:10:27 -0700 (PDT)
Date: Thu, 07 May 2009 00:07:39 -0500
From: Norm Jacobs <Norm.Jacobs@sun.com>
Subject: Re: Amendments to pconsole fast-track [PSARC/2009/275 FastTrack
 timeout 05/08/2009]
In-reply-to: <200905062324.n46NOjVY021248@marduk.eng.sun.com>
To: Gary Winiger <gww@eng.sun.com>
Cc: gww@sac.sfbay.sun.com, leland.chen@sun.com, nicolas.williams@sun.com,
        psarc-ext@sun.com, timh@spidey.central.sun.com
Message-id: <4A026C9B.7070007@Sun.COM>
MIME-version: 1.0
Content-type: text/plain; charset=ISO-8859-1; format=flowed
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200905062324.n46NOjVY021248@marduk.eng.sun.com>
User-Agent: Thunderbird 2.0.0.21 (X11/20090323)
Status: RO
Content-Length: 644

Gary Winiger wrote:
>> 	IMO, this case should be withdrawn and the bug should be fixed.
>> 	If I'm wrong about the bug, then the case should be reintroduced
>> 	with rational as to why there isn't a bug and what the policy really
>> 	should be for TIOCSTI.
>>
>> 	I'll give the project team a while to answer this before considering
>> 	further steps, such as withdrawn, waiting need spec or even derail
>> 	for a meeting.
>>     
>
> 	Filed:
> 	P3, 6838249 The TIOCSTI policy appears to require too many privileges
>   
If we consider TIOCSTI failure with EPERM on devices you own a bug, then 
this case can probably be withdrawn.

    -Norm


From casper@holland.sun.com Thu May  7 01:14:20 2009
Received: from newsunmail1brm.central.sun.com (newsunmail1brm.Central.Sun.COM [129.147.62.245])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n478EKT8008986
	for <psarc-ext@sac.sfbay.sun.com>; Thu, 7 May 2009 01:14:20 -0700 (PDT)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.145.155.6])
	by newsunmail1brm.central.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id n478E5I5033794
	for <@sunmail2sca.sfbay.sun.com:psarc-ext@Sun.COM>; Thu, 7 May 2009 02:14:19 -0600 (MDT)
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KJ900C0FLJL7L00@nwk-avmta-2.sfbay.sun.com> for psarc-ext@Sun.COM
 (ORCPT psarc-ext@Sun.COM); Thu, 07 May 2009 01:14:09 -0700 (PDT)
Received: from dm-holland-02.uk.sun.com ([129.156.101.225])
 by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KJ900JXLLJKE3A0@nwk-avmta-2.sfbay.sun.com> for
 psarc-ext@Sun.COM (ORCPT psarc-ext@Sun.COM); Thu,
 07 May 2009 01:14:09 -0700 (PDT)
Received: from holland (room101.Holland.Sun.COM [10.16.117.40])
	by dm-holland-02.uk.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2)
 with ESMTP id n478Dw9m046180; Thu, 07 May 2009 09:13:58 +0100 (BST)
Date: Thu, 07 May 2009 10:13:58 +0200
From: Casper.Dik@sun.com
Subject: Re: Amendments to pconsole fast-track [PSARC/2009/275 FastTrack
 timeout 05/08/2009]
In-reply-to: <200905062254.n46MsHqH003807@sac.sfbay.sun.com>
Sender: casper@holland.sun.com
To: Gary Winiger <gww@sac.sfbay.sun.com>
Cc: Norm.Jacobs@sun.com, Leland.Chen@sun.com, Nicolas.Williams@sun.com,
        psarc-ext@sun.com, timh@spidey.Central.Sun.COM
Message-id: <200905070813.n478Dw9m046180@dm-holland-02.uk.sun.com>
MIME-version: 1.0
Content-type: text/plain; charset=us-ascii
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200905062254.n46MsHqH003807@sac.sfbay.sun.com>
Status: RO
Content-Length: 1006


>> Norm,
>
>> 	4) Conclusion on privs/uids.
>> 	   Nit: the exec_attr entry s/suser/solaris/
>> 	   Is it really the euid that matters, or is it that euid=0 gives
>> 	   privs=all?  I don't know how to answer the tiocsti question.
>> 	   I'm not sure that's this case (though it would be nice if
>> 	   the policy was revisited and this case dependent on that revisit),
>> 	   but I'm not suggesting that be the a case requirement.
>> 
>> 	Perhaps an offline email if I've not been clear.
>
>	Talking to Nico off line about something else, he said he'd looked
>	some at tiocsti and felt it was a bug that you couldn't control
>	the tty/pty that you own.  I don't find TIOCSTI adequately
>	documented by Sun.  But google did it.  

The reason behind this is the owner doesn't really tell everything.

If a user has run su in one terminal, any other terminal can be used to
control "su"; this includes any form of malware.  I wdon't want to change 
it because it still allows privilege escalation.

Casper


From casper@holland.sun.com Thu May  7 01:24:52 2009
Received: from sunmail5.uk.sun.com (sunmail5.UK.Sun.COM [129.156.85.165])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n478OpAc009025
	for <psarc-ext@sac.sfbay.sun.com>; Thu, 7 May 2009 01:24:52 -0700 (PDT)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by sunmail5.uk.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2) with ESMTP id n478OlY0019653
	for <@sunmail2sca.sfbay.sun.com:PSARC-ext@Sun.COM>; Thu, 7 May 2009 09:24:51 +0100 (BST)
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KJ900D05M1ENE00@brm-avmta-1.central.sun.com> for PSARC-ext@Sun.COM
 (ORCPT PSARC-ext@Sun.COM); Thu, 07 May 2009 02:24:50 -0600 (MDT)
Received: from dm-holland-02.uk.sun.com ([129.156.101.225])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KJ900DL3M1E2T00@brm-avmta-1.central.sun.com> for
 PSARC-ext@Sun.COM (ORCPT PSARC-ext@Sun.COM); Thu,
 07 May 2009 02:24:50 -0600 (MDT)
Received: from holland (room101.Holland.Sun.COM [10.16.117.40])
	by dm-holland-02.uk.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2)
 with ESMTP id n478OgsV049778; Thu, 07 May 2009 09:24:42 +0100 (BST)
Date: Thu, 07 May 2009 10:24:42 +0200
From: Casper.Dik@sun.com
Subject: Re: Amendments to pconsole fast-track [PSARC/2009/275 FastTrack
 timeout 05/08/2009]
In-reply-to: <4A026C9B.7070007@Sun.COM>
Sender: casper@holland.sun.com
To: Norm Jacobs <Norm.Jacobs@sun.com>
Cc: Gary Winiger <gww@eng.sun.com>, gww@sac.sfbay.sun.com, Leland.Chen@sun.com,
        Nicolas.Williams@sun.com, PSARC-ext@sun.com,
        timh@spidey.central.sun.com
Message-id: <200905070824.n478OgsV049778@dm-holland-02.uk.sun.com>
MIME-version: 1.0
Content-type: text/plain; charset=us-ascii
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200905062324.n46NOjVY021248@marduk.eng.sun.com>
 <4A026C9B.7070007@Sun.COM>
Status: RO
Content-Length: 933


>Gary Winiger wrote:
>>> 	IMO, this case should be withdrawn and the bug should be fixed.
>>> 	If I'm wrong about the bug, then the case should be reintroduced
>>> 	with rational as to why there isn't a bug and what the policy really
>>> 	should be for TIOCSTI.
>>>
>>> 	I'll give the project team a while to answer this before considering
>>> 	further steps, such as withdrawn, waiting need spec or even derail
>>> 	for a meeting.
>>>     
>>
>> 	Filed:
>> 	P3, 6838249 The TIOCSTI policy appears to require too many privileges
>>   
>If we consider TIOCSTI failure with EPERM on devices you own a bug, then 
>this case can probably be withdrawn.


Unfortunately, I don't agree.

So what do other OSes do?

I think it's very dangerous to allow TIOCSTI, even if you own the terminal.

(Before, firefox can only run as me, if you change the semantics for 
TIOCSTI, then firefox can run as root if I've su'ed in some window)

Casper


From unixconsole@yahoo.com Thu May  7 05:16:28 2009
Received: from sunmail4.singapore.sun.com (sunmail4.Singapore.Sun.COM [129.158.71.19])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n47CGR7W009229
	for <psarc-ext@sac.sfbay.sun.com>; Thu, 7 May 2009 05:16:27 -0700 (PDT)
Received: from nwk-avmta-1.SFBay.Sun.COM (nwk-avmta-1.SFBay.Sun.COM [129.146.11.74])
	by sunmail4.singapore.sun.com (8.13.4+Sun/8.13.3/ENSMAIL,v2.2) with ESMTP id n47CGGb1009146
	for <@sunmail2sca.sfbay.sun.com:PSARC-ext@sun.com>; Thu, 7 May 2009 20:16:26 +0800 (SGT)
Received: from pmxchannel-daemon.nwk-avmta-1.sfbay.Sun.COM by
 nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KJ900D07WRB7U00@nwk-avmta-1.sfbay.Sun.COM> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@Sun.COM); Thu, 07 May 2009 05:16:23 -0700 (PDT)
Received: from sca-ea-mail-2.sun.com ([192.18.43.25])
 by nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KJ9001XKWRBMZE0@nwk-avmta-1.sfbay.Sun.COM> for
 PSARC-ext@sun.com (ORCPT PSARC-ext@Sun.COM); Thu,
 07 May 2009 05:16:23 -0700 (PDT)
Received: from relay42i.sun.com ([192.5.209.72])
	by sca-ea-mail-2.sun.com (8.13.7+Sun/8.12.9) with ESMTP id n47C0d7g006542	for
 <PSARC-ext@Sun.COM>; Thu, 07 May 2009 12:16:22 +0000 (GMT)
Received: from mms48es.mms.us.syntegra.com ([160.41.221.230] [160.41.221.230])
 by relay42i.sun.com with ESMTP id BT-MMP-2887384 for PSARC-ext@Sun.COM; Thu,
 07 May 2009 12:16:22 +0000 (Z)
Received: from relay41i.sun.com (relay41i.sun.com [192.5.209.70])
 by mms48es.mms.us.syntegra.com with ESMTP id BT-MMP-9733322 for
 PSARC-ext@Sun.COM; Thu, 07 May 2009 12:16:22 +0000 (Z)
Received: from web30803.mail.mud.yahoo.com ([68.142.200.146] [68.142.200.146])
 by relay4i.sun.com id BT-MMP-1536470 for PSARC-ext@Sun.COM; Thu,
 07 May 2009 12:16:22 +0000 (Z)
Received: (qmail 943 invoked by uid 60001); Thu, 07 May 2009 12:15:45 +0000
Received: from [67.232.124.140] by web30803.mail.mud.yahoo.com via HTTP; Thu,
 07 May 2009 05:15:44 -0700 (PDT)
Date: Thu, 07 May 2009 05:15:44 -0700 (PDT)
From: Octave Orgeron <unixconsole@yahoo.com>
Subject: Re: Amendments to pconsole fast-track [PSARC/2009/275 FastTrack
 timeout 05/08/2009]
In-reply-to: <4A021CBD.1050207@sun.com>
To: Leland Chen <Leland.Chen@sun.com>, Gary Winiger <gww@sac.sfbay.sun.com>
Cc: Norm.Jacobs@sun.com, PSARC-ext@sun.com, timh@spidey.Central.Sun.COM
Message-id: <956723.99898.qm@web30803.mail.mud.yahoo.com>
MIME-version: 1.0
X-Mailer: YahooMailRC/1277.35 YahooMailWebService/0.7.289.1
Content-type: text/plain; charset=us-ascii
Content-transfer-encoding: 7BIT
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=yahoo.com; s=s1024;
 t=1241698544; bh=QX3MUsG20EL3h+X07aG5jBkJS0lFwMiFPr5oWDvgatc=;
 h=Message-ID:X-YMail-OSG:Received:X-Mailer:References:Date:From:Subject:To:Cc:In-Reply-To:MIME-Version:Content-Type;
 b=4eDXsDg2VmnuN1NM9cZOmm+pBKdG6yEh9PVmUmI7Duk9rHn62eBaCtuGGot6rrmZD3CL7Idec58mtgy1W8gdbAEDkUOuu1lZObExuADktIYupOO8SgZJne6PB/gnpdC8oHG/WxfBQRt7iULaRx8ytI7P0lpkAg3URA+YU1dKt/A=
DomainKey-Signature: a=rsa-sha1; q=dns; c=nofws;  s=s1024; d=yahoo.com;
 h=Message-ID:X-YMail-OSG:Received:X-Mailer:References:Date:From:Subject:To:Cc:In-Reply-To:MIME-Version:Content-Type;
 b=eHeRHXPv+it9QI98hXmfewpEjGo5HPTLgUJ096fDXpwksZnKilfI9ouv8FyzAlwIKF0coduRGiEuYO+I9+eRowZCO7YZmtTYTlAhTNAhYQhXiImJGqb8dspEb1Bok+swjl8xl5w+zwAFfHPRjOvYlwOhSMkBTGmbvHIjbpLEbfI=;
X-PMX-Version: 5.4.1.325704
X-Brightmail-Tracker: AAAAAA==
X-YMail-OSG: 
 6qniQqQVM1mCJttKrqSUMZ6KDMR1PPWSgFU0Tcm6WLujCy3ZBKKmcsI1cGbBsg6csUSxVoV47wsnw6RtbCNPNBP_kLzxt..BbCrJFn4WJWhA3HEl8U.SZJWhZLt_myjSsfY9nrGYtI8FP3x_5dp8ZGGmRdEDq0M.TKxWbimPPQbcKJ.rEwSQJL0GrgLveL9r4pn3UjAJmclalaYYDmEETYtYU.ExOH7RMJFqgiMp996xychdoQlfguHg.KzS5eUnjf9D4DUi2cJ56lq4FzW8bOQq1lohbTeapnZzeXRkfanEkGozFcb_i2jwa9yH.JCskFszBUGRNb1XhbjTThgeJiuZud1P1GNhwa0TxHHanpKO6Q--
X-Antispam: No, score=-1.1/5.0, scanned in 0.132sec at (localhost [127.0.0.1])
	by smf-spamd v1.3.1 - http://smfs.sf.net/
References: <200905062113.n46LDhM8001248@sac.sfbay.sun.com>
 <4A021CBD.1050207@sun.com>
Status: RO
Content-Length: 5236


While pconsole is very handy for HA clusters, it is also widely used in N1GE/SGE grids as well. It's a very handy tool for doing the same tasks across systems at the same time with SSH. In the open source landscape, this is the best tool available. For the security concerns, most shops will setup things like sudo for SAs to use pconsole. I'd prefer to see an RBAC profile for using pconsole. It would be interesting to change the way pconsole works so that root privs are not required. The xterms that it starts up should be owned by the same user who is running pconsole. Hopefully there is an easy solution.

 *-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*
Octave J. Orgeron
Solaris Virtualization Architect and Consultant
Web: http://unixconsole.blogspot.com
E-Mail: unixconsole@yahoo.com
*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*



----- Original Message ----
From: Leland Chen <Leland.Chen@Sun.COM>
To: Gary Winiger <gww@sac.sfbay.sun.com>
Cc: Norm.Jacobs@Sun.COM; PSARC-ext@Sun.COM; timh@spidey.Central.Sun.COM
Sent: Wednesday, May 6, 2009 6:26:53 PM
Subject: Re: Amendments to pconsole fast-track [PSARC/2009/275 FastTrack timeout 05/08/2009]

Gary,

   Please find my answers below.

   Thanks,

  Leland

> Norm,
> 
>     Sorry I didn't number my questions.  I agree a Rights Profile
>     is far more in keeping with minimizing the attack surface of
>     programs than making them suid.  Any how:
>     1) To whom is the "Parallel Console Access" Rights Profile granted?
>     2) How is the  "Parallel Console Access" Rights Profile granted to
>        users?
>        What I'm trying to get at here is:  Is Parallel Console Access
>        automatically granted and if so to whom?
>  
We, SunCluster added pconsole to OpenSolaris because the feedback from customers
and fields indicate that they prefer pconsole than cconsole, which is also a parallel remote
access console shipped along with Cluster bits.

The typical use case is a system admin uses pconsole/cconsole to do system level
configuration(such as shared disk and mount point), cluster software installation
and installation for the applications using the cluster. Usually these tasks are
same operations on multiple systems, and users are system admins who have
the root account privilege.  Actually, some of the application installation/configuration
type of tasks really don't have to have root privilege. For example, oracle DB
or Web/App server installation/configuration on multiple systems for the
cluster failover/scalable services.

For the 2nd question. I guess we expect system admins to assign "Parallel Console Access" profile
to the user accounts. For example, system admin could assign the profile to to oracle dba
account, so oracle DB admins with dba account can do the oracle configuration on a set of
systems.

>     3) A help file needs to be part of creating this Rights Profile.
>        See:
>         http://opensolaris.org/os/community/arc/bestpractices/rbac-profiles/
> 
>  
I will look at other examples to come up a help file.
>     4) Conclusion on privs/uids.
>        Nit: the exec_attr entry s/suser/solaris/
>        Is it really the euid that matters, or is it that euid=0 gives
>        privs=all?  I don't know how to answer the tiocsti question.
>        I'm not sure that's this case (though it would be nice if
>        the policy was revisited and this case dependent on that revisit),
>        but I'm not suggesting that be the a case requirement.
> 
>  
I am not familiar with this area. Hopefully, Norm/Tim can help on this.


>     Perhaps an offline email if I've not been clear.
> 
> Thankx,
> Gary..
>  
>> Gary Winiger wrote:
>>    
>>>> /etc/security/prof_attr:
>>>> Parallel Console Access:::Connect to remote consoles with pconsole:
>>>>            
>>>     To whom/how is this Rights Profile granted?
>>>       Also note that a help file needs to come with the addition of
>>>     a Rights Profile.  See:
>>>     http://opensolaris.org/os/community/arc/bestpractices/rbac-profiles/
>>> 
>>>        
>>>> /etc/security/exec_attr:
>>>> Parallel Console Access:suser:cmd:::/usr/sbin/pconsole-bin:euid=0
>>>>            
>>>     I've not seen a conclusion on privileges/uids.
>>>        
>> It appears that unless the policy around TIOCSTI changes to allow the device owner to use it, then pconsole-bin needs to run with euid=0 to be useful.  It seemed like creating a rights profile for this and allowing assignment of that rights profile to a select set of users made more sense than making pconsole-bin suid root.  With a rights profile, our customers can control access to it by assigning this profile to users that have a need for pconsole.  With it suid root, anyone can use it and potentially use it to effectively hijack someone else's session.  With no rights profile and no suid root, you have to become root to use it.
>> 
>> As for who is most likely to use it and therefore need access to the profile, I expect, based on the original case, it will be sysadmins managing clusters.
>> 
>>     -Norm
>> 
>>    

_______________________________________________
opensolaris-arc mailing list
opensolaris-arc@opensolaris.org



      

From Norm.Jacobs@Sun.COM Thu May  7 08:02:06 2009
Received: from newsunmail1brm.central.sun.com (newsunmail1brm.Central.Sun.COM [129.147.62.245])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n47F26QL024226
	for <psarc-ext@sac.sfbay.sun.com>; Thu, 7 May 2009 08:02:06 -0700 (PDT)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.145.155.6])
	by newsunmail1brm.central.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id n47F26mI011299
	for <@sunmail2sca.sfbay.sun.com:psarc-ext@Sun.COM>; Thu, 7 May 2009 09:02:06 -0600 (MDT)
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KJA00B2B4FHY800@nwk-avmta-2.sfbay.sun.com> for psarc-ext@Sun.COM
 (ORCPT psarc-ext@Sun.COM); Thu, 07 May 2009 08:02:05 -0700 (PDT)
Received: from dm-sfbay-02.sfbay.sun.com ([129.146.11.31])
 by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KJA002634FGD1D0@nwk-avmta-2.sfbay.sun.com> for
 psarc-ext@Sun.COM (ORCPT psarc-ext@Sun.COM); Thu,
 07 May 2009 08:02:04 -0700 (PDT)
Received: from printing.eng.sun.com (printing.SFBay.Sun.COM [129.146.178.26])
	by dm-sfbay-02.sfbay.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2)
 with ESMTP id n47F22sl040024; Thu, 07 May 2009 08:02:02 -0700 (PDT)
Received: from [10.7.251.237] (punchin-jacobs.SFBay.Sun.COM [10.7.251.237])
	by printing.eng.sun.com (8.14.3+Sun/8.14.3) with ESMTP id n47F4mRk022836; Thu,
 07 May 2009 08:04:48 -0700 (PDT)
Date: Thu, 07 May 2009 10:02:01 -0500
From: Norm Jacobs <Norm.Jacobs@Sun.COM>
Subject: Re: Amendments to pconsole fast-track [PSARC/2009/275 FastTrack
 timeout 05/08/2009]
In-reply-to: <200905070813.n478Dw9m046180@dm-holland-02.uk.sun.com>
To: Casper.Dik@Sun.COM
Cc: Gary Winiger <gww@sac.sfbay.sun.com>, Leland.Chen@Sun.COM,
        Nicolas.Williams@Sun.COM, psarc-ext@Sun.COM,
        timh@spidey.Central.Sun.COM
Message-id: <4A02F7E9.2020807@Sun.COM>
MIME-version: 1.0
Content-type: text/plain; charset=ISO-8859-1; format=flowed
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200905062254.n46MsHqH003807@sac.sfbay.sun.com>
 <200905070813.n478Dw9m046180@dm-holland-02.uk.sun.com>
User-Agent: Thunderbird 2.0.0.21 (X11/20090323)
Status: RO
Content-Length: 1574

Casper.Dik@sun.com wrote:
>>> Norm,
>>>       
>>> 	4) Conclusion on privs/uids.
>>> 	   Nit: the exec_attr entry s/suser/solaris/
>>> 	   Is it really the euid that matters, or is it that euid=0 gives
>>> 	   privs=all?  I don't know how to answer the tiocsti question.
>>> 	   I'm not sure that's this case (though it would be nice if
>>> 	   the policy was revisited and this case dependent on that revisit),
>>> 	   but I'm not suggesting that be the a case requirement.
>>>
>>> 	Perhaps an offline email if I've not been clear.
>>>       
>> 	Talking to Nico off line about something else, he said he'd looked
>> 	some at tiocsti and felt it was a bug that you couldn't control
>> 	the tty/pty that you own.  I don't find TIOCSTI adequately
>> 	documented by Sun.  But google did it.  
>>     
>
> The reason behind this is the owner doesn't really tell everything.
>
> If a user has run su in one terminal, any other terminal can be used to
> control "su"; this includes any form of malware.  I wdon't want to change 
> it because it still allows privilege escalation.
>   
Not really.  If the user has escalated privilege in one of their shells 
and then they come along and use pconsole to attach to the tty that 
shell is running in, they can only hijack a tty that they already own.  
Since they already own it and they already have access to the shell with 
the escalated privilege, I don't really see that as an issue.  Perhaps 
you could give me the clue that helps me understand why they are getting 
to do something that they couldn't already do.

    -Norm


From Norm.Jacobs@Sun.COM Thu May  7 08:04:02 2009
Received: from sunmail3mpk.sfbay.sun.com (sunmail3mpk.SFBay.Sun.COM [129.146.11.52])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n47F429N010211
	for <psarc-ext@sac.sfbay.sun.com>; Thu, 7 May 2009 08:04:02 -0700 (PDT)
Received: from nwk-avmta-1.SFBay.Sun.COM (nwk-avmta-1.SFBay.Sun.COM [129.146.11.74])
	by sunmail3mpk.sfbay.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id n47F3vAP025343
	for <@sunmail2sca.sfbay.sun.com:PSARC-ext@Sun.COM>; Thu, 7 May 2009 08:04:01 -0700 (PDT)
Received: from pmxchannel-daemon.nwk-avmta-1.sfbay.Sun.COM by
 nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KJA00A3B4IP7100@nwk-avmta-1.sfbay.Sun.COM> for PSARC-ext@Sun.COM
 (ORCPT PSARC-ext@Sun.COM); Thu, 07 May 2009 08:04:01 -0700 (PDT)
Received: from dm-sfbay-01.sfbay.sun.com ([129.145.155.118])
 by nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KJA005UF4IOV750@nwk-avmta-1.sfbay.Sun.COM> for
 PSARC-ext@Sun.COM (ORCPT PSARC-ext@Sun.COM); Thu,
 07 May 2009 08:04:00 -0700 (PDT)
Received: from printing.eng.sun.com (printing.SFBay.Sun.COM [129.146.178.26])
	by dm-sfbay-01.sfbay.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2)
 with ESMTP id n47F3wek017869; Thu, 07 May 2009 08:03:58 -0700 (PDT)
Received: from [10.7.251.237] (punchin-jacobs.SFBay.Sun.COM [10.7.251.237])
	by printing.eng.sun.com (8.14.3+Sun/8.14.3) with ESMTP id n47F6iKe022841; Thu,
 07 May 2009 08:06:44 -0700 (PDT)
Date: Thu, 07 May 2009 10:03:56 -0500
From: Norm Jacobs <Norm.Jacobs@Sun.COM>
Subject: Re: Amendments to pconsole fast-track [PSARC/2009/275 FastTrack
 timeout 05/08/2009]
In-reply-to: <200905070824.n478OgsV049778@dm-holland-02.uk.sun.com>
To: Casper.Dik@Sun.COM
Cc: Gary Winiger <gww@eng.sun.com>, gww@sac.sfbay.sun.com, Leland.Chen@Sun.COM,
        Nicolas.Williams@Sun.COM, PSARC-ext@Sun.COM,
        timh@spidey.central.sun.com
Message-id: <4A02F85C.8000206@Sun.COM>
MIME-version: 1.0
Content-type: text/plain; charset=ISO-8859-1; format=flowed
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200905062324.n46NOjVY021248@marduk.eng.sun.com>
 <4A026C9B.7070007@Sun.COM>
 <200905070824.n478OgsV049778@dm-holland-02.uk.sun.com>
User-Agent: Thunderbird 2.0.0.21 (X11/20090323)
Status: RO
Content-Length: 1141

Casper.Dik@Sun.COM wrote:
>> Gary Winiger wrote:
>>     
>>>> 	IMO, this case should be withdrawn and the bug should be fixed.
>>>> 	If I'm wrong about the bug, then the case should be reintroduced
>>>> 	with rational as to why there isn't a bug and what the policy really
>>>> 	should be for TIOCSTI.
>>>>
>>>> 	I'll give the project team a while to answer this before considering
>>>> 	further steps, such as withdrawn, waiting need spec or even derail
>>>> 	for a meeting.
>>>>     
>>>>         
>>> 	Filed:
>>> 	P3, 6838249 The TIOCSTI policy appears to require too many privileges
>>>   
>>>       
>> If we consider TIOCSTI failure with EPERM on devices you own a bug, then 
>> this case can probably be withdrawn.
>>     
>
>
> Unfortunately, I don't agree.
>
> So what do other OSes do?
>   
> I think it's very dangerous to allow TIOCSTI, even if you own the terminal.
>
> (Before, firefox can only run as me, if you change the semantics for 
> TIOCSTI, then firefox can run as root if I've su'ed in some window)
>   
Only if I invoke it in the su'ed window, which I can already do with or 
without pconsole/TIOCSTI.

       -Norm

From casper@holland.sun.com Thu May  7 08:29:36 2009
Received: from sunmail5.uk.sun.com (sunmail5.UK.Sun.COM [129.156.85.165])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n47FTaR9009302
	for <psarc-ext@sac.sfbay.sun.com>; Thu, 7 May 2009 08:29:36 -0700 (PDT)
Received: from nwk-avmta-1.SFBay.Sun.COM (nwk-avmta-1.SFBay.Sun.COM [129.146.11.74])
	by sunmail5.uk.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2) with ESMTP id n47FTYGW027117
	for <@sunmail2sca.sfbay.sun.com:psarc-ext@Sun.COM>; Thu, 7 May 2009 16:29:35 +0100 (BST)
Received: from pmxchannel-daemon.nwk-avmta-1.sfbay.Sun.COM by
 nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KJA00D015PB1500@nwk-avmta-1.sfbay.Sun.COM> for psarc-ext@Sun.COM
 (ORCPT psarc-ext@Sun.COM); Thu, 07 May 2009 08:29:35 -0700 (PDT)
Received: from dm-holland-02.uk.sun.com ([129.156.101.225])
 by nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KJA005GT5PAVAB0@nwk-avmta-1.sfbay.Sun.COM> for
 psarc-ext@Sun.COM (ORCPT psarc-ext@Sun.COM); Thu,
 07 May 2009 08:29:35 -0700 (PDT)
Received: from holland (room101.Holland.Sun.COM [10.16.117.40])
	by dm-holland-02.uk.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2)
 with ESMTP id n47FTMSP061860; Thu, 07 May 2009 16:29:22 +0100 (BST)
Date: Thu, 07 May 2009 17:29:22 +0200
From: Casper.Dik@sun.com
Subject: Re: Amendments to pconsole fast-track [PSARC/2009/275 FastTrack
 timeout 05/08/2009]
In-reply-to: <4A02F85C.8000206@Sun.COM>
Sender: casper@holland.sun.com
To: Norm Jacobs <Norm.Jacobs@sun.com>
Cc: Gary Winiger <gww@eng.sun.com>, gww@sac.sfbay.sun.com, Leland.Chen@sun.com,
        Nicolas.Williams@sun.com, psarc-ext@sun.com,
        timh@spidey.central.sun.com
Message-id: <200905071529.n47FTMSP061860@dm-holland-02.uk.sun.com>
MIME-version: 1.0
Content-type: text/plain; charset=us-ascii
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200905062324.n46NOjVY021248@marduk.eng.sun.com>
 <4A026C9B.7070007@Sun.COM>
 <200905070824.n478OgsV049778@dm-holland-02.uk.sun.com>
 <4A02F85C.8000206@Sun.COM>
Status: RO
Content-Length: 320



>Only if I invoke it in the su'ed window, which I can already do with or 
>without pconsole/TIOCSTI.


Yes, but if I allow TIOCSTI in any terminal you own, then that's a problem.

If I understand, pconsole opens many ttys and "paste" commands there.  If 
TIOCSTI allows that, then there's a security problem.

Casper


From casper@holland.sun.com Thu May  7 08:31:00 2009
Received: from newsunmail1brm.central.sun.com (newsunmail1brm.Central.Sun.COM [129.147.62.245])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n47FUxZs009318
	for <psarc-ext@sac.sfbay.sun.com>; Thu, 7 May 2009 08:30:59 -0700 (PDT)
Received: from nwk-avmta-1.SFBay.Sun.COM (nwk-avmta-1.SFBay.Sun.COM [129.146.11.74])
	by newsunmail1brm.central.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id n47FUwed032230
	for <@sunmail2sca.sfbay.sun.com:psarc-ext@Sun.COM>; Thu, 7 May 2009 09:30:59 -0600 (MDT)
Received: from pmxchannel-daemon.nwk-avmta-1.sfbay.Sun.COM by
 nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KJA00D255RM7V00@nwk-avmta-1.sfbay.Sun.COM> for psarc-ext@Sun.COM
 (ORCPT psarc-ext@Sun.COM); Thu, 07 May 2009 08:30:58 -0700 (PDT)
Received: from dm-holland-02.uk.sun.com ([129.156.101.225])
 by nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KJA005T25RLV7B0@nwk-avmta-1.sfbay.Sun.COM> for
 psarc-ext@Sun.COM (ORCPT psarc-ext@Sun.COM); Thu,
 07 May 2009 08:30:58 -0700 (PDT)
Received: from holland (room101.Holland.Sun.COM [10.16.117.40])
	by dm-holland-02.uk.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2)
 with ESMTP id n47FUotk062412; Thu, 07 May 2009 16:30:50 +0100 (BST)
Date: Thu, 07 May 2009 17:30:50 +0200
From: Casper.Dik@sun.com
Subject: Re: Amendments to pconsole fast-track [PSARC/2009/275 FastTrack
 timeout 05/08/2009]
In-reply-to: <4A02F7E9.2020807@Sun.COM>
Sender: casper@holland.sun.com
To: Norm Jacobs <Norm.Jacobs@sun.com>
Cc: Gary Winiger <gww@sac.sfbay.sun.com>, Leland.Chen@sun.com,
        Nicolas.Williams@sun.com, PSARC-ext@sun.com,
        timh@spidey.Central.Sun.COM
Message-id: <200905071530.n47FUotk062412@dm-holland-02.uk.sun.com>
MIME-version: 1.0
Content-type: text/plain; charset=us-ascii
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200905062254.n46MsHqH003807@sac.sfbay.sun.com>
 <200905070813.n478Dw9m046180@dm-holland-02.uk.sun.com>
 <4A02F7E9.2020807@Sun.COM>
Status: RO
Content-Length: 889



>> If a user has run su in one terminal, any other terminal can be used to
>> control "su"; this includes any form of malware.  I wdon't want to change 
>> it because it still allows privilege escalation.
>>   
>Not really.  If the user has escalated privilege in one of their shells 
>and then they come along and use pconsole to attach to the tty that 
>shell is running in, they can only hijack a tty that they already own.  
>Since they already own it and they already have access to the shell with 
>the escalated privilege, I don't really see that as an issue.  Perhaps 
>you could give me the clue that helps me understand why they are getting 
>to do something that they couldn't already do.


But firefox can do that also (and acroread, and flash, etc).

That's what the problem is.  Not the action done by the user but what 
other software can do when running as you.

Casper


From gww@sac.sfbay.sun.com Thu May  7 10:14:27 2009
Received: from newsunmail1brm.central.sun.com (newsunmail1brm.Central.Sun.COM [129.147.62.245])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n47HER6C012235
	for <psarc-ext@sac.sfbay.sun.com>; Thu, 7 May 2009 10:14:27 -0700 (PDT)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.145.155.6])
	by newsunmail1brm.central.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id n47HEJ8e040924
	for <@sunmail2sca.sfbay.sun.com:psarc-ext@sun.com>; Thu, 7 May 2009 11:14:27 -0600 (MDT)
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KJA00J03AK26L00@nwk-avmta-2.sfbay.sun.com> for psarc-ext@sun.com
 (ORCPT psarc-ext@sun.com); Thu, 07 May 2009 10:14:26 -0700 (PDT)
Received: from dm-sfbay-01.sfbay.sun.com ([129.145.155.118])
 by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KJA00D19AK2EM80@nwk-avmta-2.sfbay.sun.com> for
 psarc-ext@sun.com (ORCPT psarc-ext@sun.com); Thu,
 07 May 2009 10:14:26 -0700 (PDT)
Received: from sac.sfbay.sun.com (sac.SFBay.Sun.COM [129.146.226.132])
	by dm-sfbay-01.sfbay.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2)
 with ESMTP id n47HELhe053170; Thu, 07 May 2009 10:14:21 -0700 (PDT)
Received: from sac.sfbay.sun.com (localhost [127.0.0.1])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n47HEJrT012230; Thu,
 07 May 2009 10:14:19 -0700 (PDT)
Received: (from gww@localhost)	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8/Submit)
 id n47HEIGM012229; Thu, 07 May 2009 10:14:18 -0700 (PDT)
Date: Thu, 07 May 2009 10:14:18 -0700 (PDT)
From: Gary Winiger <gww@sac.sfbay.sun.com>
Subject: Re: Amendments to pconsole fast-track [PSARC/2009/275 FastTrack
 timeout 05/08/2009]
To: Norm.Jacobs@sun.com, gww@eng.sun.com
Cc: gww@sac.sfbay.sun.com, leland.chen@sun.com, nicolas.williams@sun.com,
        psarc-ext@sun.com, timh@spidey.central.sun.com
Message-id: <200905071714.n47HEIGM012229@sac.sfbay.sun.com>
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
Status: RO
Content-Length: 2012

> From Norm.Jacobs@sun.com Wed May  6 22:07:44 2009
> Date: Thu, 07 May 2009 00:07:39 -0500
> From: Norm Jacobs <Norm.Jacobs@sun.com>
> Subject: Re: Amendments to pconsole fast-track [PSARC/2009/275 FastTrack
>  timeout 05/08/2009]
> To: Gary Winiger <gww@eng.sun.com>
> Cc: gww@sac.sfbay.sun.com, leland.chen@sun.com, nicolas.williams@sun.com,
>         psarc-ext@sun.com, timh@spidey.central.sun.com
> Content-transfer-encoding: 7BIT
> X-PMX-Version: 5.4.1.325704
> User-Agent: Thunderbird 2.0.0.21 (X11/20090323)
> 
> Gary Winiger wrote:
> >> 	IMO, this case should be withdrawn and the bug should be fixed.
> >> 	If I'm wrong about the bug, then the case should be reintroduced
> >> 	with rational as to why there isn't a bug and what the policy really
> >> 	should be for TIOCSTI.
> >>
> >> 	I'll give the project team a while to answer this before considering
> >> 	further steps, such as withdrawn, waiting need spec or even derail
> >> 	for a meeting.
> >>     
> >
> > 	Filed:
> > 	P3, 6838249 The TIOCSTI policy appears to require too many privileges
> >   
> If we consider TIOCSTI failure with EPERM on devices you own a bug, then 
> this case can probably be withdrawn.

	Hummm,  EPERM not EACCES.  Assuming I'm reading things correctly,
	from the code pre-privileges, you'd get EPERM if you weren't root
	and you didn't have the file open for read.  That's changed to
	if you don't have all privileges and you don't have the file open
	for read.  So perhaps there's a pconsole change needed.
	On the other hand, again assuming I'm reading things correctly,
	from the code pre-privileges, you'd get EACCES if you were not
	root and the stream/tty was not in the same controlling session as
	the thread issuing the TIOCSTI.  That's changed to, if you don't
	have all privileges and the issueing thread isn't in the same
	controlling session as the stream/tty.

	Is the intended use of pconsole to feed input to streams/ttys not in
	same controlling session as the thread issuing the TIOCSTI?

Gary..

From Joerg.Schilling9ab33xy531fokus.fraunhofer.de@bounce.antispameurope.com Thu May  7 12:17:59 2009
Received: from sunmail4.singapore.sun.com (sunmail4.Singapore.Sun.COM [129.158.71.19])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n47JHwNo012830
	for <psarc-ext@sac.sfbay.sun.com>; Thu, 7 May 2009 12:17:59 -0700 (PDT)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.145.155.6])
	by sunmail4.singapore.sun.com (8.13.4+Sun/8.13.3/ENSMAIL,v2.2) with ESMTP id n47JHlZA026846
	for <@sunmail2sca.sfbay.sun.com:psarc-ext@sun.com>; Fri, 8 May 2009 03:17:58 +0800 (SGT)
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KJA0020XG9VM000@nwk-avmta-2.sfbay.sun.com> for psarc-ext@sun.com
 (ORCPT psarc-ext@sun.com); Thu, 07 May 2009 12:17:55 -0700 (PDT)
Received: from brmea-mail-1.sun.com ([192.18.98.31])
 by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KJA000RUG9UL320@nwk-avmta-2.sfbay.sun.com> for
 psarc-ext@sun.com (ORCPT psarc-ext@sun.com); Thu,
 07 May 2009 12:17:54 -0700 (PDT)
Received: from relay42i.sun.com ([192.5.209.72])
	by brmea-mail-1.sun.com (8.13.6+Sun/8.12.9) with ESMTP id n47JAjvg007407	for
 <psarc-ext@sun.com>; Thu, 07 May 2009 19:17:54 +0000 (GMT)
Received: from mms48es.mms.us.syntegra.com ([160.41.221.230] [160.41.221.230])
 by relay42i.sun.com with ESMTP id BT-MMP-2951384 for psarc-ext@sun.com; Thu,
 07 May 2009 19:17:53 +0000 (Z)
Received: from relay42i.sun.com (relay42i.sun.com [192.5.209.72])
 by mms48es.mms.us.syntegra.com with ESMTP id BT-MMP-10283184 for
 psarc-ext@sun.com; Thu, 07 May 2009 19:17:52 +0000 (Z)
Received: from relay04-haj2.antispameurope.com ([83.246.65.54] [83.246.65.54])
 by relay4i.sun.com with ESMTP id BT-MMP-2173409 for psarc-ext@sun.com; Thu,
 07 May 2009 19:15:20 +0000 (Z)
Received: by relay04-haj2.antispameurope.com (ASE-Secure-MTA, from userid 1000)
	id F3F6B5EC14A; Thu, 07 May 2009 21:15:01 +0200 (CEST)
Received: from pluto.fokus.fraunhofer.de
 (pluto.fokus.fraunhofer.de [195.37.77.164])
	(using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits))
	(No client certificate requested)	by relay04-haj2.antispameurope.com
 (ASE-Secure-MTA) with ESMTP id 79AB65EC147; Thu,
 07 May 2009 21:15:01 +0200 (CEST)
Received: from EXCHSRV.fokus.fraunhofer.de (bohr [10.147.9.231])
	by pluto.fokus.fraunhofer.de (8.13.7/8.13.7) with SMTP id n47JF1fj003060; Thu,
 07 May 2009 21:15:01 +0200 (MEST)
Received: from rigel ([10.147.65.195]) by EXCHSRV.fokus.fraunhofer.de with
 Microsoft SMTPSVC(6.0.3790.3959); Thu, 07 May 2009 21:15:01 +0200
Date: Thu, 07 May 2009 21:15:01 +0200
From: Joerg.Schilling@fokus.fraunhofer.de (Joerg Schilling)
Subject: Re: Amendments to pconsole fast-track [PSARC/2009/275 FastTrack
 timeout 05/08/2009]
In-reply-to: <200905071714.n47HEIGM012229@sac.sfbay.sun.com>
Sender: Joerg.Schilling9ab33xy531fokus.fraunhofer.de@bounce.antispameurope.com
To: Norm.Jacobs@sun.com, gww@sac.sfbay.sun.com, gww@eng.sun.com
Cc: timh@spidey.central.sun.com, psarc-ext@sun.com, leland.chen@sun.com,
        gww@sac.sfbay.sun.com
Message-id: <4a033335.FlnVz/e9W/+xJz0T%Joerg.Schilling@fokus.fraunhofer.de>
MIME-version: 1.0
Content-type: text/plain; charset=ISO-8859-1
Content-transfer-encoding: 8BIT
X-PMX-Version: 5.4.1.325704
X-Brightmail-Tracker: AAAAAA==
X-Antispam: No, score=0.0/5.0, scanned in 0.399sec at (localhost [127.0.0.1])
	by smf-spamd v1.3.1 - http://smfs.sf.net/
References: <200905071714.n47HEIGM012229@sac.sfbay.sun.com>
User-Agent: nail 11.22 3/20/05
X-OriginalArrivalTime: 07 May 2009 19:15:01.0231 (UTC)
 FILETIME=[1E7467F0:01C9CF48]
Status: RO
Content-Length: 803

Gary Winiger <gww@sac.sfbay.sun.com> wrote:

> > > 	P3, 6838249 The TIOCSTI policy appears to require too many privileges
> > >   
> > If we consider TIOCSTI failure with EPERM on devices you own a bug, then 
> > this case can probably be withdrawn.
>
> 	Hummm,  EPERM not EACCES.  Assuming I'm reading things correctly,
> 	from the code pre-privileges, you'd get EPERM if you weren't root
> 	and you didn't have the file open for read.  That's changed to

For this privilege condition, EPOERM is correct.

Jörg

-- 
 EMail:joerg@schily.isdn.cs.tu-berlin.de (home) Jörg Schilling D-13353 Berlin
       js@cs.tu-berlin.de                (uni)  
       joerg.schilling@fokus.fraunhofer.de (work) Blog: http://schily.blogspot.com/
 URL:  http://cdrecord.berlios.de/private/ ftp://ftp.berlios.de/pub/schily

From Nicolas.Williams@Sun.COM Thu May  7 12:42:57 2009
Received: from sunmail5.uk.sun.com (sunmail5.UK.Sun.COM [129.156.85.165])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n47JguxR013351
	for <psarc-ext@sac.sfbay.sun.com>; Thu, 7 May 2009 12:42:56 -0700 (PDT)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by sunmail5.uk.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2) with ESMTP id n47JggUk022359;
	Thu, 7 May 2009 20:42:52 +0100 (BST)
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KJA00B13HFE4400@brm-avmta-1.central.sun.com>; Thu,
 07 May 2009 13:42:51 -0600 (MDT)
Received: from binky.Central.Sun.COM ([129.153.128.104])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KJA00I8EHFDE9E0@brm-avmta-1.central.sun.com>; Thu,
 07 May 2009 13:42:49 -0600 (MDT)
Received: from binky.Central.Sun.COM (localhost [127.0.0.1])
	by binky.Central.Sun.COM (8.14.3+Sun/8.14.3) with ESMTP id n47JeZ0n026875;
 Thu, 07 May 2009 14:40:35 -0500 (CDT)
Received: (from nw141292@localhost)
	by binky.Central.Sun.COM (8.14.3+Sun/8.14.3/Submit) id n47JeZpL026874; Thu,
 07 May 2009 14:40:35 -0500 (CDT)
Date: Thu, 07 May 2009 14:40:35 -0500
From: Nicolas Williams <Nicolas.Williams@Sun.COM>
Subject: Re: Amendments to pconsole fast-track [PSARC/2009/275 FastTrack
 timeout 05/08/2009]
In-reply-to: <200905071530.n47FUotk062412@dm-holland-02.uk.sun.com>
To: Casper.Dik@Sun.COM
Cc: Norm Jacobs <Norm.Jacobs@Sun.COM>, Gary Winiger <gww@sac.sfbay.sun.com>,
        Leland.Chen@Sun.COM, PSARC-ext@Sun.COM, timh@spidey.Central.Sun.COM
Message-id: <20090507194035.GW1500@Sun.COM>
MIME-version: 1.0
Content-type: text/plain; charset=us-ascii
Content-transfer-encoding: 7BIT
Content-disposition: inline
X-PMX-Version: 5.4.1.325704
References: <200905062254.n46MsHqH003807@sac.sfbay.sun.com>
 <200905070813.n478Dw9m046180@dm-holland-02.uk.sun.com>
 <4A02F7E9.2020807@Sun.COM>
 <200905071530.n47FUotk062412@dm-holland-02.uk.sun.com>
X-Authentication-warning: binky.Central.Sun.COM: nw141292 set sender to
 Nicolas.Williams@sun.com using -f
User-Agent: Mutt/1.5.7i
Status: RO
Content-Length: 1198

On Thu, May 07, 2009 at 05:30:50PM +0200, Casper.Dik@Sun.COM wrote:
> 
> 
> >> If a user has run su in one terminal, any other terminal can be used to
> >> control "su"; this includes any form of malware.  I wdon't want to change 
> >> it because it still allows privilege escalation.
> >>   
> >Not really.  If the user has escalated privilege in one of their shells 
> >and then they come along and use pconsole to attach to the tty that 
> >shell is running in, they can only hijack a tty that they already own.  
> >Since they already own it and they already have access to the shell with 
> >the escalated privilege, I don't really see that as an issue.  Perhaps 
> >you could give me the clue that helps me understand why they are getting 
> >to do something that they couldn't already do.
> 
> 
> But firefox can do that also (and acroread, and flash, etc).
> 
> That's what the problem is.  Not the action done by the user but what 
> other software can do when running as you.

They can also just debug your shells.

What should hapen is that this ioctl should require a basic privilege
that firefox and friends run without.  (Also, we need to use labeling
more for sandboxing.)

Nico
-- 

From tim.haley@sun.com Tue May 26 06:36:48 2009
Received: from sunmail4.singapore.sun.com (sunmail4.Singapore.Sun.COM [129.158.71.19])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n4QDalx7012423
	for <psarc-ext@sac.sfbay.sun.com>; Tue, 26 May 2009 06:36:47 -0700 (PDT)
Received: from nwk-avmta-1.SFBay.Sun.COM (nwk-avmta-1.SFBay.Sun.COM [129.146.11.74])
	by sunmail4.singapore.sun.com (8.13.4+Sun/8.13.3/ENSMAIL,v2.2) with ESMTP id n4QDaglV024728
	for <@sunmail2sca.sfbay.sun.com:PSARC-ext@sun.com>; Tue, 26 May 2009 21:36:46 +0800 (SGT)
Received: from pmxchannel-daemon.nwk-avmta-1.sfbay.Sun.COM by
 nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KK900E9N7594000@nwk-avmta-1.sfbay.Sun.COM> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Tue, 26 May 2009 06:36:45 -0700 (PDT)
Received: from brmea-mail-1.sun.com ([192.18.98.31])
 by nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KK900EFP7566P00@nwk-avmta-1.sfbay.Sun.COM> for
 PSARC-ext@sun.com (ORCPT PSARC-ext@sun.com); Tue,
 26 May 2009 06:36:42 -0700 (PDT)
Received: from fe-amer-10.sun.com ([192.18.109.80])
	by brmea-mail-1.sun.com (8.13.6+Sun/8.12.9) with ESMTP id n4QDafw8021068	for
 <PSARC-ext@sun.com>; Tue, 26 May 2009 13:36:41 +0000 (GMT)
Received: from conversion-daemon.mail-amer.sun.com by mail-amer.sun.com
 (Sun Java(tm) System Messaging Server 7u2-7.02 64bit (built Apr 16 2009))
 id <0KK900J006RTLV00@mail-amer.sun.com> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Tue, 26 May 2009 07:36:41 -0600 (MDT)
Received: from Giles.local ([unknown] [76.120.1.50])
 by mail-amer.sun.com (Sun Java(tm) System Messaging Server 7u2-7.02 64bit
 (built Apr 16 2009)) with ESMTPSA id <0KK9000US74RBN90@mail-amer.sun.com>; Tue,
 26 May 2009 07:36:32 -0600 (MDT)
Date: Tue, 26 May 2009 07:36:26 -0600
From: Tim Haley <tim.haley@sun.com>
Subject: Re: Amendments to pconsole fast-track [PSARC/2009/275 FastTrack
 timeout 05/27/2009]
Sender: Timothy.Haley@sun.com
To: PSARC-ext@sun.com
Cc: Leland.Chen@sun.com, Norm.Jacobs@sun.com
Message-id: <4A1BF05A.4030403@sun.com>
MIME-version: 1.0
Content-type: text/plain; CHARSET=US-ASCII; format=flowed
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
User-Agent: Thunderbird 2.0.0.21 (Macintosh/20090302)
Status: RO
Content-Length: 3119

My attempts to get some consensus off-line seem to have floundered a 
bit, so I will bring this back to the alias where they can flounder 
here. :-)

Norm made the following comments in a recent mail that I'll quote here.

"
Ok, for TIOCSTI, there are effectively three choices here.

   1. maintain the current behaviour, which appears to require
      PRIV_ALL
   2. modify the behaviour to allow the device owner to use TIOCSTI,
      when the sessions match.
   3. modify the behaviour to allow the device owner to use TIOCSTI
      regardless of session.

Casper appears to believe that 1 is the only sane answer.  Nico appears 
to believe that 2 is a reasonable answer.  I suspect that 3 is off the 
table.

It appears to me (and the cluster folks can correct me), that pconsole 
intends to be able to use devices outside of it's controlling session. 
So, regardless of whether or not 1 or 2 is the ultimate solution to the 
TIOCSTI quandary, I believe that pconsole will end up requiring a rights 
profile.  I believe that this profile should be assigned by 
administrator action and that it should be separated from other rights 
profiles (not part of System Administrator).  The following probably 
covers it.

   /etc/security/prof_attr:
   Parallel Console Access:::Connect to remote consoles with 
pconsole:help=pconsole.html

   /etc/security/exec_attr:
   Parallel Console Access:solaris:cmd:::/usr/sbin/pconsole-bin:privs=all
or
   Parallel Console 
Access:solaris:cmd:::/usr/sbin/pconsole-bin:privs=proc_session
"

So, distilling that into a proposal:

----8<---------------

Amendments to PSARC/2008/606 pconsole - parallel console

Amendment 1:

The pconsole-bin binary requires elevated privilege to be useful.  We
request to move the binary from the originally stated /usr/bin to
/usr/sbin, in line with where other binaries requiring privilege
usually exist.

Amendment 2:

A new execution profile and attribute will be defined.  This profile
will *NOT* be assigned to anyone by default.  The pconsole manual page
will be modified to say:

  -    NOTE:
  -        This program must be run as root.   To  allow  non-root
  -        users  to  use  this  program, the system administrator
  -        must make the pconsole-bin binary setuid root by  issu-
  -        ing the following command:
  -
  -        # chmod 4555 /usr/bin/pconsole-bin
  -
  -        This is NOT recommended however, as it could result  in
  -        making the system less secure.
  -
  +    NOTE:
  +        This program must be either run as root or by a user granted
  +        the "Parallel Console Access" rights profile:
  +
  +        # usermod -P "Parallel Console Access" login-name
  +

RBAC changes:

/etc/security/prof_attr:
Parallel Console Access:::Connect to remote consoles with 
pconsole:help=pconsole.html

/etc/security/exec_attr:
Parallel Console Access:solaris:cmd:::/usr/sbin/pconsole-bin:privs=all

------>8--------

If 6838249 is truly a bug, then the exec profile could perhaps be reduced to

Parallel Console 
Access:solaris:cmd:::/usr/sbin/pconsole-bin:privs=proc_session

upon fixing it.

-tim



From casper@holland.sun.com Tue May 26 06:49:33 2009
Received: from sunmail4.singapore.sun.com (sunmail4.Singapore.Sun.COM [129.158.71.19])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n4QDnWLD012460
	for <psarc-ext@sac.sfbay.sun.com>; Tue, 26 May 2009 06:49:32 -0700 (PDT)
Received: from nwk-avmta-1.SFBay.Sun.COM (nwk-avmta-1.SFBay.Sun.COM [129.146.11.74])
	by sunmail4.singapore.sun.com (8.13.4+Sun/8.13.3/ENSMAIL,v2.2) with ESMTP id n4QDnODP001508;
	Tue, 26 May 2009 21:49:31 +0800 (SGT)
Received: from pmxchannel-daemon.nwk-avmta-1.sfbay.Sun.COM by
 nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KK900G0J7QJQY00@nwk-avmta-1.sfbay.Sun.COM>; Tue,
 26 May 2009 06:49:31 -0700 (PDT)
Received: from dm-holland-02.uk.sun.com ([129.156.101.225])
 by nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KK900CY47QGOY70@nwk-avmta-1.sfbay.Sun.COM>; Tue,
 26 May 2009 06:49:29 -0700 (PDT)
Received: from holland (room101.Holland.Sun.COM [10.16.117.40])
	by dm-holland-02.uk.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2)
 with ESMTP id n4QDnP2m032980; Tue, 26 May 2009 14:49:25 +0100 (BST)
Date: Tue, 26 May 2009 15:49:25 +0200
From: Casper.Dik@sun.com
Subject: Re: Amendments to pconsole fast-track [PSARC/2009/275 FastTrack
 timeout 05/27/2009]
In-reply-to: <4A1BF05A.4030403@sun.com>
Sender: casper@holland.sun.com
To: Tim Haley <tim.haley@sun.com>
Cc: PSARC-ext@sun.com, Leland.Chen@sun.com, Norm.Jacobs@sun.com
Message-id: <200905261349.n4QDnP2m032980@dm-holland-02.uk.sun.com>
MIME-version: 1.0
Content-type: text/plain; charset=us-ascii
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <4A1BF05A.4030403@sun.com>
Status: RO
Content-Length: 791


>Ok, for TIOCSTI, there are effectively three choices here.
>
>   1. maintain the current behaviour, which appears to require
>      PRIV_ALL
>   2. modify the behaviour to allow the device owner to use TIOCSTI,
>      when the sessions match.
>   3. modify the behaviour to allow the device owner to use TIOCSTI
>      regardless of session.
>
>Casper appears to believe that 1 is the only sane answer.  Nico appears 
>to believe that 2 is a reasonable answer.  I suspect that 3 is off the 
>table.

The current implementation is:
	if the ioctl flag is FREAD (read-only), then require all
else
	if (the session is the same as the current session)
		then ok
	else
		require all


So I'd say that the current behaviour is choice #2.


But I think that's not what you actually want.

Casper


From gww@eng.sun.com Tue May 26 11:11:17 2009
Received: from sunmail5.uk.sun.com (sunmail5.UK.Sun.COM [129.156.85.165])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n4QIBFqJ019072
	for <psarc-ext@sac.sfbay.sun.com>; Tue, 26 May 2009 11:11:15 -0700 (PDT)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by sunmail5.uk.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2) with ESMTP id n4QIBDOg013639;
	Tue, 26 May 2009 19:11:14 +0100 (BST)
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KK900C09JUN7W00@brm-avmta-1.central.sun.com>; Tue,
 26 May 2009 12:11:11 -0600 (MDT)
Received: from dm-eng-02.sfbay.sun.com ([129.146.11.32])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KK900590JUN82B0@brm-avmta-1.central.sun.com>; Tue,
 26 May 2009 12:11:11 -0600 (MDT)
Received: from marduk.eng.sun.com (marduk.SFBay.Sun.COM [129.146.108.224])
	by dm-eng-02.sfbay.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2)
 with ESMTP id n4QIBAdG010681; Tue, 26 May 2009 11:11:10 -0700 (PDT)
Received: from marduk.eng.sun.com (localhost [127.0.0.1])
	by marduk.eng.sun.com (8.13.6+Sun/8.12.11) with ESMTP id n4QI9l25010808; Tue,
 26 May 2009 11:09:47 -0700 (PDT)
Received: (from gww@localhost)
	by marduk.eng.sun.com (8.13.6+Sun/8.12.11/Submit) id n4QI9l5a010807; Tue,
 26 May 2009 11:09:47 -0700 (PDT)
Date: Tue, 26 May 2009 11:09:47 -0700 (PDT)
From: Gary Winiger <gww@eng.sun.com>
Subject: Re: Amendments to pconsole fast-track [PSARC/2009/275 FastTrack
 timeout 05/27/2009]
To: tim.haley@sun.com, casper.dik@sun.com
Cc: PSARC-ext@sun.com, Leland.Chen@sun.com, Norm.Jacobs@sun.com
Message-id: <200905261809.n4QI9l5a010807@marduk.eng.sun.com>
Content-transfer-encoding: 7BIT
X-Sun-Charset: US-ASCII
X-PMX-Version: 5.4.1.325704
Status: RO
Content-Length: 1233

> >Ok, for TIOCSTI, there are effectively three choices here.
> >
> >   1. maintain the current behaviour, which appears to require
> >      PRIV_ALL
> >   2. modify the behaviour to allow the device owner to use TIOCSTI,
> >      when the sessions match.
> >   3. modify the behaviour to allow the device owner to use TIOCSTI
> >      regardless of session.
> >
> >Casper appears to believe that 1 is the only sane answer.  Nico appears 
> >to believe that 2 is a reasonable answer.  I suspect that 3 is off the 
> >table.
> 
> The current implementation is:
> 	if the ioctl flag is FREAD (read-only), then require all
		or EPERM
> else
> 	if (the session is the same as the current session)
> 		then ok
> 	else
> 		require all

		or EACCES

> So I'd say that the current behaviour is choice #2.
>
> But I think that's not what you actually want.

	If the return is EPERM, then pconsole has a bug that should just
	be fixed.  If it is EACCES, then the question is why is it going
	after a tty not in its session?  If pconsole's reason for existance
	is to violate the TIOCSTI, then either 3 or a Rights Profile is the
	way forward.

	BTW, has the question of policy on other systems that implement
	TIOCSTI been answered?

Gary..
	

From tim.haley@sun.com Tue May 26 15:17:08 2009
Received: from newsunmail1brm.central.sun.com (newsunmail1brm.Central.Sun.COM [129.147.62.245])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n4QMH8AE024993
	for <psarc-ext@sac.sfbay.sun.com>; Tue, 26 May 2009 15:17:08 -0700 (PDT)
Received: from nwk-avmta-1.SFBay.Sun.COM (nwk-avmta-1.SFBay.Sun.COM [129.146.11.74])
	by newsunmail1brm.central.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id n4QMGfAq060198
	for <@sunmail2sca.sfbay.sun.com:PSARC-ext@sun.com>; Tue, 26 May 2009 16:17:08 -0600 (MDT)
Received: from pmxchannel-daemon.nwk-avmta-1.sfbay.Sun.COM by
 nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KK900A0BV89K000@nwk-avmta-1.sfbay.Sun.COM> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Tue, 26 May 2009 15:16:58 -0700 (PDT)
Received: from brmea-mail-4.sun.com ([192.18.98.36])
 by nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KK900DQ8V85PV70@nwk-avmta-1.sfbay.Sun.COM> for
 PSARC-ext@sun.com (ORCPT PSARC-ext@sun.com); Tue,
 26 May 2009 15:16:53 -0700 (PDT)
Received: from fe-amer-09.sun.com ([192.18.109.79])
	by brmea-mail-4.sun.com (8.13.6+Sun/8.12.9) with ESMTP id n4QMGrrG014637	for
 <PSARC-ext@sun.com>; Tue, 26 May 2009 22:16:53 +0000 (GMT)
Received: from conversion-daemon.mail-amer.sun.com by mail-amer.sun.com
 (Sun Java(tm) System Messaging Server 7u2-7.02 64bit (built Apr 16 2009))
 id <0KK900500UQIV000@mail-amer.sun.com> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Tue, 26 May 2009 16:16:52 -0600 (MDT)
Received: from [172.20.25.27] ([unknown] [172.20.25.27])
 by mail-amer.sun.com (Sun Java(tm) System Messaging Server 7u2-7.02 64bit
 (built Apr 16 2009)) with ESMTPSA id <0KK900BE0V83B790@mail-amer.sun.com>; Tue,
 26 May 2009 16:16:51 -0600 (MDT)
Date: Tue, 26 May 2009 16:16:51 -0600
From: Tim Haley <tim.haley@sun.com>
Subject: Re: Amendments to pconsole fast-track [PSARC/2009/275 FastTrack
 timeout 05/27/2009]
In-reply-to: <200905261809.n4QI9l5a010807@marduk.eng.sun.com>
Sender: Timothy.Haley@sun.com
To: Gary Winiger <gww@eng.sun.com>
Cc: Casper.Dik@sun.com, PSARC-ext@sun.com, Leland.Chen@sun.com,
        Norm.Jacobs@sun.com
Message-id: <4A1C6A53.8060301@sun.com>
MIME-version: 1.0
Content-type: text/plain; CHARSET=US-ASCII; format=flowed
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200905261809.n4QI9l5a010807@marduk.eng.sun.com>
User-Agent: Thunderbird 2.0.0.21 (X11/20090505)
Status: RO
Content-Length: 1891

Gary Winiger wrote:
>>> Ok, for TIOCSTI, there are effectively three choices here.
>>>
>>>   1. maintain the current behaviour, which appears to require
>>>      PRIV_ALL
>>>   2. modify the behaviour to allow the device owner to use TIOCSTI,
>>>      when the sessions match.
>>>   3. modify the behaviour to allow the device owner to use TIOCSTI
>>>      regardless of session.
>>>
>>> Casper appears to believe that 1 is the only sane answer.  Nico appears 
>>> to believe that 2 is a reasonable answer.  I suspect that 3 is off the 
>>> table.
>> The current implementation is:
>> 	if the ioctl flag is FREAD (read-only), then require all
> 		or EPERM
>> else
>> 	if (the session is the same as the current session)
>> 		then ok
>> 	else
>> 		require all
> 
> 		or EACCES
> 
>> So I'd say that the current behaviour is choice #2.
>>
>> But I think that's not what you actually want.
> 
> 	If the return is EPERM, then pconsole has a bug that should just
> 	be fixed.  If it is EACCES, then the question is why is it going
> 	after a tty not in its session?  If pconsole's reason for existance
> 	is to violate the TIOCSTI, then either 3 or a Rights Profile is the
> 	way forward.
> 
> 	BTW, has the question of policy on other systems that implement
> 	TIOCSTI been answered?
> 
> Gary..
> 	
I googled a little.

I'm not at all a Linux expert and could be reading it wrong, but it appears to 
want the caller of the ioctl to have the CAP_SYS_ADMIN capability if they 
aren't writing to the current processes' terminal.

FreeBSD

it looks like the ioctl is #ifdef'd out

OpenBSD

          case TIOCSTI:                   /* simulate terminal input */
   964                 if (p->p_ucred->cr_uid && (flag & FREAD) == 0)
   965                         return (EPERM);
   966                 if (p->p_ucred->cr_uid && !isctty(p, tp))
   967                         return (EACCES);

-tim

From tim.haley@sun.com Tue May 26 15:41:42 2009
Received: from sunmail3mpk.sfbay.sun.com (sunmail3mpk.SFBay.Sun.COM [129.146.11.52])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n4QMfgb2025308
	for <psarc-ext@sac.sfbay.sun.com>; Tue, 26 May 2009 15:41:42 -0700 (PDT)
Received: from nwk-avmta-1.SFBay.Sun.COM (nwk-avmta-1.SFBay.Sun.COM [129.146.11.74])
	by sunmail3mpk.sfbay.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id n4QMffOx014242
	for <@sunmail2sca.sfbay.sun.com:PSARC-ext@sun.com>; Tue, 26 May 2009 15:41:42 -0700 (PDT)
Received: from pmxchannel-daemon.nwk-avmta-1.sfbay.Sun.COM by
 nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KK900E11WDH4600@nwk-avmta-1.sfbay.Sun.COM> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Tue, 26 May 2009 15:41:41 -0700 (PDT)
Received: from brmea-mail-4.sun.com ([192.18.98.36])
 by nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KK900DXXWDDPR70@nwk-avmta-1.sfbay.Sun.COM> for
 PSARC-ext@sun.com (ORCPT PSARC-ext@sun.com); Tue,
 26 May 2009 15:41:37 -0700 (PDT)
Received: from fe-amer-10.sun.com ([192.18.109.80])
	by brmea-mail-4.sun.com (8.13.6+Sun/8.12.9) with ESMTP id n4QMfblL024238	for
 <PSARC-ext@sun.com>; Tue, 26 May 2009 22:41:37 +0000 (GMT)
Received: from conversion-daemon.mail-amer.sun.com by mail-amer.sun.com
 (Sun Java(tm) System Messaging Server 7u2-7.02 64bit (built Apr 16 2009))
 id <0KK900200VNBJU00@mail-amer.sun.com> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Tue, 26 May 2009 16:41:37 -0600 (MDT)
Received: from [172.20.25.27] ([unknown] [172.20.25.27])
 by mail-amer.sun.com (Sun Java(tm) System Messaging Server 7u2-7.02 64bit
 (built Apr 16 2009)) with ESMTPSA id <0KK900AMBWCX0B30@mail-amer.sun.com>; Tue,
 26 May 2009 16:41:22 -0600 (MDT)
Date: Tue, 26 May 2009 16:41:21 -0600
From: Tim Haley <tim.haley@sun.com>
Subject: Re: Amendments to pconsole fast-track [PSARC/2009/275 FastTrack
 timeout 05/27/2009]
In-reply-to: <200905261809.n4QI9l5a010807@marduk.eng.sun.com>
Sender: Timothy.Haley@sun.com
To: Gary Winiger <gww@eng.sun.com>
Cc: Casper.Dik@sun.com, PSARC-ext@sun.com, Leland.Chen@sun.com,
        Norm.Jacobs@sun.com
Message-id: <4A1C7011.9000405@sun.com>
MIME-version: 1.0
Content-type: text/plain; CHARSET=US-ASCII; format=flowed
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200905261809.n4QI9l5a010807@marduk.eng.sun.com>
User-Agent: Thunderbird 2.0.0.21 (X11/20090505)
Status: RO
Content-Length: 2743

Gary Winiger wrote:
>>> Ok, for TIOCSTI, there are effectively three choices here.
>>>
>>>   1. maintain the current behaviour, which appears to require
>>>      PRIV_ALL
>>>   2. modify the behaviour to allow the device owner to use TIOCSTI,
>>>      when the sessions match.
>>>   3. modify the behaviour to allow the device owner to use TIOCSTI
>>>      regardless of session.
>>>
>>> Casper appears to believe that 1 is the only sane answer.  Nico appears 
>>> to believe that 2 is a reasonable answer.  I suspect that 3 is off the 
>>> table.
>> The current implementation is:
>> 	if the ioctl flag is FREAD (read-only), then require all
> 		or EPERM
>> else
>> 	if (the session is the same as the current session)
>> 		then ok
>> 	else
>> 		require all
> 
> 		or EACCES
> 
>> So I'd say that the current behaviour is choice #2.
>>
>> But I think that's not what you actually want.
> 
> 	If the return is EPERM, then pconsole has a bug that should just
> 	be fixed.  If it is EACCES, then the question is why is it going
> 	after a tty not in its session?  If pconsole's reason for existance
> 	is to violate the TIOCSTI, then either 3 or a Rights Profile is the
> 	way forward.
> 
Maybe this will help and maybe it won't.  A while back I did an experiment 
with pconsole, starting a session to two remote machines from my desktop:


spidey587] ps -o ppid,pid,sid,args -p 
12655,19040,19122,19126,20490,20492,20497,20511,20502,20516,20530,20531
  PPID   PID   SID COMMAND
     1 12655  6620 gnome-terminal
12655 19040 19040 bash
19040 19122 19040 -sh -c bash
19122 19126 19040 bash
19126 20490 19040 ksh pconsole timh@pensieve timh@x4150-bdr-02
20490 20492 19040 ksh pconsole timh@pensieve timh@x4150-bdr-02
20492 20497 19040 xterm -geometry 80x24 -fn 10x20 -title pconsole: 
timh@pensieve -name pconsole:
20492 20502 19040 xterm -geometry 80x24 -fn 10x20 -title pconsole: 
timh@x4150-bdr-02 -name pconso
20497 20511 20511 /usr/bin/ssh timh@pensieve
20502 20516 20516 /usr/bin/ssh timh@x4150-bdr-02
20492 20530 19040 xterm -geometry 80x24 -title pconsole -name pconsole -e 
/usr/bin/pconsole-bin t
20530 20531 20531 /usr/bin/pconsole-bin timh@pensieve#/dev/pts/6 
timh@x4150-bdr-02#/dev/pts/10

If I understand correctly, the SID tells us what session the process is in. 
Therefore, the xterms that display the two remote sessions have the same 
session id as the shell I started pconsole in.  The pconsole-bin and ssh' 
connected to those two remote systems do NOT have the same session id, 
however, and all three have their own session ids.

when I type in the pconsole window, whatever I type shows up in both of the 
other windows.  pconsole-bin stuffs these characters into the ssh ttys, which 
have a different session id.

-tim



From casper@holland.sun.com Wed May 27 00:00:07 2009
Received: from sunmail4.singapore.sun.com (sunmail4.Singapore.Sun.COM [129.158.71.19])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n4R705i6027567
	for <psarc-ext@sac.sfbay.sun.com>; Wed, 27 May 2009 00:00:06 -0700 (PDT)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by sunmail4.singapore.sun.com (8.13.4+Sun/8.13.3/ENSMAIL,v2.2) with ESMTP id n4R6xmBI018832;
	Wed, 27 May 2009 15:00:04 +0800 (SGT)
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KKA00101JFXR500@brm-avmta-1.central.sun.com>; Wed,
 27 May 2009 00:59:57 -0600 (MDT)
Received: from dm-holland-02.uk.sun.com ([129.156.101.225])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KKA002QXJFWD2A0@brm-avmta-1.central.sun.com>; Wed,
 27 May 2009 00:59:57 -0600 (MDT)
Received: from holland (room101.Holland.Sun.COM [10.16.117.40])
	by dm-holland-02.uk.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2)
 with ESMTP id n4R6xpMM017211; Wed, 27 May 2009 07:59:51 +0100 (BST)
Date: Wed, 27 May 2009 08:59:51 +0200
From: Casper.Dik@sun.com
Subject: Re: Amendments to pconsole fast-track [PSARC/2009/275 FastTrack
 timeout 05/27/2009]
In-reply-to: <4A1C6A53.8060301@sun.com>
Sender: casper@holland.sun.com
To: Tim Haley <tim.haley@sun.com>
Cc: Gary Winiger <gww@eng.sun.com>, PSARC-ext@sun.com, Leland.Chen@sun.com,
        Norm.Jacobs@sun.com
Message-id: <200905270659.n4R6xpMM017211@dm-holland-02.uk.sun.com>
MIME-version: 1.0
Content-type: text/plain; charset=us-ascii
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200905261809.n4QI9l5a010807@marduk.eng.sun.com>
 <4A1C6A53.8060301@sun.com>
Status: RO
Content-Length: 629



>I'm not at all a Linux expert and could be reading it wrong, but it appears to 
>want the caller of the ioctl to have the CAP_SYS_ADMIN capability if they 
>aren't writing to the current processes' terminal.
>
>FreeBSD
>
>it looks like the ioctl is #ifdef'd out
>
>OpenBSD
>
>          case TIOCSTI:                   /* simulate terminal input */
>   964                 if (p->p_ucred->cr_uid && (flag & FREAD) == 0)
>   965                         return (EPERM);
>   966                 if (p->p_ucred->cr_uid && !isctty(p, tp))
>   967                         return (EACCES);


That's pretty much what we have.

Casper


From tim.haley@sun.com Wed May 27 12:38:55 2009
Received: from sunmail4.singapore.sun.com (sunmail4.Singapore.Sun.COM [129.158.71.19])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n4RJcsUk007608
	for <psarc-ext@sac.sfbay.sun.com>; Wed, 27 May 2009 12:38:54 -0700 (PDT)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.145.155.6])
	by sunmail4.singapore.sun.com (8.13.4+Sun/8.13.3/ENSMAIL,v2.2) with ESMTP id n4RJcRjw027263
	for <@sunmail2sca.sfbay.sun.com:PSARC-ext@sun.com>; Thu, 28 May 2009 03:38:53 +0800 (SGT)
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KKB00401IKRGE00@nwk-avmta-2.sfbay.sun.com> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Wed, 27 May 2009 12:38:51 -0700 (PDT)
Received: from brmea-mail-2.sun.com ([192.18.98.43])
 by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KKB00JVRIKQ6Y90@nwk-avmta-2.sfbay.sun.com> for
 PSARC-ext@sun.com (ORCPT PSARC-ext@sun.com); Wed,
 27 May 2009 12:38:51 -0700 (PDT)
Received: from fe-amer-10.sun.com ([192.18.109.80])
	by brmea-mail-2.sun.com (8.13.6+Sun/8.12.9) with ESMTP id n4RJcouf010926	for
 <PSARC-ext@sun.com>; Wed, 27 May 2009 19:38:50 +0000 (GMT)
Received: from conversion-daemon.mail-amer.sun.com by mail-amer.sun.com
 (Sun Java(tm) System Messaging Server 7u2-7.02 64bit (built Apr 16 2009))
 id <0KKB00D00I7ZDM00@mail-amer.sun.com> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Wed, 27 May 2009 13:38:50 -0600 (MDT)
Received: from [172.20.25.27] ([unknown] [172.20.25.27])
 by mail-amer.sun.com (Sun Java(tm) System Messaging Server 7u2-7.02 64bit
 (built Apr 16 2009)) with ESMTPSA id <0KKB00N7HIKC4T70@mail-amer.sun.com>; Wed,
 27 May 2009 13:38:40 -0600 (MDT)
Date: Wed, 27 May 2009 13:38:36 -0600
From: Tim Haley <tim.haley@sun.com>
Subject: Re: Amendments to pconsole fast-track [PSARC/2009/275 FastTrack
 timeout 05/27/2009]
In-reply-to: <4A1BF05A.4030403@sun.com>
Sender: Timothy.Haley@sun.com
To: PSARC-ext@sun.com
Cc: Leland.Chen@sun.com, Norm.Jacobs@sun.com
Message-id: <4A1D96BC.2050303@sun.com>
MIME-version: 1.0
Content-type: text/plain; CHARSET=US-ASCII; format=flowed
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <4A1BF05A.4030403@sun.com>
User-Agent: Thunderbird 2.0.0.21 (X11/20090505)
Status: RO
Content-Length: 66

This case was approved in today's (05/27/09) PSARC meeting.

-tim

