Files
linux-stable-mirror/rust/kernel
Jann Horn ef2d3e4635 rust: task: clarify comments on task UID accessors
Linux has separate subjective and objective task credentials, see the
comment above `struct cred`. Clarify which accessor functions operate on
which set of credentials.

Also document that Task::euid() is a very weird operation. You can see how
weird it is by grepping for task_euid() in the history - binder was its
only user. Task::euid() obtains the objective effective UID - it looks
at the credentials of the task for purposes of acting on it as an
object, but then accesses the effective UID (which the credentials.7 man
page describes as "[...] used by the kernel to determine the permissions
that the process will have when accessing shared resources [...]").

For context:
Arguably, binder's use of task_euid() is a theoretical security problem,
which only has no impact on Android because Android has no setuid binaries
executable by apps.
commit 29bc22ac5e ("binder: use euid from cred instead of using task")
originally fixed that by removing that only user of task_euid(), but the
fix got reverted in commit c21a80ca06 ("binder: fix test regression
due to sender_euid change") because some Android test started failing.
It was since fixed again by commit 65b6721522 ("binder: use
current_euid() for transaction sender identity"), which uses
current_euid() instead.

Signed-off-by: Jann Horn <jannh@google.com>
Reviewed-by: Gary Guo <gary@garyguo.net>
Signed-off-by: Alice Ryhl <aliceryhl@google.com>
Signed-off-by: Paul Moore <paul@paul-moore.com>
2026-07-07 15:10:48 -04:00
..
2026-04-03 11:57:35 +02:00
2026-05-20 00:47:24 +02:00
2026-06-09 04:13:21 +02:00
2026-05-25 09:40:52 +05:30