Re: Loopback (dir->dir) mounting (NOT -o loop)

From: H. Peter Anvin (hpa@zytor.com)
Date: Fri Jun 02 2000 - 04:25:26 EST


Followup to: <20000601235558.A188@bug.ucw.cz>
By author: Pavel Machek <pavel@suse.cz>
In newsgroup: linux.dev.kernel
>
> Hi!
>
> > > That will surely confuse hell out of the backup utility. It is
> > > probably going to confuse autoclean.
> >
> > And you allow your backups freely span the filesystem boundaries? I've
> > learnt not to do it _really_ hard way. Even harder was the autocleaner -
> > ever went "uh, /mnt is already busy, let's mount it for an hour under
> > /tmp/foo... Oh, FSCK! Let's hope these tapes are alive and there goes
> > my fscking weekend..."?
>
> It is bad to allow backups over fs boundaries; but it is harmless if
> you do not do "mistake". Oops. It used to be harmless. Now it is
> security hole. If you *really* want to have that mount in 2.4.0, let
> me know, and I'll make nice bugtraq announcement. Then we'll see how
> many holes this added.
>
> Pavel

It's worse than that. fs boundaries are typically detected by st_dev
changing, but that is not necessarily the case if your bind goes from
one part of one filesystem to another. Suddenly your bind is
undetectable to all existing software.

        -hpa

-- 
<hpa@transmeta.com> at work, <hpa@zytor.com> in private!
"Unix gives you enough rope to shoot yourself in the foot."

- To unsubscribe from this list: send the line "unsubscribe linux-kernel" in the body of a message to majordomo@vger.rutgers.edu Please read the FAQ at http://www.tux.org/lkml/



This archive was generated by hypermail 2b29 : Wed Jun 07 2000 - 21:00:14 EST