Re: link() security

From: xystrus (xystrus@haxm.com)
Date: Sat Apr 13 2002 - 12:02:33 EST


On Sat, Apr 13, 2002 at 05:59:54PM +0100, Alan Cox wrote:
> > http://openwall.com. Work based on Solar Designer's Openwall patch has
> > been brought forward to more recent 2.4 and 2.5 kernels. Both the
> > following projects implement the Openwall secure link feature:
> >
> > http://grsecurity.net
> > http://lsm.immunix.org
> >
> > This can break some applications that make assumptions wrt. link(2)
> > (Courier MTA for example).
>
> How practical is it to make this a mount option and to do so cleanly ?

Perhaps two options: one to allow creation of the link only when the
UIDs match; and the other to allow the link when GIDs match, to keep
Courier happy?

-
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at http://vger.kernel.org/majordomo-info.html
Please read the FAQ at http://www.tux.org/lkml/



This archive was generated by hypermail 2b29 : Mon Apr 15 2002 - 22:00:22 EST