Re: [PATCH] Filesystem linking protections

From: Chris Wright
Date: Mon Feb 07 2005 - 15:12:30 EST


* John Richard Moser (nigelenki@xxxxxxxxxxx) wrote:
> I've yet to see this break anything on Ubuntu or Gentoo; Brad Spengler
> claims this breaks nothing on Debian. On the other hand, this could
> potentially squash the second most prevalent security bug.

Yes I know, I've worked on distro with it as well in the past. And it
has broken atd and courier in the past. This is something that also
can be done in userspace using sane subdirs in +t world writable dirs,
or O_EXCL so there's work to be done in userspace.

thanks,
-chris
--
Linux Security Modules http://lsm.immunix.org http://lsm.bkbits.net
-
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at http://vger.kernel.org/majordomo-info.html
Please read the FAQ at http://www.tux.org/lkml/