Re: VFS: Dynamic umask for the access rights of linked objects

From: Jiri Kosina
Date: Thu Mar 02 2006 - 11:09:22 EST


On Tue, 28 Feb 2006, Chris Wright wrote:

> Solar Designer's Openwall Linux patch contains code for these types of
> restrictions (at least since 2.2 if not earlier). Idea was stolen and
> made into an LSM smth like 4 or 5 years ago. Neither of these have made
> it upstream. Attempts have also been made to codify such restrictions
> in SELinux policy. Polyinstantiation and per-process namespaces can be
> done effectively with code that's now in mainline, and can mitigate much
> of this risk.

Just to make the discussion complete, I point out to the paper about a
thing called RaceGuard, presented at USENIX some time ago -
http://www.usenix.org/events/sec01/full_papers/cowanbeattie/cowanbeattie.pdf

--
JiKos.
-
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at http://vger.kernel.org/majordomo-info.html
Please read the FAQ at http://www.tux.org/lkml/