Re: Chroot bug

From: Miloslav Semler
Date: Tue Sep 25 2007 - 13:19:34 EST



On Tue, Sep 25, 2007 at 07:05:06PM +0200, Jan Engelhardt wrote:

Perhaps that was formulated a bit sloppy. It of course means
"On chroot(2), implicitly close all FDs that point outside."

Bollocks. Pack 'em into SCM_RIGHTS datagram, send to yourself,
do chroot, recvmsg() and move on, cheerfully spitting at the
YAidiotic "hardening".
so if you check sanity in fchdir (if directory_is_out), your method will not succeed :)
-
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at http://vger.kernel.org/majordomo-info.html
Please read the FAQ at http://www.tux.org/lkml/