On Tue, Sep 25, 2007 at 07:05:06PM +0200, Jan Engelhardt wrote:so if you check sanity in fchdir (if directory_is_out), your method will not succeed :)
Perhaps that was formulated a bit sloppy. It of course means
"On chroot(2), implicitly close all FDs that point outside."
Bollocks. Pack 'em into SCM_RIGHTS datagram, send to yourself,
do chroot, recvmsg() and move on, cheerfully spitting at the
YAidiotic "hardening".