Re: VFAT Naming Bugs

Richard Gooch (rgooch@atnf.csiro.au)
Fri, 11 Jun 1999 16:29:24 +1000


Gordon Chaffee writes:
> Jeff Merkey <jmerkey@timpanogas.com> writes:
> > 1. The names PIPE, $CLOCK, and NETQ are reserved as special device file
> > names for some versions of DOS and Win95 and can get folks into trouble
> > if you allow linux to create these names.
>
> You can create CLOCK$ and NETQ on Windows NT, so by your definition,
> folks can get into trouble from NT to. Maybe we should just make it
> illegal to write any filename to the vfat filesystem and make it
> safe for everyone.

Actually, because of the lack of permission checks in VFAT, there is a
gaping security threat. So, in the best interests of the user, we
should overwrite the VFAT FS with zeros at mount and unmount time. And
at other random times just to be sure.

Regards,

Richard....

-
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.rutgers.edu
Please read the FAQ at http://www.tux.org/lkml/