RE: securety related question...

"Bob Kimmel" <[email protected]>
Newsgroups gmane.linux.lfs.security
Message-ID <[email protected]>
> [06.10.2002] Bill maltby - LFS Related <-- :
> > On Sun, 6 Oct 2002, Richard Lightman wrote:
> >
> > > Could you check that you can bind a rw device ro? I read somewhere
> > > that there was a patch to keep separate mount flags for each mount,
> > > but it does not appear to be there yet:
> >
> > I get the same results with the same version of mount that you have.
> > Further, if I do a "remount,ro", the remount affects the "base" mount as
> > well as the bound mount. So, until separate flags for the bound mount
> > point become available, there is reduced security available for
> the "host"
> > partition if it must be mounted rw.
>
> Isn't it logical? The --bind is the only option (no additionals) and its
> purpose is to make the *already mounted* partition available at another
> place, that *same* partition (and this means with all its flags).
>
> How are we going to end up, if --bind would allow to change the flags,
> suddenly a by intention mounted ro partition will be rw, and what you
> believe protected by ro is suddenly deleted via the bound mounting point!
>

Would it be feasible to allow --bind to change the flags, but only to
more restrictive permissions?  I.e., you could bind a rw partition
as ro, not bind a ro partition as rw.

BK

Bob Kimmel
Bendheim Center for Finance
Department of Economics
Princeton University
[email protected]

-- 
Unsubscribe: send email to [email protected]
and put 'unsubscribe lfs-security' in the subject header of the message
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.