RE: securety related question...
"Bob Kimmel" <[email protected]>
| Newsgroups | gmane.linux.lfs.security |
|---|---|
| Message-ID | <[email protected]> |
> [06.10.2002] Bill maltby - LFS Related <-- : > > On Sun, 6 Oct 2002, Richard Lightman wrote: > > > > > Could you check that you can bind a rw device ro? I read somewhere > > > that there was a patch to keep separate mount flags for each mount, > > > but it does not appear to be there yet: > > > > I get the same results with the same version of mount that you have. > > Further, if I do a "remount,ro", the remount affects the "base" mount as > > well as the bound mount. So, until separate flags for the bound mount > > point become available, there is reduced security available for > the "host" > > partition if it must be mounted rw. > > Isn't it logical? The --bind is the only option (no additionals) and its > purpose is to make the *already mounted* partition available at another > place, that *same* partition (and this means with all its flags). > > How are we going to end up, if --bind would allow to change the flags, > suddenly a by intention mounted ro partition will be rw, and what you > believe protected by ro is suddenly deleted via the bound mounting point! > Would it be feasible to allow --bind to change the flags, but only to more restrictive permissions? I.e., you could bind a rw partition as ro, not bind a ro partition as rw. BK Bob Kimmel Bendheim Center for Finance Department of Economics Princeton University [email protected] -- Unsubscribe: send email to [email protected] and put 'unsubscribe lfs-security' in the subject header of the message