Re: Relax the prohibition of usage fchdir(2) to quit a chroot

Paul Goyette <[email protected]>
Newsgroups gmane.os.netbsd.devel.security
Message-ID <[email protected]>
IMHO, we should not implement this "feature".  We should not introduce 
ways to avoid deliberate, well-thought-out security mechanisms.

The use-case itself is broken, in my opinion.



On Sun, 21 Sep 2014, Kamil Rytarowski wrote:

> Thanks Marc,
>
> Well, right the better word is 'add feature' and we would change the
> discussion from 'don't touch anything' to 'let's add chroot
> restrictions swappable in runtime, that's a cool feature opening
> opportunities' and then to mind-storm ideas what and how to restrict.
>
> In some other way we might end up with floating patches around ;-)
>
> With kind regards.
>

-------------------------------------------------------------------------
| Paul Goyette     | PGP Key fingerprint:     | E-mail addresses:       |
| (Retired)        | FA29 0E3B 35AF E8AE 6651 | paul at whooppee.com    |
| Network Engineer | 0786 F758 55DE 53BA 7731 | pgoyette at juniper.net |
| Kernel Developer |                          | pgoyette at netbsd.org  |
-------------------------------------------------------------------------
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.