Re: Relax the prohibition of usage fchdir(2) to quit a chroot

Taylor R Campbell <[email protected]>
Newsgroups gmane.os.netbsd.devel.security
Message-ID <[email protected]>
   Date: Sun, 21 Sep 2014 11:37:23 +0200
   From: "Kamil Rytarowski" <[email protected]>

   My proposition is to add:

   security.chroot.allow_fchdir_out_of_chroot = 0
   security.chroot.allow_sysctl_inside_chroot = 1

   It's not broken by a 'the right design', but stops the job from being done.

   It passed a year after coming to conclusion how to walk-around
   it... fix the kernel.

The kernel is not broken.  Creating this security hole is ridiculous.
Fix the userland software -- it's not hard to structure right.  If
rpm's code base is an unmaintainable mess, too bad.
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.