[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Message-ID: <20090201164104.0daafdf7@lxorguk.ukuu.org.uk>
Date: Sun, 1 Feb 2009 16:41:04 +0000
From: Alan Cox <alan@...rguk.ukuu.org.uk>
To: Christoph Hellwig <hch@....de>
Cc: Christoph Hellwig <hch@....de>,
Sukadev Bhattiprolu <sukadev@...ux.vnet.ibm.com>,
"H. Peter Anvin" <hpa@...or.com>, linux-kernel@...r.kernel.org
Subject: Re: devpts multiple instances feedback
On Sun, 1 Feb 2009 17:29:58 +0100
Christoph Hellwig <hch@....de> wrote:
> On Mon, Jan 26, 2009 at 09:58:53PM +0000, Alan Cox wrote:
> > > > That was also one of the reasons for the default 000 mode on the pts/ptmx
> > > > device node
> > >
> > > So just make it 000 but always created it.
> >
> > That still allows it to be subverted with some security rulesets -
> > remember root can open a 000 file by default.
>
> root can also mknod device nodes by default.
That depends on your SELinux policy rules
--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@...r.kernel.org
More majordomo info at http://vger.kernel.org/majordomo-info.html
Please read the FAQ at http://www.tux.org/lkml/
Powered by blists - more mailing lists