[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <508AFF17.6050705@panasas.com>
Date: Fri, 26 Oct 2012 14:22:31 -0700
From: Boaz Harrosh <bharrosh@...asas.com>
To: Kees Cook <keescook@...omium.org>
CC: Linus Torvalds <torvalds@...ux-foundation.org>,
<linux-kernel@...r.kernel.org>,
Alexander Viro <viro@...iv.linux.org.uk>,
<linux-fsdevel@...r.kernel.org>
Subject: Re: [PATCH] VFS: add config options to enable link restrictions
On 10/26/2012 01:23 PM, Kees Cook wrote:
>
> Every distro will ship with this enabled (except perhaps Damn
> Vulnerable Linux), so why make it harder?
>
So please remind me why can't it be on by default in code.
And the normal sysctl to turn it off for these who want to
experiment with "filesystem corruption".
So the basic premise is that you must not have any
filesystem corruption at the parts used by boot up until
the init portion that turns "filesystem corruption" on
> -Kees
>
Cheers
Boaz
--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@...r.kernel.org
More majordomo info at http://vger.kernel.org/majordomo-info.html
Please read the FAQ at http://www.tux.org/lkml/
Powered by blists - more mailing lists