On Wed, 26 Sep 2007 01:05:07 +0930 David Newall <david@davidnewall.com> wrote: > Alan Cox wrote: > >> Marek's loading dynamic libraries, it seems clear that the prime purpose > >> of chroot is to aid security. Being able to cd your way out is handy > >> > > > > Does it - I can't find any evidence for that. > > It seems self-evident to me. What do you think is it prime purpose? Debugging and testing. At least that is as I understand it much of where it came from. > > A root user can get out of a chroot a million different ways > One of those ways shouldn't be that chroot lets you out. A fence with 10000 open gates is not improved by turning it into a fence with 9999 open gates. - To unsubscribe from this list: send the line "unsubscribe linux-kernel" in the body of a message to majordomo@vger.kernel.org More majordomo info at http://vger.kernel.org/majordomo-info.html Please read the FAQ at http://www.tux.org/lkml/
- Follow-Ups:
- Re: Chroot bug
- From: David Newall <david@davidnewall.com>
- Re: Chroot bug
- From: Jan Engelhardt <jengelh@computergmbh.de>
- Re: Chroot bug
- References:
- Re: sys_chroot+sys_fchdir Fix
- From: "Philipp Marek" <philipp@marek.priv.at>
- Re: sys_chroot+sys_fchdir Fix
- From: David Newall <david@davidnewall.com>
- Re: sys_chroot+sys_fchdir Fix
- From: Philipp Marek <philipp@marek.priv.at>
- Re: sys_chroot+sys_fchdir Fix
- From: David Newall <david@davidnewall.com>
- Re: sys_chroot+sys_fchdir Fix
- From: Bill Davidsen <davidsen@tmr.com>
- Re: sys_chroot+sys_fchdir Fix
- From: David Newall <david@davidnewall.com>
- Re: sys_chroot+sys_fchdir Fix
- From: "Serge E. Hallyn" <serge@hallyn.com>
- Re: sys_chroot+sys_fchdir Fix
- From: David Newall <david@davidnewall.com>
- Re: sys_chroot+sys_fchdir Fix
- From: "Serge E. Hallyn" <serge@hallyn.com>
- Re: sys_chroot+sys_fchdir Fix
- From: David Newall <david@davidnewall.com>
- Re: sys_chroot+sys_fchdir Fix
- From: "Serge E. Hallyn" <serge@hallyn.com>
- Re: sys_chroot+sys_fchdir Fix
- From: David Newall <david@davidnewall.com>
- Chroot bug (was: sys_chroot+sys_fchdir Fix)
- From: David Newall <david@davidnewall.com>
- Re: Chroot bug (was: sys_chroot+sys_fchdir Fix)
- From: Alan Cox <alan@lxorguk.ukuu.org.uk>
- Re: Chroot bug
- From: David Newall <david@davidnewall.com>
- Re: sys_chroot+sys_fchdir Fix
- Prev by Date: Re: Chroot bug
- Next by Date: Re: ACPI power off regression in 2.6.23-rc8 (NOT in rc7)
- Previous by thread: Re: Chroot bug
- Next by thread: Re: Chroot bug
- Index(es):
![]() |