On Sep 25 2007 16:48, Alan Cox wrote: >David Newall <[email protected]> wrote: >> Alan Cox wrote: >>>> >>>> Marek's loading dynamic libraries, it seems clear that the prime >>>> purpose of chroot is to aid security. Being able to cd your way >>>> out is handy >>> >>> Does it - I can't find any evidence for that. >> >> It seems self-evident to me. What do you think is it prime purpose? > >Debugging and testing. At least that is as I understand it much of where >it came from. > >>> A root user can get out of a chroot a million different ways Uhm, you _do_ have considered the case of setuid(non-0)-after-chroot, have not you? - To unsubscribe from this list: send the line "unsubscribe linux-kernel" in the body of a message to [email protected] More majordomo info at http://vger.kernel.org/majordomo-info.html Please read the FAQ at http://www.tux.org/lkml/
- References:
- Re: sys_chroot+sys_fchdir Fix
- From: "Philipp Marek" <[email protected]>
- Re: sys_chroot+sys_fchdir Fix
- From: David Newall <[email protected]>
- Re: sys_chroot+sys_fchdir Fix
- From: Philipp Marek <[email protected]>
- Re: sys_chroot+sys_fchdir Fix
- From: David Newall <[email protected]>
- Re: sys_chroot+sys_fchdir Fix
- From: Bill Davidsen <[email protected]>
- Re: sys_chroot+sys_fchdir Fix
- From: David Newall <[email protected]>
- Re: sys_chroot+sys_fchdir Fix
- From: "Serge E. Hallyn" <[email protected]>
- Re: sys_chroot+sys_fchdir Fix
- From: David Newall <[email protected]>
- Re: sys_chroot+sys_fchdir Fix
- From: "Serge E. Hallyn" <[email protected]>
- Re: sys_chroot+sys_fchdir Fix
- From: David Newall <[email protected]>
- Re: sys_chroot+sys_fchdir Fix
- From: "Serge E. Hallyn" <[email protected]>
- Re: sys_chroot+sys_fchdir Fix
- From: David Newall <[email protected]>
- Chroot bug (was: sys_chroot+sys_fchdir Fix)
- From: David Newall <[email protected]>
- Re: Chroot bug (was: sys_chroot+sys_fchdir Fix)
- From: Alan Cox <[email protected]>
- Re: Chroot bug
- From: David Newall <[email protected]>
- Re: Chroot bug
- From: Alan Cox <[email protected]>
- Re: sys_chroot+sys_fchdir Fix
- Prev by Date: Re: Chroot bug
- Next by Date: Re: Chroot bug
- Previous by thread: Re: Chroot bug
- Next by thread: Re: Chroot bug
- Index(es):