Alan Cox wrote:
On Wed, 26 Sep 2007 01:05:07 +0930 David Newall <david@davidnewall.com> wrote:Alan Cox wrote:Marek's loading dynamic libraries, it seems clear that the prime purpose of chroot is to aid security. Being able to cd your way out is handyDoes it - I can't find any evidence for that.It seems self-evident to me. What do you think is it prime purpose?Debugging and testing. At least that is as I understand it much of where it came from.
Good call. Though I suppose, since it's used 24x7 to aid security on countless production servers, that security dwarfs testing. Still, debugging, yes that's valid.
I don't suppose it makes and difference; whatever the purpose, a chroot that doesn't change the root is buggy.
- To unsubscribe from this list: send the line "unsubscribe linux-kernel" in the body of a message to majordomo@vger.kernel.org More majordomo info at http://vger.kernel.org/majordomo-info.html Please read the FAQ at http://www.tux.org/lkml/
- Follow-Ups:
- Re: Chroot bug
- From: Adrian Bunk <bunk@kernel.org>
- Re: Chroot bug
- From: Alan Cox <alan@lxorguk.ukuu.org.uk>
- Re: Chroot bug
- References:
- Re: sys_chroot+sys_fchdir Fix
- From: "Philipp Marek" <philipp@marek.priv.at>
- Re: sys_chroot+sys_fchdir Fix
- From: David Newall <david@davidnewall.com>
- Re: sys_chroot+sys_fchdir Fix
- From: Philipp Marek <philipp@marek.priv.at>
- Re: sys_chroot+sys_fchdir Fix
- From: David Newall <david@davidnewall.com>
- Re: sys_chroot+sys_fchdir Fix
- From: Bill Davidsen <davidsen@tmr.com>
- Re: sys_chroot+sys_fchdir Fix
- From: David Newall <david@davidnewall.com>
- Re: sys_chroot+sys_fchdir Fix
- From: "Serge E. Hallyn" <serge@hallyn.com>
- Re: sys_chroot+sys_fchdir Fix
- From: David Newall <david@davidnewall.com>
- Re: sys_chroot+sys_fchdir Fix
- From: "Serge E. Hallyn" <serge@hallyn.com>
- Re: sys_chroot+sys_fchdir Fix
- From: David Newall <david@davidnewall.com>
- Re: sys_chroot+sys_fchdir Fix
- From: "Serge E. Hallyn" <serge@hallyn.com>
- Re: sys_chroot+sys_fchdir Fix
- From: David Newall <david@davidnewall.com>
- Chroot bug (was: sys_chroot+sys_fchdir Fix)
- From: David Newall <david@davidnewall.com>
- Re: Chroot bug (was: sys_chroot+sys_fchdir Fix)
- From: Alan Cox <alan@lxorguk.ukuu.org.uk>
- Re: Chroot bug
- From: David Newall <david@davidnewall.com>
- Re: Chroot bug
- From: Alan Cox <alan@lxorguk.ukuu.org.uk>
- Re: sys_chroot+sys_fchdir Fix
- Prev by Date: [08/17] GFP_VFALLBACK: Allow fallback of compound pages to virtual mappings
- Next by Date: Re: vm86.c audit_syscall_exit() call trashes registers
- Previous by thread: Re: Chroot bug
- Next by thread: Re: Chroot bug
- Index(es):
![]() |