Re: suid bit on directories

From: Bill Davidsen (davidsen@tmr.com)
Date: Tue May 21 2002 - 13:03:17 EST


On Mon, 20 May 2002, Michael Hoennig wrote:

> Anyway, when I find time in the next weeks, I will try this patch and post
> it. I will do it as a mount option. Nobody is forced to use it ;-)

If I might offer a suggestion, that requires a patched mount command, etc.
I would offer as an alternative implementation which might be both easier
to do and more useful in testing. Make the capability an option in the
kernel, and then require that it be enabled in /proc/sys with default off.
Think TCP_SYN_COOKIES or similar. That way you can have a single patch set
for the kernel only, and no one can possibly "stumble on it" and complain.
Also, you can disable without reboot or remount after testing.

-- 
bill davidsen <davidsen@tmr.com>
  CTO, TMR Associates, Inc
Doing interesting things with little computers since 1979.

- To unsubscribe from this list: send the line "unsubscribe linux-kernel" in the body of a message to majordomo@vger.kernel.org More majordomo info at http://vger.kernel.org/majordomo-info.html Please read the FAQ at http://www.tux.org/lkml/



This archive was generated by hypermail 2b29 : Thu May 23 2002 - 22:00:22 EST