Re: [RFC][PATCH 4/11] security: AppArmor - Core access controls

From: Rik van Riel
Date: Wed Apr 19 2006 - 19:05:18 EST


On Wed, 19 Apr 2006, Crispin Cowan wrote:
> Arjan van de Ven wrote:

> > that sounds too bad ;)
> > If I manage to mount /etc/passwd as /tmp/passwd, you'll only find the
> > later and your entire security system seems to be down the drain.

> If you are a confined process, then you don't get to mount things, for
> this reason, among others.

Are confined processes always restricted from starting
non-confined processes?

--
All Rights Reversed
-
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at http://vger.kernel.org/majordomo-info.html
Please read the FAQ at http://www.tux.org/lkml/