Re: Linux-NFS/IBM Open-Edition(OS/390)

Olaf Kirch (okir@monad.swb.de)
Sat, 10 May 1997 14:48:52 +0200 (MET DST)


To: linux-kernel@vger.rutgers.edu
Subject: Re: Linux-NFS/IBM Open-Edition(OS/390)
Newsgroups: swb.lists.linux.kernel
X-Newsreader: TIN [UNIX 1.3 950515BETA PL0]

In article <199705091200.IAA14687@tigger.techforce.com> you wrote:
: When creating a file or directory
: on the Open-Edition exported directory from Linux, It does NOT set the
: uid to that of the linux user, but rather it sets it to the uid of the
: Open-Edition server (0).

I'd call that a bug in their implementation, and an amusing security hole
as well. Try calling

ofd = creat("foobar", 04755);

copy some interesting program to the open fd and execute it. Hm.

I'll send a patch to Linus that sets the uid/gid in the request. I
just hope that that won't break other servers :-(

Olaf

-- 
Olaf Kirch         |  In those days, the future used to be better, too.
okir@monad.swb.de  |                               Karl Valentin