看板FB_security
標 題Re: Call for review: restricted hardlinks.
發信站NCTU CSIE FreeBSD Server (Tue Mar 9 10:18:49 2004)
轉信站ptt!FreeBSD.csie.NCTU!not-for-mail
When you restrict links, do you want to restrict copying as well?
Seems somewhat paranoid to me. You already need write permission on the
directory where you create the link, and permissions are checked against
the inode on open(2) anyway.
My $0.0002.
--
Regards,
Georg.
Am Mo, den 08.03.2004 schrieb Pawel Jakub Dawidek um 10:36:
> Hi.
>
> I've no response from so@ in this topic, probably because leak of time,
> so I'll try here.
>
> Here is a patch that I'm planing to commit:
>
> http://people.freebsd.org/~pjd/patches/restricted_hardlinks.patch
>
> It adds two new sysctls:
>
> security.bsd.hardlink_check_uid
> security.bsd.hardlink_check_gid
>
> If sysctl security.bsd.hardlink_check_uid is set to 1, unprivileged users
> are not permitted to create hard links to files not owned by them.
> If sysctl security.bsd.hardlink_check_gid is set to 1, unprivileged users
> are not permitted to create hard links to files if they are not member
> of file's group.
>
> For now user is able to create hardlinks to any files.
_______________________________________________
[email protected] mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-security
To unsubscribe, send any mail to "
[email protected]"