Hello. Andreas Gruenbacher wrote:AppArmor can't determine which pathname (/tmp/public/file or /tmp/secret/file) was requested by touch command if bound mount is used in the following way # mkdir /tmp/public /tmp/secret # mount -t tmpfs none /tmp/public # mount --bind /tmp/public /tmp/secret # touch /tmp/public/file because security_inode_create() doesn't receive vfsmount, can it? It is possible to determine that the requested pathname is either /tmp/public/file or /tmp/secret/file by comparing address of vfsmount available from current->namespace, but it is impossible to determine which one. Yes, of course, TOMOYO checks "/tmp/b/f". What I meant PROCEDURE FOR REACHING is "which directory does the process need to go through to reach the requested file if the process's current directory is the root of the process's namespace". And in this case, it is "/tmp/b/f". Thanks. -
| Al Viro | Re: Dual-Licensing Linux Kernel with GPL V2 and GPL V3 |
| Greg KH | [2.6.22.2 review 05/84] Fix deadlocks in sparc serial console. |
| Linus Torvalds | Linux 2.6.27-rc8 |
| Greg Kroah-Hartman | [PATCH 006/196] Chinese: add translation of oops-tracing.txt |
git: | |
| Natalie Protasevich | [BUG] New Kernel Bugs |
| Jarek Poplawski | Re: [PATCH] pkt_sched: Destroy gen estimators under rtnl_lock(). |
| Linus Torvalds | Re: [GIT]: Networking |
| Gerrit Renker | [PATCH 0/37] dccp: Feature negotiation - last call for comments |
| Manuel Bouyer | Re: Interactive performance in -current |
| YAMAMOTO Takashi | Re: statvfs(2) replacement for statfs(2) patch |
| Nathan Langford | microkernels |
| Garrett D'Amore | Re: wsmux inject |
