If the process can chmod the file, it can ptrace the daemon, too.
Or, using CAP_DAC_OVERRIDE, it can patch the daemon.
Both will void any security.
Having no window for creating stale temp files is nice to have. We only
need a clever fool to implement it.-) But since it's hard to get killed
just in the right moment for having a stale temp file, there is very low
interest for this feature.
--
You know you're in trouble when packet floods are competing to flood you.
-- grc.com
Friß, Spammer: dnLqD2P@t.7eggert.dyndns.orgnpkrx@imrx.fp6.7eggert.dyndns.org
-