Casey Schaufler wrote:Why do people continue speaking symlinks and chroots? To avoid the effect of symlinks and chroots, AppArmor and TOMOYO Linux derive pathnames from dentry and vfsmount. If /etc/passwd was a symlink, the derived pathname will be /home/smalley/heeheehee. If accessed from inside a chroot, the derived pathname will be /roots/crispin/etc/passwd. It is true that namespace may differ between processes, but I think that that is the matter of how to restrict namespace manipulation operations. As I said, a system can't survive if namespace is madly manipulated. To keep the system workable, /bin/ must be the directory for binary programs, /etc/ must be the directory for configuration files, and so on in all namespaces. It is true that the pathname may change while traversing up the dentry/vfsmount trees. But the change does not occur infinitely. As I said, a system can't survive if files and directories are madly renamed. The possible changes are bounded by the policy. At least, I want people not to speak symlinks and chroots when talking about AppArmor and TOMOYO Linux. Regards. --
| Borislav Petkov | 2.6.23-rc1: no setup signature found... |
| Andrew Morton | Re: [PATCH] Memory management livelock |
| Greg KH | [GIT PATCH] driver core patches against 2.6.24 |
| Steven King | ti_usb_3410_5052 breakage in 2.6.24-rc1 |
git: | |
| Linus Torvalds | cleaner/better zlib sources? |
| Theodore Ts'o | [PATCH] Add --no-reuse-delta, --window, and --depth options to git-gc |
| Karl | Re: [PATCH] Add a birdview-on-the-source-code section to the user manual |
| Yossi Leybovich | corrupt object on git-gc |
| GVG GVG | ssh_exchange_identification: Connection closed by remote host |
| Richard Stallman | Re: Real men don't attack straw men |
| David Newman | setting dscp or tos bits |
| Stijn | Re: [i386/Thinkpad T41]USB mouse + Xorg obsd 4.1 |
| Quentin Garnier | [cube@cubidou.net: Re: Moving ethfoo in the main tree] |
| cube | Moving ethfoo in the main tree |
| Blair Sadewitz | PCI latency timer values |
| Oliver Gould | kqemu: driver(9)/filedesc(9) questions |
