Openwall GNU/*/Linux - a small security-enhanced Linux distro for servers
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Date: Sun, 12 Aug 2012 22:34:23 +0400
From: Solar Designer <solar@...nwall.com>
To: owl-dev@...ts.openwall.com
Subject: Re: protected_{symlinks,hardlinks,fifos}

On Sun, Aug 12, 2012 at 09:54:35PM +0400, Vasily Kulikov wrote:
> The patch implementing protected_{symlinks,hardlinks} was backported from the
> upstream kernel.  Almost the same way protected_fifos was implemented (ala
> HARDEN_FIFO).  They work well.
> 
> The question here is -- what defaults should be for OpenVZ containers:
> on, off, or inherit CT0's value?
> 
> My opinion is default on, the same with CT0 (which runs Owl).

I am fine with this.  Thanks!

Alexander

Powered by blists - more mailing lists

Your e-mail address:

Powered by Openwall GNU/*/Linux - Powered by OpenVZ