|
|
Message-ID: <20120812204429.GA7874@kludge.henri.nerv.fi>
Date: Sun, 12 Aug 2012 23:44:29 +0300
From: Henri Salo <henri@...v.fi>
To: owl-dev@...ts.openwall.com
Subject: Re: protected_{symlinks,hardlinks,fifos}
On Sun, Aug 12, 2012 at 09:54:35PM +0400, Vasily Kulikov wrote:
> Solar,
>
> The patch implementing protected_{symlinks,hardlinks} was backported from the
> upstream kernel. Almost the same way protected_fifos was implemented (ala
> HARDEN_FIFO). They work well.
>
> The question here is -- what defaults should be for OpenVZ containers:
> on, off, or inherit CT0's value?
>
> My opinion is default on, the same with CT0 (which runs Owl).
>
> --
> Vasily
Vote for default on.
- Henri Salo
Powered by blists - more mailing lists
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.