Re: [PATCH] exec: Only allow a threaded init to exec from thethread_group_leader

From: Andrew Morton
Date: Sun Jan 29 2006 - 05:53:13 EST


ebiederm@xxxxxxxxxxxx (Eric W. Biederman) wrote:
>
> If process id namespaces become a reality init stops being
> terribly special, and becomes something you may have several
> of running at any one time. If one of those inits is compromised
> by a hostile user I having the whole system go down so we can
> avoid executing a cheap test sounds terribly wrong. That is
> why I really care.

Wouldn't it be better to do nothing until/unless there's some code in the
kernel or init which actually needs the change?

-
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at http://vger.kernel.org/majordomo-info.html
Please read the FAQ at http://www.tux.org/lkml/