Re: TOMOYO Linux Security Goal

From: Serge E. Hallyn
Date: Mon Dec 31 2007 - 11:17:46 EST


Quoting Tetsuo Handa (penguin-kernel@xxxxxxxxxxxxxxxxxxx):
> Hello.
>
> Serge E. Hallyn wrote:
> > > Does a process get different mount trees by just calling clone() or unshare()?
> > > My understanding is that clone() or unshare() disables propergation of
> > > mount tree changes when somebody calls mount() or umount() or pivot_root().
> >
> > Yes, with further propagation rules possible.
> >
> Excuse me. To which statement did you say "yes"?

Sorry, "yes your understanding was correct."

> Does clone() or unshare() change visible directories without
> calling following mount()/umount()/pivot_root()?
>
> Regards.
> -
> To unsubscribe from this list: send the line "unsubscribe linux-security-module" in
> the body of a message to majordomo@xxxxxxxxxxxxxxx
> More majordomo info at http://vger.kernel.org/majordomo-info.html
--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at http://vger.kernel.org/majordomo-info.html
Please read the FAQ at http://www.tux.org/lkml/