Re: Proposal: restrict link(2)

Harald Koenig (koenig@tat.physik.uni-tuebingen.de)
Wed, 11 Dec 1996 13:30:55 +0100 (MET)


> If, however, /tmp/foo is a HARD link to /etc/passwd, chown("/tmp/foo",
> uid, gid) will lead to the user owning /etc/passwd - not a desirable
> thing, in general.
>
> My proposal would be to disallow linking a file into a directory which
> has the sticky bit set unless the owner of the file is attempting this.
> In other words, Joe Random Cracker can't do a 'ln /etc/passwd /tmp/foo'
> beforehand.

why is Joe Random Cracker allowed to make a hard link to /etc/passwd at all
(or to any other file not owed by him) ?

Harald

--
All SCSI disks will from now on                     ___       _____
be required to send an email notice                0--,|    /OOOOOOO\
24 hours prior to complete hardware failure!      <_/  /  /OOOOOOOOOOO\
                                                    \  \/OOOOOOOOOOOOOOO\
                                                      \ OOOOOOOOOOOOOOOOO|//
Harald Koenig,                                         \/\/\/\/\/\/\/\/\/
Inst.f.Theoret.Astrophysik                              //  /     \\  \
koenig@tat.physik.uni-tuebingen.de                     ^^^^^       ^^^^^