Re: another (!) new kmod.c

Stefan Monnier (monnier+lists/linux/kernel/news/@TEQUILA.SYSTEMSZ.CS.YALE.EDU)
17 Apr 1998 16:59:33 -0400


"Adam J. Richter" <adam@yggdrasil.com> writes:
> To some extent, I regard this as a feature, because I envision
> using chroot to create somewhat insular environments, like say, an

This is fairly bogus: it doesn't prevent the use of a module from a chrooted
env, but only loading the module from there. So all you need to do from
your chroot jail is to wait for some helpful soul to load the module you want
from some other process. Doesn't seem like a robust security feature.
It's maybe not bad in and of itself, but it's only potentially useful in some
contrived cases.

Stefan

-
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.rutgers.edu