Re: devpts multiple instances feedback
From: Alan Cox
Date: Sun Feb 01 2009 - 11:40:55 EST
On Sun, 1 Feb 2009 17:29:58 +0100
Christoph Hellwig <hch@xxxxxx> wrote:
> On Mon, Jan 26, 2009 at 09:58:53PM +0000, Alan Cox wrote:
> > > > That was also one of the reasons for the default 000 mode on the pts/ptmx
> > > > device node
> > >
> > > So just make it 000 but always created it.
> >
> > That still allows it to be subverted with some security rulesets -
> > remember root can open a 000 file by default.
>
> root can also mknod device nodes by default.
That depends on your SELinux policy rules
--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at http://vger.kernel.org/majordomo-info.html
Please read the FAQ at http://www.tux.org/lkml/