Re: [ANN] unionfs patchset-13 release



André Braga wrote:
A post scriptum to the original message:
The buggy behaviour won't affect the host system, but the jail could
well be compromised. I also have this feeling that ACLs also aren't
respected inside jails or can be overwritten as easily as shown below

Thanks,
André

for all folks who have deep consideration of FS:
We do not know well around MAC and ACL. Someone knows
well around those, please teach us. Does MAC have
a information of schg of chflags?


for all folks who have deep consideration of FS: part2
Yeah, it is possible to make capability for setting the
ALC and MAC information to the upper layer of the unionfs.
With that, we must consider the policy that what
information should be copied to shadow file when it makes
shadow file. Without the policy, we cannot make it.

We want to know your opinions if you have deep
consideration of it. What do you make of it?

--
Daichi GOTO, http://people.freebsd.org/~daichi
_______________________________________________
freebsd-current@xxxxxxxxxxx mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-current
To unsubscribe, send any mail to "freebsd-current-unsubscribe@xxxxxxxxxxx"



Relevant Pages

  • Re: [ANN] unionfs patchset-13 release
    ... The buggy behaviour won't affect the host system, but the jail could ... I also have this feeling that ACLs also aren't ... We do not know well around MAC and ACL. ... information should be copied to shadow file when it makes ...
    (freebsd-hackers)
  • Re: [fw-wiz] VM system for firewall use
    ... In the VM environment the compromise would ... More importantly the data objects in a MAC environment never ... I'm not sure that jail gives you much. ...
    (Firewall-Wizards)
  • Re: Access Control Lists
    ... ACLs are honored if a user logs into the actual machine ... ACLs are not honored if the user connects via AFP ... > machine is running Mac OS X Server. ... the file server runs as a very privileged user (and looking ...
    (comp.sys.mac.misc)
  • Re: rsync in funktionierend?
    ... Eigentümerschaft, flags, eflags und ACLs via ssh von einem Mac zum anderen ... nicht mit hfs-Dateisystemen, sondern nfs bzw. cifs. ... ACLs unterstützt. ...
    (de.comp.sys.mac.misc)
  • Re: AppArmor FAQ
    ... An easy-to-use yet ... inadequate solution for MAC or jail. ...
    (Linux-Kernel)