Research Menu

.
Skip Search Box

SELinux Mailing List

Re: [BUGTRAQ] Linux patches to solve /tmp race problem

From: Magosányi Árpád <mag_at_bunuel.tii.matav.hu>
Date: Sat, 21 Apr 2001 10:45:02 +0200


Hi!

This is a good functionality. What about making a selinux-dependent version of it, which can include the TSID (or much better the label representation) in the pathname?
It could be very useful for creating multilevel directories.

A levelezőm azt hiszi, hogy Donaldson, Matthew a következőeket írta:
> Hi all,
>
> I have recently developed some patches to the Linux 2.2 kernels which solve
> the /tmp race problem without needing to define environment variables -
> useful particularly for naive applications and scripts which dont use
> TMPDIR and friends.
>
> The patch creates "dynamic" symlinks, which point to different paths
> depending on the user accessing them (for example, including the UID in the
> path name). Such a link can be placed instead of /tmp and/or /var/tmp, and
> any other similar directories. More usefully, these links can be configured
> to automatically create the directory they refer to if it does not exist.
>
> This means you can create a directory such as /tmp_files, for example, and
> have the /tmp link automatically create user directories in it on demand.
> Default permissions and ownership can be specified.
>
> The patches are available from http://www.datadeliverance.com in the Linux
> Patches section, along with a full discussion of the issues involved. Your
> comments on the scheme are invited.
>
> Cheers
>
> -Matthew
>
> --
> +--------------------------------------------------------------------------+
> | Matthew Donaldson http://www.datadeliverance.com |
> | Data Deliverance Pty. Ltd. Email: matthew@datadeliverance.com |
> | 30 Musgrave Ave. Phone: +61 8 8265 7976 _ |
> | Banksia Park Fax: +61 8 8265 0032 John / \/ |
> | South Australia 5091 3:16 \_/\ |
> +--------------------------------------------------------------------------+
>

-- 
GNU GPL: csak tiszta forrásból

--
You have received this message because you are subscribed to the selinux list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.
Received on Sat 21 Apr 2001 - 05:01:59 EDT
 

Date Posted: Jan 15, 2009 | Last Modified: Jan 15, 2009 | Last Reviewed: Jan 15, 2009

 
bottom

National Security Agency / Central Security Service