Re: [AppArmor 01/41] Pass struct vfsmount to the inode_create LSM hook

Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
From: Alan Cox
Date: Saturday, May 26, 2007 - 6:34 am

> As such, AA can detect whether you did exec("gzip") or exec("gunzip")

That's not actually useful for programs which link the same binary to
multiple names because if you don't consider argv[0] as well I can run
/usr/bin/gzip passing argv[0] of "gunzip" and get one set of policies and
the other set of behaviour.

And then we have user added hardlinks of course.

-
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
Re: [AppArmor 01/41] Pass struct vfsmount to the inode_cre ..., Andreas Gruenbacher, (Thu May 24, 11:10 am)
Re: [AppArmor 01/41] Pass struct vfsmount to the inode_cre ..., Andreas Gruenbacher, (Thu May 24, 2:56 pm)
Re: [AppArmor 01/41] Pass struct vfsmount to the inode_cre ..., Andreas Gruenbacher, (Thu May 24, 9:14 pm)
Re: [AppArmor 01/41] Pass struct vfsmount to the inode_cre ..., Jeremy Maitin-Shepard, (Thu May 24, 10:17 pm)
Re: [AppArmor 01/41] Pass struct vfsmount to the inode_cre ..., Jeremy Maitin-Shepard, (Fri May 25, 11:10 am)
Re: [AppArmor 01/41] Pass struct vfsmount to the inode_cre ..., Jeremy Maitin-Shepard, (Fri May 25, 11:13 am)
Re: [AppArmor 01/41] Pass struct vfsmount to the inode_cre ..., Andreas Gruenbacher, (Fri May 25, 1:00 pm)
Re: [AppArmor 01/41] Pass struct vfsmount to the inode_cre ..., Andreas Gruenbacher, (Sat May 26, 4:46 am)
Re: Pass struct vfsmount to the inode_create LSM hook, Tetsuo Handa, (Sat May 26, 5:09 am)
Re: [AppArmor 01/41] Pass struct vfsmount to the inode_cre ..., Andreas Gruenbacher, (Sat May 26, 5:10 am)
Re: [AppArmor 01/41] Pass struct vfsmount to the inode_cre ..., Alan Cox, (Sat May 26, 6:34 am)
Re: Pass struct vfsmount to the inode_create LSM hook, Andreas Gruenbacher, (Sat May 26, 6:41 am)
Re: [AppArmor 01/41] Pass struct vfsmount to the inode_cre ..., Andreas Gruenbacher, (Sat May 26, 7:05 am)
Re: Pass struct vfsmount to the inode_create LSM hook, Tetsuo Handa, (Sat May 26, 7:44 am)
Re: Pass struct vfsmount to the inode_create LSM hook, Andreas Gruenbacher, (Sat May 26, 9:52 am)
Re: Pass struct vfsmount to the inode_create LSM hook, Kyle Moffett, (Sat May 26, 11:16 am)
Re: [AppArmor 01/41] Pass struct vfsmount to the inode_cre ..., Toshiharu Harada, (Sun May 27, 12:25 am)