Is there a reason we do not turn on the file system hardlink/symlink protection in Rawhide?

Chris Adams cmadams at hiwaay.net
Thu Mar 14 15:26:17 UTC 2013


Once upon a time, John Reiser <jreiser at bitwagon.com> said:
> The other descriptions of fs.protected_*links say that the protection
> applies to the lookup side when following a link, and not to the
> creation side when installing the link.  So the potential vulnerabilities
> still can be created, but damage is averted at the last possible moment.

That is for symlink protection I believe.  There's no way to do any
hardlink "protection" at lookup time.

Basically, these are two very different things being lumped together,
and they should be addressed individually.
-- 
Chris Adams <cmadams at hiwaay.net>
Systems and Network Administrator - HiWAAY Internet Services
I don't speak for anybody but myself - that's enough trouble.


More information about the devel mailing list