Subject: Re: Addition to force open to open only regular files
To: NetBSD Kernel Technical Discussion List <tech-kern@netbsd.org>
From: Greg A. Woods <woods@weird.com>
List: tech-kern
Date: 11/16/2000 14:06:43
[ On Thursday, November 16, 2000 at 08:17:26 (+0200), Jukka Marin wrote: ]
> Subject: Re: Addition to force open to open only regular files
>
> Err.  I want to be able to put several tarballs on one tape.  And Amanda
> depends on the norewind tape device, too.  Please don't break the current
> behaviour!

I'm not talking about breaking or changing anything!

Just the opposite in fact.

I'm only saying that the relative risk of some unathorised user process
opening a tape device and causing a spurious rewind (which could in
theory overwrite earlier files if done at the right time) is relatively
low and that the correct way to fix this is to make it very hard for a
rogue user to subvert a set-ID process into opening arbitrary files
(even if all it does is fstat() and close() them again).

(well, OK, yes, then I'm talking about breaking $HOSTALIASES and maybe
even $LOCALDOMAIN too.)

-- 
							Greg A. Woods

+1 416 218-0098      VE3TCP      <gwoods@acm.org>      <robohack!woods>
Planix, Inc. <woods@planix.com>; Secrets of the Weird <woods@weird.com>