Skip site navigation (1)Skip section navigation (2)
Date:      Wed, 12 Feb 2003 21:05:18 +0100
From:      Pawel Jakub Dawidek <nick@garage.freebsd.pl>
To:        Mooneer Salem <mooneer@translator.cx>
Cc:        freebsd-bugs@freebsd.org
Subject:   Re: kern/48198: Non-jailed users can kill processes owned by same UID
Message-ID:  <20030212200518.GJ10767@garage.freebsd.pl>
In-Reply-To: <FHEMJMOKKMJDGKFOHHEPCEEHEOAA.mooneer@translator.cx>
References:  <FHEMJMOKKMJDGKFOHHEPCEEHEOAA.mooneer@translator.cx>

next in thread | previous in thread | raw e-mail | index | archive | help

--enLffk0M6cffIOOh
Content-Type: text/plain; charset=iso-8859-2
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable

On Tue, Feb 11, 2003 at 09:22:55PM -0800, Mooneer Salem wrote:
+> >Description:
+>         When a process is running inside a jail that is owned by a UID t=
hat
+> exists outside of
+>         the jail as well as inside, the outside user is able to kill that
+> process, even if
+>         both users are not the same person. If this is the case, this co=
uld
+> cause people to be
+>         more than slightly annoyed.

IMHO this is correct behaviour. Non-jailed users can play with files owned
by users that share this same UID inside jail, etc.

Your solution isn't complete and this isn't a bug, IMHO.

--=20
Pawel Jakub Dawidek
UNIX Systems Administrator
http://garage.freebsd.pl
Am I Evil? Yes, I Am.

--enLffk0M6cffIOOh
Content-Type: application/pgp-signature
Content-Disposition: inline

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.0.7 (FreeBSD)

iQCVAwUBPkqo/j/PhmMH/Mf1AQGnygP/XwH/Gl45VZk0pcHrpFaOSXEgsU3afTfm
a3zmQcG/jFwzhYLC+1eRdG+1/AfvQOidObJcCRsc2RMU1aM90DG2UzvS51Q0/bSt
cwVsLOx82f1Gxt+FSmZSRrPCfz7YsvDcyQXuOrowN+PRsP96Gs5b63XiiPX+5q7h
lqflPPlrM7k=
=k3hD
-----END PGP SIGNATURE-----

--enLffk0M6cffIOOh--

To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-bugs" in the body of the message




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?20030212200518.GJ10767>