From owner-freebsd-security@FreeBSD.ORG Mon Nov 21 18:40:37 2005 Return-Path: X-Original-To: freebsd-security@freebsd.org Delivered-To: freebsd-security@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id EC66D16A435; Mon, 21 Nov 2005 18:40:36 +0000 (GMT) (envelope-from avg@icyb.net.ua) Received: from citadel.icyb.net.ua (citadel.icyb.net.ua [212.40.38.140]) by mx1.FreeBSD.org (Postfix) with ESMTP id 0780E43D62; Mon, 21 Nov 2005 18:40:32 +0000 (GMT) (envelope-from avg@icyb.net.ua) Received: from [212.40.38.87] (oddity-e.topspin.kiev.ua [212.40.38.87]) by citadel.icyb.net.ua (8.8.8p3/ICyb-2.3exp) with ESMTP id UAA12875; Mon, 21 Nov 2005 20:40:24 +0200 (EET) (envelope-from avg@icyb.net.ua) Message-ID: <43821498.905@icyb.net.ua> Date: Mon, 21 Nov 2005 20:40:24 +0200 From: Andriy Gapon User-Agent: Mozilla Thunderbird 1.0.7 (X11/20051016) X-Accept-Language: en-us, en MIME-Version: 1.0 To: Lowell Gilbert References: <4381BFE2.80106@icyb.net.ua> <44sltqxgj5.fsf@be-well.ilk.org> In-Reply-To: <44sltqxgj5.fsf@be-well.ilk.org> Content-Type: text/plain; charset=ISO-8859-1 Content-Transfer-Encoding: 7bit X-Mailman-Approved-At: Tue, 22 Nov 2005 03:37:48 +0000 Cc: freebsd-fs@freebsd.org, freebsd-security@freebsd.org Subject: Re: mount -u -r drops nosuid ? X-BeenThere: freebsd-security@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: "Security issues \[members-only posting\]" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Mon, 21 Nov 2005 18:40:37 -0000 on 21/11/2005 15:43 Lowell Gilbert said the following: > The behaviour is explicitly documented. > > I think it is safer (less room to shoot yourself in the foot) to have > the flags be exactly the ones you specified in the remount (no more, > no less) than to have to know exactly what the state was beforehand. > But clearly it's possible to surprise the operator either way. Actually, somebody (Vasiliy ) off the list tought me about -o current option to mount. Really useful, I wonder how I managed to not notice it so far. Thanks Vasily! -- Andriy Gapon