> You can mount the fs only once. This will probably break shm in
> chrooted environments.
I think it would be best to code it in such a way that you
can mount multiple instances of shmfs, in such a way that
the differently chrooted programs cannot see each other's
shared memory. That should make it a bit more difficult to
get out of a chroot() jail...
(security buffs, please tell me if I'm full of it)
cheers,
Rik
-- The Internet is not a network of computers. It is a network of people. That is its real strength.
- To unsubscribe from this list: send the line "unsubscribe linux-kernel" in the body of a message to majordomo@vger.rutgers.edu Please read the FAQ at http://www.tux.org/lkml/