kern/121073: [kernel] [patch] run chroot as an unprivileged user

FreeBSD Security Officer cperciva at FreeBSD.org
Sat Mar 1 06:40:03 UTC 2008


The following reply was made to PR kern/121073; it has been noted by GNATS.

From: FreeBSD Security Officer <cperciva at freebsd.org>
To: bug-followup at FreeBSD.org, jille at quis.cx
Cc:  
Subject: Re: kern/121073: [kernel] [patch] run chroot as an unprivileged user
Date: Fri, 29 Feb 2008 22:36:24 -0800

 This is an interesting approach, and at first glance I can't see anything wrong
 with it.  That said, it needs very careful consideration; so to avoid confusion
 and make sure that this doesn't get committed before the right people have a
 chance to consider it sufficiently:
 
          +----------------------------------------------------------+
          |UNDER NO CONDITIONS SHOULD THIS PATCH BE COMMITTED WITHOUT|
          |EXPLICIT APPROVAL FROM THE FREEBSD SECURITY OFFICER.      |
          +----------------------------------------------------------+
 
 Colin Percival


More information about the freebsd-bugs mailing list