phk
e1c9acedca
Add a sysctl variable which can help stop chroot(2) escapes.
...
kern.chroot_allow_open_directories = 0
chroot(2) fails if there are open directories.
kern.chroot_allow_open_directories = 1 (default)
chroot(2) fails if there are open directories and the process
is subject of a previous chroot(2).
kern.chroot_allow_open_directories = anything else
filedescriptors are not checked. (old behaviour).
I'm very interested in reports about software which breaks when
running with the default setting.
1999-03-23 14:26:40 +00:00
..
1998-09-26 11:54:02 +00:00
1999-03-15 21:56:54 +00:00
1999-03-09 23:44:00 +00:00
1998-10-11 04:41:43 +00:00
1998-06-11 10:39:32 +00:00
1999-03-23 14:26:40 +00:00
1999-03-23 05:07:56 +00:00
1998-03-19 07:34:22 +00:00
1999-03-05 17:11:37 +00:00
1998-09-11 05:39:08 +00:00
1999-01-27 04:35:02 +00:00
1999-03-23 03:41:09 +00:00
1998-10-12 16:32:32 +00:00
1999-03-22 10:38:07 +00:00
1999-01-29 11:39:24 +00:00
1999-01-09 21:51:00 +00:00
1998-11-16 23:51:14 +00:00
1999-02-03 17:23:49 +00:00
1999-03-05 18:45:32 +00:00
1998-04-11 07:28:53 +00:00
1998-10-11 04:18:30 +00:00
1999-02-03 17:23:49 +00:00
1998-12-12 18:05:06 +00:00
1998-06-30 18:06:23 +00:00
1999-03-23 05:07:56 +00:00
1999-03-12 14:47:33 +00:00
1998-10-11 17:14:56 +00:00
1999-03-02 22:53:24 +00:00
1998-12-27 15:04:33 +00:00
1998-12-10 02:35:24 +00:00
1998-10-11 04:45:50 +00:00
1999-01-22 12:43:42 +00:00
1998-12-27 15:04:33 +00:00
1999-03-23 05:07:56 +00:00
1999-02-05 11:23:44 +00:00
1998-10-11 04:21:56 +00:00
1998-05-18 21:59:53 +00:00
1999-03-05 15:50:07 +00:00
1998-09-16 04:17:47 +00:00
1999-02-12 17:22:30 +00:00
1998-11-13 00:54:26 +00:00
1998-12-16 06:04:29 +00:00
1998-10-11 04:39:56 +00:00
1999-03-11 09:09:20 +00:00
1998-03-19 07:34:22 +00:00
1999-03-14 17:56:11 +00:00
1998-08-15 12:51:49 +00:00
1998-10-11 04:10:14 +00:00
1999-01-10 09:53:51 +00:00
1998-12-24 13:17:58 +00:00
1998-03-20 16:50:08 +00:00
1999-03-14 17:56:11 +00:00
1998-01-11 03:30:40 +00:00