9fans - fans of the OS Plan 9 from Bell Labs
 help / color / mirror / Atom feed
From: erik quanstrom <quanstro@quanstro.net>
To: 9fans@9fans.net
Subject: Re: [9fans] log oversight
Date: Mon, 16 Mar 2009 09:37:10 -0400	[thread overview]
Message-ID: <866da449cc6debeba3d36260cfa2608b@quanstro.net> (raw)
In-Reply-To: <20090316042359.GI22497@masters6.cs.jhu.edu>

> An alternative for the paranoid perhaps would be to make an additional fs
> (in fossil) containing the log files.  This fs could be set to accept only
> the hostowner's credentials for attach requests.  The hostowner, meanwhile,
> when constructing namespaces, could bind the right file(s) into the log
> directory.  I haven't thought it through in more detail than that, but if I
> were to engineer a replacement, that's how I'd start.  HTH.

this would give you exactly the same security behavior as we currently have,
but if the fd were ever closed or dup(2)'d over, syslog(2) would
stop working.

- erik



      parent reply	other threads:[~2009-03-16 13:37 UTC|newest]

Thread overview: 11+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2009-03-16  1:49 Jeff Sickel
2009-03-16  2:35 ` balaji
2009-03-16  3:04   ` erik quanstrom
2009-03-16  3:18     ` ron minnich
2009-03-16  3:55       ` J.R. Mauro
2009-03-16  4:31         ` Alex Efros
2009-03-16  6:30         ` ron minnich
2009-03-16 15:06           ` J.R. Mauro
2009-03-16  4:23 ` Nathaniel W Filardo
2009-03-16  4:36   ` Jeff Sickel
2009-03-16 13:37   ` erik quanstrom [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=866da449cc6debeba3d36260cfa2608b@quanstro.net \
    --to=quanstro@quanstro.net \
    --cc=9fans@9fans.net \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).