[PATCH] Allow %n in -D_FORTIFY_SOURCE=2 linux programs if /proc is not mounted

Ulrich Drepper drepper@redhat.com
Wed Oct 20 10:22:00 GMT 2004


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Jakub Jelinek wrote:
> If /proc is not mounted, it is IMHO better to be less protected than
> fail on legitimate %n uses.

I'm not sure this is such a good idea.  This can potentially affect only
a handful of programs, those running before /proc is mounted and those
used fater it is unmounted.  If insight into t hose programs is hard
enough we should use your patch.

I worry about an exploit where a process running as root first run
umount for /proc to disable this and maybe other checks.

- --
➧ Ulrich Drepper ➧ Red Hat, Inc. ➧ 444 Castro St ➧ Mountain View, CA ❖
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.6 (GNU/Linux)

iD8DBQFBdjw52ijCOnn/RHQRAijkAJ4jexDj8zWdoVHU3d5lzibKB9TtTwCeNhRu
WvfPM+zC0fIySlUIOWYMpss=
=Opea
-----END PGP SIGNATURE-----



More information about the Libc-hacker mailing list