Re: root access to block disk devices


From: Arkady A Drovosekov <drawa@suct.uu.ru>
Subject: Re: root access to block disk devices
Date: Tue, 17 Jul 2001 08:06:50 +0600

Next Article (by Author): 1.1.2-pre8 first run Arkady A Drovosekov
Previous Article (by Author): Re: root access to block disk devices Arkady A Drovosekov
Top of Thread: root access to block disk devices steve
Articles sorted by: [Date] [Author] [Subject]


On Mon, Jul 16, 2001 at 05:41:37PM -0500, steve wrote:
steve> turned out to be a bigger chore than I thought.  For instance, the init
steve> process tried to access device /dev/ram3.  Any idea why that might be?  
don't know

steve> Anyway, I think I'm going to have to start out blocking access to
steve> specific devices rather than blocking access to all devices and giving
steve> it back where needed.  I need to do a lot more research and testing to
steve> get the latter to work.
you can add trace to all devices and then check logs for access attempts

steve> Does anyone have a list of devices (besides disks and kmem/mem) that you
steve> recommend removing access to?
memory, ioports, mounted disks (what I missed?).
It's may be better to ask Solar Designer about it. He did it in his patch
for 2.0 kernels
-- 
Best regards,
Arkady
-
To unsubscribe from the rsbac list, send a mail to
majordomo@rsbac.org with
unsubscribe rsbac
as single line in the body.

Next Article (by Author): 1.1.2-pre8 first run Arkady A Drovosekov
Previous Article (by Author): Re: root access to block disk devices Arkady A Drovosekov
Top of Thread: root access to block disk devices steve
Articles sorted by: [Date] [Author] [Subject]


Go to Compuniverse LWGate Home Page.