1 |
On Thursday 30 September 2004 2:04 pm, Paul de Vrieze wrote: |
2 |
> Well, the issue is that without being root the file permissions in the |
3 |
> install stage will not be correct. The only even more secure option |
4 |
> besides the sandbox would be some kind of chroot with an overlay |
5 |
> filesystem. That would though require a nonstandard kernel module and as |
6 |
> such raise all kinds of other problems. |
7 |
Simply implementing sandbox as a kernel module would have the same security |
8 |
effect as such a chroot. Then, libsandbox (or whatever it's called) could |
9 |
simply use the module if available and fallback to the normal way if it's |
10 |
not... |
11 |
-- |
12 |
Luke-Jr |
13 |
Developer, Utopios |
14 |
http://utopios.org/ |