Gentoo Archives: gentoo-dev

From: Drake Wyrm <wyrm@×××××.com>
To: gentoo-dev@l.g.o
Subject: Re: [gentoo-dev] Making procfs mount as nosuid,noexec by default
Date: Sun, 16 Jul 2006 13:55:58
Message-Id: 20060716013928.GA307@phaenix.haell.com
In Reply to: Re: [gentoo-dev] Making procfs mount as nosuid,noexec by default by Ned Ludd
1 Ned Ludd <solar@g.o> wrote:
2 > Not 100% sure about the noexec part as that might break upx which
3 > calls /proc/self/exe as part of it's decompresser routines.
4
5 /proc/self/exe is a symlink, and the permissions of symlinks aren't used
6 for anything. It's less than trivial (and I think impossible) to set
7 them to anything but 0777. In any case, the noexec option only affects
8 regular files. Directories, for example, also keep their execute flags.
9
10
11 --
12 Batou: Hey, Major... You ever hear of "human rights"?
13 Kusanagi: I understand the concept, but I've never seen it in action.
14 --Ghost in the Shell