On Wed, Oct 03, 2012 at 10:05:25PM +0100, Alan Cox wrote: > > If this happens, I _really_ want to bring back the CONFIG options I had in > > an earlier version of this patch. I want to be able to declare the default > > at build time, and not leave a system vulnerable from boot until sysctls > > get set. > > If your early boot code trusts a random writeable user directory I think > you have other problems.
You should see some of the things various Android devices do! :) -Kees -- Kees Cook @outflux.net -- To unsubscribe from this list: send the line "unsubscribe linux-kernel" in the body of a message to [email protected] More majordomo info at http://vger.kernel.org/majordomo-info.html Please read the FAQ at http://www.tux.org/lkml/

