devfs
[Top] [All Lists]

Re: Default: insecure

To: rgooch@xxxxxxxxxxxxxxx
Subject: Re: Default: insecure
From: Pascal Bourguignon <pjb@xxxxxxxxxxxxxxxxx>
Date: Fri, 21 Sep 2001 00:36:03 +0200 (CEST)
Cc: Robert.Siemer@xxxxxx, devfs@xxxxxxxxxxx
In-reply-to: <200109202203.f8KM3R806364@vindaloo.ras.ucalgary.ca> (message from Richard Gooch on Thu, 20 Sep 2001 16:03:27 -0600)
Organization: InformatiMago.
References: <200109201531.f8KFVbP02796@vindaloo.ras.ucalgary.ca> <20010920184715A.siemer@panorama.hadiko.de> <200109201702.f8KH2Lh03467@vindaloo.ras.ucalgary.ca> <20010920223240K.siemer@panorama.hadiko.de> <20010920212855.D7B7960634@thalassa.informatimago.com> <200109202203.f8KM3R806364@vindaloo.ras.ucalgary.ca>
Reply-to: <pjb@xxxxxxxxxxxxxxxxx>
Sender: owner-devfs@xxxxxxxxxxx

> Date: Thu, 20 Sep 2001 16:03:27 -0600
> From: Richard Gooch <rgooch@xxxxxxxxxxxxxxx>
> 
> Pascal Bourguignon writes:
> > > From: Robert Siemer <Robert.Siemer@xxxxxx>
> > > [...]
> > > But how do you protect tape users from other users accessing their
> > > tape during backup (... or just before)?
> > 
> > What about using flock on the tape devices? Wouldn't this work?
> 
> Not needed to protect against other openers (only one open at a time
> is allowed). And flocks are lost when you close the file descriptor.
> Also, flocks are advisory only (in general).
> 
> > On the other hand, if the tapes belong to their users, then the device
> > should  be  assigned  to  the  proper  owner as  soon  as  a  tape  is
> > (physically) mounted on  it. I don't know any mechanism  in unix to do
> > that other than "chown $USER $TAPEDEVICE" before mounting the tape.
> > 
> > The question is: How do you assign a tape device to a user?
> 
> chown(2).

Thank you :-)  I suggested chown(1) just one  line above.  My question
was to Robert, on the policy  plan. Depending on the policy adopted to
assign tape devices to the  users, one could develop some scripts with
a  strategically placed  "chown  $USER $TAPEDEVICE",  to automate  the
process.



-- 
__Pascal_Bourguignon__              (o_ Software patents are endangering
()  ASCII ribbon against html email //\ the computer industry all around
/\  and Microsoft attachments.      V_/ the world http://lpf.ai.mit.edu/
1962:DO20I=1.100  2001:my($f)=`fortune`;  http://petition.eurolinux.org/

-----BEGIN GEEK CODE BLOCK-----
Version: 3.1
GCS/IT d? s++:++(+++)>++ a C+++  UB+++L++++$S+X++++>$ P- L+++ E++ W++
N++ o-- K- w------ O- M++$ V PS+E++ Y++ PGP++ t+ 5? X+ R !tv b++(+)
DI+++ D++ G++ e+++ h+(++) r? y---? UF++++
------END GEEK CODE BLOCK------

<Prev in Thread] Current Thread [Next in Thread>