Open tyler-gilbert opened 6 years ago
If /app is marked SOS_ROOT, only ROOT can access that filesystem.
This needs to be enforced atomically in kernel mode on each function. It can't just be some gatekeeper code at the ROOT level.
If /app is marked SOS_ROOT, only ROOT can access that filesystem.