Al Viro responded favourably to blocking mounts over magic-links (or rather, mounts over "ethereal" components like everything in /proc/self/*), and this is fairly easy to implement. This would eliminate all concerns about races in procfs for kernels that support this.
Al Viro responded favourably to blocking mounts over magic-links (or rather, mounts over "ethereal" components like everything in
/proc/self/*
), and this is fairly easy to implement. This would eliminate all concerns about races in procfs for kernels that support this.