Because the access control is on directories only, 
it will be hard to know precisely what access is 
permitted to any file with link count > 1.

Per-file ACLs do make this much clearer, despite 
the cost.

> Hard links are incredibly useful and it make no sense to 
> disable them only
> for security issues as security can be addressed by 
> forbidding changing
> the inode->i_link by users that can't change all other fields of the
> inode.

Reply via email to