Hi Herbert,

> yes, because the bind mount probably doesn't exist
> when the tools try to write to /dev/null

Hmmm, anyway

> IMHO a more secure solution would be to bind mount
> the /dev/log only and keep the entire /dev read only
> as that is more secure than having them on var

AFAIK its not possible the bind-mount a file, or am I wrong?

I played around and came to a very nice solution :)
I added a Script to the prepre-start level, that mounts a tmpfs on /dev
and creates the necessary nodes. Seems to do fine

Thx for the help anyway

Oliver

Attachment: smime.p7s
Description: S/MIME Cryptographic Signature

_______________________________________________
Vserver mailing list
[email protected]
http://list.linux-vserver.org/mailman/listinfo/vserver

Reply via email to