@dalias the email already points out that openat() was not designed for security but both Linux and FreeBSD made changes to make it so: "... their strategy was to add an additional flag which didn't allow upwards traversal. I think that misses the point, and have a different proposal."
@brynet
Embed Notice
HTML Code
Corresponding Notice
- Embed this notice
Can Acar (canacar@ioc.exchange)'s status on Thursday, 29-May-2025 02:29:04 JST Can Acar