linux-fsdevel.vger.kernel.org archive mirror
 help / color / mirror / Atom feed
From: Jan-Benedict Glaw <jbglaw@lug-owl.de>
To: "Joseph D. Wagner" <theman@josephdwagner.info>
Cc: viro@parcelfarce.linux.theplanet.co.uk,
	'Guy' <bugzilla@watkins-home.com>,
	'Bryan Henderson' <hbryan@us.ibm.com>, 'Jan Hudec' <bulb@ucw.cz>,
	linux-fsdevel@vger.kernel.org
Subject: Re: RFC: Illegal Characters in File Names
Date: Wed, 21 Jul 2004 14:43:15 +0200	[thread overview]
Message-ID: <20040721124315.GS4690@lug-owl.de> (raw)
In-Reply-To: <S266335AbUGTWQ6/20040720221658Z+360@vger.kernel.org>

[-- Attachment #1: Type: text/plain, Size: 2631 bytes --]

On Tue, 2004-07-20 17:16:57 -0500, Joseph D. Wagner <theman@josephdwagner.info>
wrote in message <S266335AbUGTWQ6/20040720221658Z+360@vger.kernel.org>:
> > What security risk?  You mean running applications written by lusers?
> 
> But that's the million dollar question, Regis.  How do you know if the
> application is any good or not?  Not every program that runs on Linux

When it's a FSF GNU application and some 10 years around, I tend to
think that it's old enough to have all major problems removed.

> is open source.  Not every end user running Linux is skilled enough to
> read the source code.

I think you'll face a hard time finding such badly written software on
most systems, and especially those ran (sp?) by root are not of that
slice. (Except root is incompetent and likes to start KDE or Gnome...)

> And don't give me that crap about how a proprietary company's software
> is implied to be better.  Microsoft is a multi-billion dollar
> proprietary software company, and they can't even fix bugs in IE.
> How can you place such demands on other programmers?

In Germany, we've got sentence, "Ist der Ruf erst ruiniert, lebt sich's
völlig ungeniert", meaning something like if you did some bad things,
nobody will mind if you do even more of them.

Open source programmers will get blamed *personally* for the bullshit
they produce. Nobody likes to write security advisories. It's *pain*. At
large software companies, there's no such blame, no such pain. I guess
commonly those people writing the advisories won't have seen the code at
all. Bugs just happen as systemic failures, nobody is personally blamed
for them. That's different for open-sources software, because you know
the author, sometimes even personally.

> I'm afraid, however, that Bryan Henderson's analysis is correct when he said:
> 
> > This is the well known conflict between what's
> > philosophically right and what's practical. [trimmed]
> > So even though filesystem design shouldn't have to
> > solve that problem, it's a very practical place to
> > solve it.
> 
> I'm afraid this won't happen until it's a file system option.

If you were to introduce an additional "check_filename()" system call,
you'd just put a function of the very same name into the application...

MfG, JBG

-- 
   Jan-Benedict Glaw       jbglaw@lug-owl.de    . +49-172-7608481
   "Eine Freie Meinung in  einem Freien Kopf    | Gegen Zensur | Gegen Krieg
    fuer einen Freien Staat voll Freier Bürger" | im Internet! |   im Irak!
   ret = do_actions((curr | FREE_SPEECH) & ~(NEW_COPYRIGHT_LAW | DRM | TCPA));

[-- Attachment #2: Digital signature --]
[-- Type: application/pgp-signature, Size: 189 bytes --]

  reply	other threads:[~2004-07-21 12:43 UTC|newest]

Thread overview: 68+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2004-07-19  0:41 RFC: Illegal Characters in File Names Joseph Wagner
2004-07-19  8:47 ` Jan Hudec
2004-07-19 19:21   ` Joseph D. Wagner
2004-07-19 20:08     ` Pat LaVarre
2004-07-19 20:54       ` Joseph D. Wagner
2004-07-20  6:33     ` Jan-Benedict Glaw
2004-07-20 16:25       ` Joseph D. Wagner
2004-07-20 20:42         ` Stephen Rothwell
     [not found]       ` <20040720162549.857014B7E7@dvmwest.gt.owl.de>
2004-07-20 16:52         ` Jan-Benedict Glaw
     [not found]   ` <20040719192145.50750578E5@jabberwock.ucw.cz>
2004-07-19 21:01     ` Jan Hudec
2004-07-20 16:40       ` Bryan Henderson
2004-07-20 16:54         ` Guy
2004-07-20 18:10           ` viro
2004-07-20 20:44             ` Guy
2004-07-20 21:27               ` Matthew Wilcox
2004-07-20 21:37                 ` Jan Hudec
2004-07-20 21:40                   ` Matthew Wilcox
2004-07-20 21:45                     ` Jan Hudec
2004-07-20 21:49                       ` Guy
2004-07-20 22:04                         ` Jan Hudec
2004-07-20 22:11                         ` Paul Stewart
2004-07-20 22:16                       ` Joseph D. Wagner
2004-07-21 12:26                         ` Jan-Benedict Glaw
2004-07-21 15:28                           ` Guy
2004-07-21 16:25                             ` Jan-Benedict Glaw
2004-07-21 12:24                       ` Jan-Benedict Glaw
2004-07-20 21:41               ` Bryan Henderson
2004-07-21 12:21               ` Jan-Benedict Glaw
2004-07-21 15:25                 ` Guy
2004-07-22 18:04                   ` Matthew Wilcox
2004-07-22 18:35                     ` Guy
2004-07-20 20:57             ` Jan Hudec
2004-07-20 21:09               ` Guy
2004-07-20 21:36                 ` Jan Hudec
2004-07-20 22:13                 ` viro
2004-07-20 22:44                   ` Jan Hudec
2004-07-20 22:51                     ` viro
2004-07-20 23:30                   ` Guy
2004-07-21 20:25                     ` Bryan Henderson
2004-07-22  3:17                       ` John Newbigin
2004-07-22  3:24                         ` Matthew Wilcox
2004-07-22  6:01                         ` viro
2004-07-22 22:12                         ` Bryan Henderson
2004-07-22 14:51                       ` Jan-Benedict Glaw
2004-07-22 22:44                         ` Bryan Henderson
2004-07-22 22:47                           ` Jan Hudec
2004-07-23 18:10                             ` Bryan Henderson
2004-07-20 23:52                   ` John Newbigin
2004-07-21  3:26                     ` Joseph D. Wagner
2004-07-21  4:15                     ` viro
2004-07-21  5:03                     ` Guy
2004-07-21 12:28                 ` Jan-Benedict Glaw
2004-07-21 15:30                   ` Guy
2004-07-21 16:26                     ` Jan-Benedict Glaw
2004-07-21 16:33                       ` Jan Hudec
2004-07-21 16:41                       ` Guy
2004-07-21 17:01                         ` Jan Hudec
2004-07-20 22:16             ` Joseph D. Wagner
2004-07-21 12:43               ` Jan-Benedict Glaw [this message]
2004-07-20 22:31             ` viro
2004-07-20 18:27           ` Bryan Henderson
2004-07-19  9:26 ` Matthew Wilcox
2004-07-19 19:21   ` Joseph D. Wagner
     [not found]   ` <E1BmdhG-0004NG-00@master.debian.org>
2004-07-20  2:43     ` Matthew Wilcox
2004-07-20  3:16       ` Joseph D. Wagner
2004-07-20  8:45         ` Jan Hudec
2004-07-20 16:25           ` Joseph D. Wagner
2004-07-20 16:41             ` Guy

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20040721124315.GS4690@lug-owl.de \
    --to=jbglaw@lug-owl.de \
    --cc=bugzilla@watkins-home.com \
    --cc=bulb@ucw.cz \
    --cc=hbryan@us.ibm.com \
    --cc=linux-fsdevel@vger.kernel.org \
    --cc=theman@josephdwagner.info \
    --cc=viro@parcelfarce.linux.theplanet.co.uk \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).