diff options
author | Dmitry Marakasov <amdmi3@FreeBSD.org> | 2008-06-26 11:02:14 +0000 |
---|---|---|
committer | Dmitry Marakasov <amdmi3@FreeBSD.org> | 2008-06-26 11:02:14 +0000 |
commit | 57b06340158a1e5c0daac1cc779b12312cae8d68 (patch) | |
tree | 2ca27a2125332c4f6dd4b6dc14e8dd1ab361e8cc /sysutils/kiconvtool/pkg-descr | |
parent | dfa2d819b059c6eb3c35594d955d2b1eac533278 (diff) | |
download | ports-57b06340158a1e5c0daac1cc779b12312cae8d68.tar.gz ports-57b06340158a1e5c0daac1cc779b12312cae8d68.zip |
Notes
Diffstat (limited to 'sysutils/kiconvtool/pkg-descr')
-rw-r--r-- | sysutils/kiconvtool/pkg-descr | 16 |
1 files changed, 16 insertions, 0 deletions
diff --git a/sysutils/kiconvtool/pkg-descr b/sysutils/kiconvtool/pkg-descr new file mode 100644 index 000000000000..09decdc27580 --- /dev/null +++ b/sysutils/kiconvtool/pkg-descr @@ -0,0 +1,16 @@ +On FreeBSD, it's possible to allow plain users to mount filesystems +without using su or sudo. This is enabled via vfs.usermount sysctl. +However, if file name conversion is used when mounting a filesystem, +in most cases mount will fail with `mount_XXX: XXX_iconv: Operation +not permitted denied' error. This is caused by the fact that character +set conversion tables need to be loaded into kernel, but, apart +from mounting, that's not allowed to plain users, because charset +tables are large enough to initiate a denial of service by filling +kernel memory with many tables. + +This utility allows you to load only specific charset tables into +kernel, so usermounts with file name conversions won't fail and in +the same time it's not possible to bring the system down by filling +kernel memory. + +WWW: http://wiki.freebsd.org/DmitryMarakasov/kiconvtool |