Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

In the past I used something like inotab to use an inotify-based trigger to pipe data from SSH to a different system that didn't have any NAS or SAN support, it might also work to detect 'who' is touching any files that boxxy has previously seen rules for.

Perhaps still too tricky to make it do magic things and break programs in the process, but it could be used to audit who's working with what paths and let the user print a report so they know what apps to boxx up and make them behave.



That is an excellent idea! Something like could definitely be worth adding. It's why there's a "remount rootfs as ro" flag; that way anything not specified in rules is ro and misbehaving programs will explode.


Love exploding apps. That's what they get for eating my filesystem.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: