Re: disable-cap-mlock

From: Chris Wright
Date: Thu Apr 01 2004 - 21:02:04 EST


* Andrew Morton (akpm@xxxxxxxx) wrote:
> Rumour has it that the more exhasperated among us are brewing up a patch to
> login.c which will allow capabilities to be retained after the setuid. So
> you do
>
> echo "oracle CAP_IPC_LOCK" > /etc/logincap.conf
>
> And that's it.
>
> See any reason why this won't work?

Looks ok, and sounds very similar to what pam_cap does.

thanks,
-chris
--
Linux Security Modules http://lsm.immunix.org http://lsm.bkbits.net
-
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at http://vger.kernel.org/majordomo-info.html
Please read the FAQ at http://www.tux.org/lkml/